Patents by Inventor Shashidhar Merugu

Shashidhar Merugu has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 8613071
    Abstract: Transaction accelerators can be configured to terminate secure connections. A server-side accelerator intercepts a secure connection request that is from a client and that is directed to a server. The server-side accelerator responds to the secure connection request in place of the server, thereby establishing a secure connection between the client and the server-side accelerator. Alternatively, the server-side accelerator monitors the establishment of a secure connection between the client and the server. After the secure connection has been established, the server-side accelerator forwards security information to a client-side accelerator, enabling the client-side accelerator to assume control of the secure connection. As a result of this arrangement, the client-side accelerator is able to encrypt and decrypt data on the secure connection and accelerate it in cooperation with the server-side accelerator.
    Type: Grant
    Filed: July 18, 2006
    Date of Patent: December 17, 2013
    Assignee: Riverbed Technology, Inc.
    Inventors: Mark Stuart Day, Case Larsen, Shashidhar Merugu
  • Patent number: 8478986
    Abstract: A method is provided for establishing a split-terminated secure communication connection between a client and a server. A first network intermediary intercepts a secure communication connection request directed from the client to the server. A second intermediary having a digital certificate in the name of the server (and a corresponding private key) acts in place of the server to establish a first secure communication session with the client, during which it receives a secret from the client for generating the session key. The second intermediary supplies the secret and/or the session key to the first intermediary, which allows the first intermediary to establish follow-on secure communication sessions in which the secret is reused. The second intermediary may also supply the first intermediary with a copy of its certificate so that it can respond to new secure communication requests and, yet further, may also supply a copy of the private key.
    Type: Grant
    Filed: December 3, 2008
    Date of Patent: July 2, 2013
    Assignee: Riverbed Technology, Inc.
    Inventors: Shashidhar Merugu, Case Thomas Larsen, Naveen Maveli
  • Patent number: 8463843
    Abstract: In a system where transactions are accelerated with asynchronous writes that require acknowledgements, with pre-acknowledging writes at a source of the writes, a destination-side transaction accelerator includes a queue for queue writes to a destination, at least some of the writes being pre-acknowledged by a source-side transaction accelerator prior to the write completing at the destination, a memory for storing a status of a destination-side queue and possibly other determinants, and logic for signaling to the source-side transaction accelerator with instructions to alter pre-acknowledgement rules to hold off on and pursue pre-acknowledgements based on the destination-side queue status. The rules can take into account adjusting the flow of pre-acknowledged requests or pre-acknowledgements at the sender-side transaction accelerator based at least on the computed logical length.
    Type: Grant
    Filed: May 29, 2007
    Date of Patent: June 11, 2013
    Assignee: Riverbed Technology, Inc.
    Inventors: Kartik Subbanna, Nitin Gupta, Adityashankar Kini, Daniel Conor O'Sullivan, Shashidhar Merugu, Steven James Procter, Vivasvat Manohar Keswani
  • Patent number: 8438628
    Abstract: A method and apparatus are provided for split-terminating a secure client-server communication connection, with client authentication. During handshaking between the client and the server, cooperating network intermediaries relay the handshaking messages, without altering the messages. At least one of the intermediaries possesses a private key of the server, and extracts a set of data fields from the handshaking messages, including a Client-Key-Exchange message that can be decrypted with the private key. The intermediary uses the extracted data to compute the client-server session key separate from the client's and the server's similar computation, and may transmit the key to the other intermediary via a secure communication channel. The client and the server thus establish the end-to-end client-server connection, and may authenticate each other, after which the network intermediaries may intercept and optimize the client-server communications transparently to the client and the server.
    Type: Grant
    Filed: June 29, 2010
    Date of Patent: May 7, 2013
    Assignee: Riverbed Technology, Inc.
    Inventors: Paras Shah, Case Thomas Larsen, Shashidhar Merugu, Yongsub Nam
  • Patent number: 8307203
    Abstract: A local network traffic processor and an application are resident on a common computer system. The application is configured to trust a server certificate issued by a local network traffic processor, the local network traffic processor operatively being paired with a remote network traffic processor. A proxy server certificate, generated using identification information of a server associated with the remote network traffic processor and signed by the local certification authority, is used to establish a secure session between a local network traffic processor and the application.
    Type: Grant
    Filed: July 14, 2009
    Date of Patent: November 6, 2012
    Assignee: Riverbed Technology, Inc.
    Inventors: Charles Fraleigh, Nitin Gupta, Case Larsen, Shashidhar Merugu, Eric Ogren, Paras Shah, Oleg Smolsky
  • Publication number: 20100299525
    Abstract: A method and apparatus are provided for split-terminating a secure client-server communication connection, with client authentication. During handshaking between the client and the server, cooperating network intermediaries relay the handshaking messages, without altering the messages. At least one of the intermediaries possesses a private key of the server, and extracts a set of data fields from the handshaking messages, including a Client-Key-Exchange message that can be decrypted with the private key. The intermediary uses the extracted data to compute the client-server session key separate from the client's and the server's similar computation, and may transmit the key to the other intermediary via a secure communication channel. The client and the server thus establish the end-to-end client-server connection, and may authenticate each other, after which the network intermediaries may intercept and optimize the client-server communications transparently to the client and the server.
    Type: Application
    Filed: June 29, 2010
    Publication date: November 25, 2010
    Applicant: RIVERBED TECHNOLOGY, INC.
    Inventors: Paras Shah, Case Thomas Larsen, Shashidhar Merugu, Yongsub Nam
  • Publication number: 20100049970
    Abstract: A local network traffic processor and an application are resident on a common computer system. The application is configured to trust a server certificate issued by a local network traffic processor, the local network traffic processor operatively being paired with a remote network traffic processor. A proxy server certificate, generated using identification information of a server associated with the remote network traffic processor and signed by the local certification authority, is used to establish a secure session between a local network traffic processor and the application.
