Patents by Inventor Navan Narang

Navan Narang has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8411650
    Abstract: A method for providing a virtual private network by home agent in a mobile IP environment includes providing a home agent operable to receive a registration request from a foreign agent and negotiate conditions of attachment of a mobile node to the foreign agent and further operable to store an IP address of the foreign agent in response to the negotiated conditions. The method also includes receiving, at the home agent, from the foreign agent, a registration request for the mobile node. The method also includes determining, by the home agent, a virtual private network membership of the mobile node based on a characteristic associated with the mobile node. The method further includes mapping the mobile node to an identifier associated with the home agent and transmitting the mapping to the foreign agent. The identifier is indicative of the virtual private network membership of the mobile subscriber.
    Type: Grant
    Filed: April 18, 2005
    Date of Patent: April 2, 2013
    Assignee: Cisco Technology, Inc.
    Inventors: Jayaraman R. Iyer, Navan Narang, Michael L. Shannon, Arghya T. Mukherjee
  • Patent number: 8356171
    Abstract: A system for efficiently reauthenticating a client of a network. In a specific embodiment, the system includes an authentication server and a Security GateWay (SGW) in communication with the client. The SGW includes reauthentication information associated with the client. In a more specific embodiment, the authentication server includes an Authentication, Authorization, and Accounting (AAA) server. The SGW further includes one or more routines for employing the reauthentication information to reauthenticate the client. The AAA server performs initial authentication of the client to enable client access to the network, which yields the reauthentication information. The reauthentication information includes one or more keys and/or counters, such as an authorization key, an encryption key, and a master key, which is/are predetermined by the AAA server.
    Type: Grant
    Filed: April 26, 2006
    Date of Patent: January 15, 2013
    Assignee: Cisco Technology, Inc.
    Inventors: Kevin Shatzkamer, Anand K. Oswal, Mark Grayson, Jayaraman Iyer, Navan Narang
  • Patent number: 8315246
    Abstract: A system for enhancing functionality of a network. In a specific embodiment, the system employs strategic communications between a network controller and a security gateway. The strategic communications occur via a feedback communications channel between the network controller and the security gateway. The feedback communications channel facilitates transferring security information, such as International Mobile Subscriber Identity (IMSI) and other information, between the network controller and the security gateway. The security information may facilitate enabling the SGW to make intelligent decisions as to how to treat a client communications session. In the specific embodiment, the feedback communications channel includes an intervening Authentication, Authorization, and Accounting (AAA) server that is coupled between the UMA and the network controller.
    Type: Grant
    Filed: May 18, 2006
    Date of Patent: November 20, 2012
    Assignee: Cisco Technology, Inc.
    Inventors: Kevin Shatzkamer, Anand K. Oswal, Navan Narang, Jayaraman Iyer, Richard Kyle Forster
  • Patent number: 8018948
    Abstract: In one embodiment, a security gateway receives an IPSec Initiation (IPSec INIT) request from a client. The security gateway may communicate with a AAA server to authenticate the client. After authentication, the security gateway intercepts a URR Discovery request from the client. The security gateway determines registration information for a response to the registration request. The registration information may be information on where the client can locate a D-GANC. A response is generated using the determined information and sent to the client. The response to the discovery request is performed without communicating with a P-GANC. Accordingly, a security gateway is used to authenticate the client and also to respond to the discovery request. This does not require that a P-GANC function be deployed in a network. Thus, cost and processing power may be saved.
    Type: Grant
    Filed: March 19, 2007
    Date of Patent: September 13, 2011
    Assignee: Cisco Technology, Inc.
    Inventors: Kevin Shatzkamer, Anand K. Oswal, Jayaraman Iyer, Mark Grayson, Navan Narang
  • Publication number: 20080235783
    Abstract: In one embodiment, a security gateway receives an IPSec Initiation (IPSec INIT) request from a client. The security gateway may communicate with a AAA server to authenticate the client. After authentication, the security gateway intercepts a URR Discovery request from the client. The security gateway determines registration information for a response to the registration request. The registration information may be information on where the client can locate a D-GANC. A response is generated using the determined information and sent to the client. The response to the discovery request is performed without communicating with a P-GANC. Accordingly, a security gateway is used to authenticate the client and also to respond to the discovery request. This does not require that a P-GANC function be deployed in a network. Thus, cost and processing power may be saved.
    Type: Application
    Filed: March 19, 2007
    Publication date: September 25, 2008
    Applicant: CISCO TECHNOLOGY, INC.
    Inventors: Kevin Shatzkamer, Anand K. Oswal, Jayaraman Iyer, Mark Grayson, Navan Narang
  • Publication number: 20070268888
    Abstract: A system for enhancing functionality of a network. In a specific embodiment, the system employs strategic communications between a network controller and a security gateway. The strategic communications occur via a feedback communications channel between the network controller and the security gateway. The feedback communications channel facilitates transferring security information, such as International Mobile Subscriber Identity (IMSI) and other information, between the network controller and the security gateway. The security information may facilitate enabling the SGW to make intelligent decisions as to how to treat a client communications session. In the specific embodiment, the feedback communications channel includes an intervening Authentication, Authorization, and Accounting (AAA) server that is coupled between the UMA and the network controller.
    Type: Application
    Filed: May 18, 2006
    Publication date: November 22, 2007
    Applicant: Cisco Technology, Inc.
    Inventors: Kevin Shatzkamer, Anand K. Oswal, Navan Narang, Jayaraman Iyer, Richard Kyle Forster
  • Publication number: 20070256120
    Abstract: A system for efficiently reauthenticating a client of a network. In a specific embodiment, the system includes an authentication server and a Security GateWay (SGW) in communication with the client. The SGW includes reauthentication information associated with the client. In a more specific embodiment, the authentication server includes an Authentication, Authorization, and Accounting (AAA) server. The SGW further includes one or more routines for employing the reauthentication information to reauthenticate the client. The AAA server performs initial authentication of the client to enable client access to the network, which yields the reauthentication information. The reauthentication information includes one or more keys and/or counters, such as an authorization key, an encryption key, and a master key, which is/are predetermined by the AAA server.
    Type: Application
    Filed: April 26, 2006
    Publication date: November 1, 2007
    Applicant: Cisco Technology, Inc.
    Inventors: Kevin Shatzkamer, Anand Oswal, Mark Grayson, Jayaraman Iyer, Navan Narang
  • Publication number: 20060233141
    Abstract: A method for providing a virtual private network by home agent in a mobile IP environment includes providing a home agent operable to receive a registration request from a foreign agent and negotiate conditions of attachment of a mobile node to the foreign agent and further operable to store an IP address of the foreign agent in response to the negotiated conditions. The method also includes receiving, at the home agent, from the foreign agent, a registration request for the mobile node. The method also includes determining, by the home agent, a virtual private network membership of the mobile node based on a characteristic associated with the mobile node. The method further includes mapping the mobile node to an identifier associated with the home agent and transmitting the mapping to the foreign agent. The identifier is indicative of the virtual private network membership of the mobile subscriber.
    Type: Application
    Filed: April 18, 2005
    Publication date: October 19, 2006
    Inventors: Jayaraman Iyer, Navan Narang, Michael Shannon, Arghya Mukherjee