Patents by Inventor Shengyou Zeng
Shengyou Zeng has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 8453216Abstract: An extensible authentication framework is used in cable networks such as Data Over Cable Service Interface Specification (DOCSIS) cable networks. The authentication scheme allows for centralized authentication of cable modems, as well as authentication of the cable network by cable modems. Additionally, the authentication scheme allows a Cable Modem Termination System (CMTS) to authenticate devices downstream from cable modems, such as Customer Premise Equipment (CPE) devices.Type: GrantFiled: November 22, 2010Date of Patent: May 28, 2013Assignee: Cisco Technology, Inc.Inventors: Shengyou Zeng, Jason Frazier, Joshua B. Littlefield, Joseph A. Salowey
-
Patent number: 8437360Abstract: A CMTS or other data aggregation component having a DHCPv6 relay agent extracts a Media Access Control (MAC) address of an end device from a data packet received from an end device. A DHCPv6 data frame is created for transmission to a DHCPv6 server. The MAC address may be inserted into a specific option of the DHCPv6 data frame, where data in the option may not be processed by the server and are echoed back to the aggregation component or CMTS. The DHCPv6 data frame is transmitted to the DHCPv6 server. The component receives a response message from the server that may contain the MAC address or similar client hardware address as it was sent to the server by the network component. The network component may determine an outgoing port interface from which the response message should be sent, utilizing the MAC address and an interface bundling table. In this manner, interface bundling may be enabled.Type: GrantFiled: November 14, 2007Date of Patent: May 7, 2013Assignee: Cisco Technology, Inc.Inventors: Hemant Singh, Madhu Sudan, Shengyou Zeng
-
Patent number: 8255682Abstract: A system that eliminates some of the security vulnerabilities in the prior art systems by using a new sequence of steps to perform initialization of the cable modem: Instead of performing authentication after the cable modem has been registered, the cable modem authentication step is performed immediately after the cable modem completes ranging. Thus an early authentication method and system are provided. The control of authentication is shifted from the cable modem to the CMTS. Instead of the CMTS relying on a Registration Request message (REG-REQ) to determine whether a cable modem must perform authentication (that is to determine if BPI+ is enabled) the CMTS configuration is what determines whether a cable modem must perform authentication.Type: GrantFiled: July 27, 2006Date of Patent: August 28, 2012Assignee: Cisco Technology, Inc.Inventor: Shengyou Zeng
-
Patent number: 7957305Abstract: A hierarchical cable modem clone detection system: A cable modem clone detection system uses a cable modem media access control (MAC) address and physical location information such as information relating to a cable interface, upstream and downstream port numbers, fiber node information, and load balancing group descriptors to determine if a cable modem is a clone. The hierarchical approach first make a clone determination at a cable modem termination system, then at a regional operations center and finally at a network operations center.Type: GrantFiled: August 16, 2006Date of Patent: June 7, 2011Assignee: Cisco Technology, Inc.Inventors: Shengyou Zeng, Hemant Singh
-
Publication number: 20110066855Abstract: An extensible authentication framework is used in cable networks such as Data Over Cable Service Interface Specification (DOCSIS) cable networks. The authentication scheme allows for centralized authentication of cable modems, as well as authentication of the cable network by cable modems. Additionally, the authentication scheme allows a Cable Modem Termination System (CMTS) to authenticate devices downstream from cable modems, such as Customer Premise Equipment (CPE) devices.Type: ApplicationFiled: November 22, 2010Publication date: March 17, 2011Applicant: Cisco Technology, Inc.Inventors: Shengyou Zeng, Jason Frazier, Joshua B. Littlefield, Joseph A. Salowey
-
Patent number: 7865727Abstract: An extensible authentication framework is used in cable networks such as Data Over Cable Service Interface Specification (DOCSIS) cable networks. The authentication scheme allows for centralized authentication of cable modems, as well as authentication of the cable network by cable modems. Additionally, the authentication scheme allows a Cable Modem Termination System (CMTS) to authenticate devices downstream from cable modems, such as Customer Premise Equipment (CPE) devices.Type: GrantFiled: August 24, 2006Date of Patent: January 4, 2011Assignee: Cisco Technology, Inc.Inventors: Shengyou Zeng, Jason Frazier, Joshua B. Littlefield, Joseph A. Salowey
-
Patent number: 7835274Abstract: A provisioning server has a port to receive a request for a network address including an indication that a remote device is wideband capable. The provisioning server also has a processor to respond to the request with a network address and include an address for a configuration file and to provide a configuration file that allows wideband service. A cable modem has a port to request a network address and indicate wideband capability. The cable modem also has a processor to receive a response to that request that includes a network address and an address for a configuration file. The processor also receives a configuration file and allows the cable modem to be configured for wideband service.Type: GrantFiled: May 25, 2005Date of Patent: November 16, 2010Assignee: Cisco Technology, Inc.Inventors: John T. Chapman, Alon Shlomo Bernstein, Jin Zhang, William Guckel, Shengyou Zeng