    Type: Application
    Filed: July 14, 2009
    Publication date: February 25, 2010
    Inventors: Charles Fraleigh, Nitin Gupta, Case Larsen, Shashidhar Merugu, Eric Ogren, Paras Shah, Oleg Smolsky
  • Publication number: 20090083538
    Abstract: A method is provided for establishing a split-terminated secure communication connection between a client and a server. A first network intermediary intercepts a secure communication connection request directed from the client to the server. A second intermediary having a digital certificate in the name of the server (and a corresponding private key) acts in place of the server to establish a first secure communication session with the client, during which it receives a secret from the client for generating the session key. The second intermediary supplies the secret and/or the session key to the first intermediary, which allows the first intermediary to establish follow-on secure communication sessions in which the secret is reused. The second intermediary may also supply the first intermediary with a copy of its certificate so that it can respond to new secure communication requests and, yet further, may also supply a copy of the private key.
    Type: Application
    Filed: December 3, 2008
    Publication date: March 26, 2009
    Applicant: RIVERBED TECHNOLOGY, INC.
    Inventors: Shashidhar Merugu, Case Thomas Larsen, Naveen Maveli
  • Publication number: 20090083537
    Abstract: A network intermediary device such as a transaction accelerator intercepts a client request for a secure communication connection with a server. The intermediary issues a substitute connection request to the server and receives a digital certificate during establishment of a secure communication session between the intermediary and the server. Based on information in the received digital certificate, the intermediary selects an appropriate operational configuration for responding to the client's request. The intermediary consults an ordered list or other collection of digital certificates it possesses, and chooses one having a common name that matches the server's common name. The match may comprise the first matching name, the longest match, the best match, the broadest match (e.g., a certificate having a name that includes one or more wildcard characters), etc. The intermediary then uses the selected certificate (and corresponding private key) to establish a secure communication session with the client.
    Type: Application
    Filed: December 3, 2008
    Publication date: March 26, 2009
    Applicant: RIVERBED TECHNOLOGY, INC.
    Inventors: Case Thomas Larsen, Shashidhar Merugu, Paras Shah, Naveen Maveli
  • Publication number: 20080005274
    Abstract: In a system where transactions are accelerated with asynchronous writes that require acknowledgements, with pre-acknowledging writes at a source of the writes, a destination-side transaction accelerator includes a queue for queue writes to a destination, at least some of the writes being pre-acknowledged by a source-side transaction accelerator prior to the write completing at the destination, a memory for storing a status of a destination-side queue and possibly other determinants, and logic for signaling to the source-side transaction accelerator with instructions to alter pre-acknowledgement rules to hold off on and pursue pre-acknowledgements based on the destination-side queue status. The rules can take into account adjusting the flow of pre-acknowledged requests or pre-acknowledgements at the sender-side transaction accelerator based at least on the computed logical length.
    Type: Application
    Filed: May 29, 2007
    Publication date: January 3, 2008
    Applicant: Riverbed Technology, Inc.
    Inventors: Kartik Subbanna, Nitin Gupta, Adityashankar Kini, Daniel O'Sullivan, Shashidhar Merugu, Steven Procter, Vivasvat Keswani
  • Publication number: 20070038853
    Abstract: Transaction accelerators can be configured to terminate secure connections. A server-side accelerator intercepts a secure connection request from a client and directed to a server. The server-side accelerator responds to secure connection request in place of the server, thereby establishing a secure connection between the client and the server-side accelerator. Alternatively, the server-side accelerator monitors the establishment of a secure connection between the client and the server. After the secure connection has been established, the server-side accelerator forwards security information to a client-side accelerator, enabling the client-side accelerator to assume control of the secure connection. As a result of this arrangement, the client-side accelerator is able to encrypt and decrypt data on the secure connection and accelerate it in cooperation with the server-side accelerator.
    Type: Application
    Filed: July 18, 2006
    Publication date: February 15, 2007
    Applicant: Riverbed Technology, Inc.
    Inventors: Mark Day, Case Larsen, Shashidhar Merugu
  • Patent number: 7061874
    Abstract: Classification of packets into flows is an inherent operation performed by networks that support enhanced services. To support multiple-dimensional packet classification, a packet classification system is provided to select representative bits from a packet to look up a set of rules. The per-flow classification works with a large set of rules, where each rule comprises of multiple fields and also allows fast dynamic variation in the rule set. A lookup process includes a simple and finite set of instructions that can be efficiently implemented as pipelined hardware and support very high packet arrival rates.
    Type: Grant
    Filed: January 18, 2002
    Date of Patent: June 13, 2006
    Assignee: Broadcom Corporation
    Inventors: Shashidhar Merugu, Ajay Chandra V Gummalla, Dolors Sala
  • Publication number: 20020152209
    Abstract: Classification of packets into flows is an inherent operation performed by networks that support enhanced services. To support multiple-dimensional packet classification, a packet classification system is provided to select representative bits from a packet to look up a set of rules. The per-flow classification works with a large set of rules, where each rule comprises of multiple fields and also allows fast dynamic variation in the rule set. A lookup process includes a simple and finite set of instructions that can be efficiently implemented as pipelined hardware and support very high packet arrival rates.
    Type: Application
    Filed: January 18, 2002
    Publication date: October 17, 2002
    Applicant: Broadcom Corporation
    Inventors: Shashidhar Merugu, Ajay Chandra V. Gummalla, Dolors Sala