-
Publication number: 20090125957Abstract: A CMTS or other data aggregation component having a DHCPv6 relay agent extracts a Media Access Control (MAC) address of an end device from a data packet received from an end device. A DHCPv6 data frame is created for transmission to a DHCPv6 server. The MAC address may be inserted into a specific option of the DHCPv6 data frame, where data in the option may not be processed by the server and are echoed back to the aggregation component or CMTS. The DHCPv6 data frame is transmitted to the DHCPv6 server. The component receives a response message from the server that may contain the MAC address or similar client hardware address as it was sent to the server by the network component. The network component may determine an outgoing port interface from which the response message should be sent, utilizing the MAC address and an interface bundling table. In this manner, interface bundling may be enabled.Type: ApplicationFiled: November 14, 2007Publication date: May 14, 2009Applicant: CISCO TECHNOLOGY, INC.Inventors: Hemant SINGH, Madhu SUDAN, Shengyou ZENG
-
Publication number: 20080126540Abstract: A hierarchical cable modem clone detection system: A cable modem clone detection system uses a cable modem media access control (MAC) address and physical location information such as information relating to a cable interface, upstream and downstream port numbers, fiber node information, and load balancing group descriptors to determine if a cable modem is a clone.Type: ApplicationFiled: August 16, 2006Publication date: May 29, 2008Applicant: CISCO TECHNOLOGY, INC.Inventors: SHENGYOU ZENG, HEMANT SINGH
-
Publication number: 20080065883Abstract: An extensible authentication framework is used in cable networks such as Data Over Cable Service Interface Specification (DOCSIS) cable networks. The authentication scheme allows for centralized authentication of cable modems, as well as authentication of the cable network by cable modems. Additionally, the authentication scheme allows a Cable Modem Termination System (CMTS) to authenticate devices downstream from cable modems, such as Customer Premise Equipment (CPE) devices.Type: ApplicationFiled: August 24, 2006Publication date: March 13, 2008Applicant: CISCO TECHNOLOGY, INC.Inventors: Shengyou Zeng, Jason Frazier, Joshua B. Littlefield, Joseph A. Salowey
-
Publication number: 20080028437Abstract: A system that eliminates some of the security vulnerabilities in the prior art systems by using a new sequence of steps to perform initialization of the cable modem: Instead of performing authentication after the cable modem has been registered, the cable modem authentication step is performed immediately after the cable modem completes ranging. Thus an early authentication method and system are provided. The control of authentication is shifted from the cable modem to the CMTS. Instead of the CMTS relying on a Registration Request message (REG-REQ) to determine whether a cable modem must perform authentication (that is to determine if BPI+ is enabled) the CMTS configuration is what determines whether a cable modem must perform authentication.Type: ApplicationFiled: July 27, 2006Publication date: January 31, 2008Applicant: CISCO TECHNOLOGY, INC.Inventor: SHENGYOU ZENG
-
Publication number: 20070220598Abstract: The innovation discloses an AAA-based key/credential distribution system and methodology that is enhanced for establishing a trust relationship between an end device and network application servers which are known at the time of end device authentication. This enhancement can reduce the complexity of key distribution while increasing performance and computational efficiency. By using information that is typically accessible to an AAA server with respect to which instance of a service a client should use based upon load, location, etc., the subject innovation can proactively distribute credentials to an end device. This proactive distribution enables the end device to directly prompt authentication with a network entity.Type: ApplicationFiled: June 16, 2006Publication date: September 20, 2007Applicant: CISCO SYSTEMS, INC.Inventors: Joseph Salowey, Shengyou Zeng
-
Publication number: 20060002294Abstract: A provisioning server has a port to receive a request for a network address including an indication that a remote device is wideband capable. The provisioning server also has a processor to respond to the request with a network address and include an address for a configuration file and to provide a configuration file that allows wideband service. A cable modem has a port to request a network address and indicate wideband capability. The cable modem also has a processor to receive a response to that request that includes a network address and an address for a configuration file. The processor also receives a configuration file and allows the cable modem to be configured for wideband service.Type: ApplicationFiled: May 25, 2005Publication date: January 5, 2006Inventors: John Chapman, Alon Bernstein, Jin Zhang, William Guckel, Shengyou Zeng