Patents by Inventor Srihari Raghavan
Srihari Raghavan has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Publication number: 20250112921Abstract: Techniques and architecture are described for providing a configurable security posture for a network device using an extended ownership artifact, e.g., an ownership voucher, an ownership certificate, etc., and a security profile mechanism that scales to user needs and desires for security profiles on network devices, i.e., easily and securely customizable on thousands of nodes of a network. The configurable security posture may be achieved using the manufacturer authorized signing authority (MASA) to issue an ownership voucher with a security bit extension to support security profile additions. Using the MASA service, a user may explicitly decide on various security postures of a given network device and may apply that profile across the fixed or modular chassis of a network of network devices.Type: ApplicationFiled: December 12, 2024Publication date: April 3, 2025Inventors: Jabir Hamediya Mohammed, Reda Haddad, Srihari Raghavan, Sandesh K. Rao
-
Patent number: 12206664Abstract: Techniques and architecture are described for providing a configurable security posture for a network device using an extended ownership artifact, e.g., an ownership voucher, an ownership certificate, etc., and a security profile mechanism that scales to user needs and desires for security profiles on network devices, i.e., easily and securely customizable on thousands of nodes of a network. The configurable security posture may be achieved using the manufacturer authorized signing authority (MASA) to issue an ownership voucher with a security bit extension to support security profile additions. Using the MASA service, a user may explicitly decide on various security postures of a given network device and may apply that profile across the fixed or modular chassis of a network of network devices.Type: GrantFiled: May 16, 2022Date of Patent: January 21, 2025Assignee: Cisco Technology, Inc.Inventors: Jabir Hamediya Mohammed, Reda Haddad, Srihari Raghavan, Sandesh K. Rao
-
Patent number: 12067402Abstract: Techniques and architecture are described for validating and verifying iPXE scripts prior to execution during a booting process. During the booting process of a network device, right after the UEFI/BIOS stage of the booting process, a trusted iPXE script may make a request to a network server for the ownership voucher and owner certificate of the network device. The ownership voucher and owner certificate may then be stored in a trusted platform module (TPM) on the network device. In configurations, the retrieved owner certificate may be validated by the ownership voucher. The owner certificate may be used to validate iPXE scripts. Once validated, the iPXE scripts may be executed and the booting process may be continued to the kernel loading step and the application loading step. During a subsequent booting process of the network device, the ownership voucher and owner certificate may be retrieved from the TPM.Type: GrantFiled: September 13, 2022Date of Patent: August 20, 2024Assignee: Cisco Technology, Inc.Inventors: Reda Haddad, Martin Edward Ramsdale, Srihari Raghavan, Jabir Hamediya Mohammed, Sandesh K. Rao
-
Publication number: 20240086205Abstract: Techniques and architecture are described for validating and verifying iPXE scripts prior to execution during a booting process. During the booting process of a network device, right after the UEFI/BIOS stage of the booting process, a trusted iPXE script may make a request to a network server for the ownership voucher and owner certificate of the network device. The ownership voucher and owner certificate may then be stored in a trusted platform module (TPM) on the network device. In configurations, the retrieved owner certificate may be validated by the ownership voucher. The owner certificate may be used to validate iPXE scripts. Once validated, the iPXE scripts may be executed and the booting process may be continued to the kernel loading step and the application loading step. During a subsequent booting process of the network device, the ownership voucher and owner certificate may be retrieved from the TPM.Type: ApplicationFiled: September 13, 2022Publication date: March 14, 2024Inventors: Reda Haddad, Martin Edward Ramsdale, Srihari Raghavan, Jabir Hamediya Mohammed, Sandesh K. Rao
-
Patent number: 11862832Abstract: A modular fuel cell subsystem includes multiple rows of modules, where each row comprises a plurality of fuel cell power modules and a power conditioning module containing a DC to AC inverter electrically connected the power modules. In some embodiments, a single gas and water distribution module is fluidly connected to multiple rows of power modules, and a single mini power distribution module is electrically connected to each of the power conditioning module in each row of modules. In some embodiments, each row of modules further includes a fuel processing module located on an opposite side of the plurality of fuel cell power modules from the power conditioning module. Fuel and water connections may enter each row from the side of the row containing the fuel processing module, and electrical connections may enter each row from the side of the row containing the power conditioning module.Type: GrantFiled: July 28, 2022Date of Patent: January 2, 2024Assignee: BLOOM ENERGY CORPORATIONInventors: Srihari Raghavan, David Trevisan, Richard Leitch, Armando Gomez, Aaron Ells, Jessica Mahler
-
Publication number: 20230394493Abstract: In one embodiment, methods for mediated transfer of ownership are described. The method may include receiving a request for an ownership voucher from a device, validating an identifier of the device, determining whether to issue the ownership voucher, generating a signed ownership voucher, and sending the signed ownership voucher to the device. In another embodiment, methods for unmediated transfer of ownership are described, including receiving, an ownership voucher associated with a first ownership certificate, determining whether the ownership voucher comprises a signature associated with a manufacturer, based at least in part on determining that the signature of the manufacturer is absent, determining that a second ownership certificate is stored in memory, determining that the second ownership certificate comprises a signature associated with a user, validating the ownership voucher; and based at least in part on the validating, enrolling the first ownership certificate on the network device.Type: ApplicationFiled: June 2, 2022Publication date: December 7, 2023Inventors: Sandesh K. Rao, Reda Haddad, Srihari Raghavan, Jabir Hamediya Mohammed
-
Publication number: 20230370454Abstract: Techniques and architecture are described for providing a configurable security posture for a network device using an extended ownership artifact, e.g., an ownership voucher, an ownership certificate, etc., and a security profile mechanism that scales to user needs and desires for security profiles on network devices, i.e., easily and securely customizable on thousands of nodes of a network. The configurable security posture may be achieved using the manufacturer authorized signing authority (MASA) to issue an ownership voucher with a security bit extension to support security profile additions. Using the MASA service, a user may explicitly decide on various security postures of a given network device and may apply that profile across the fixed or modular chassis of a network of network devices.Type: ApplicationFiled: May 16, 2022Publication date: November 16, 2023Inventors: Jabir Hamediya Mohammed, Reda Haddad, Srihari Raghavan, Sandesh K. Rao
-
Publication number: 20230037162Abstract: A modular fuel cell subsystem includes multiple rows of modules, where each row comprises a plurality of fuel cell power modules and a power conditioning module containing a DC to AC inverter electrically connected the power modules. In some embodiments, a single gas and water distribution module is fluidly connected to multiple rows of power modules, and a single mini power distribution module is electrically connected to each of the power conditioning module in each row of modules. In some embodiments, each row of modules further includes a fuel processing module located on an opposite side of the plurality of fuel cell power modules from the power conditioning module. Fuel and water connections may enter each row from the side of the row containing the fuel processing module, and electrical connections may enter each row from the side of the row containing the power conditioning module.Type: ApplicationFiled: July 28, 2022Publication date: February 2, 2023Inventors: Srihari Raghavan, David Trevisan, Richard Leitch, Armando Gomez, Aaron Ells, Jessica Mahler
-
Patent number: 11245484Abstract: Systems, methods, and computer-readable media for authenticating time sources using attestation-based techniques include receiving, at a destination device, a time reference signal from a source device, the source and destination devices being network devices. The time reference signal can include a time synchronization signal or a time distribution signal. The destination device can obtain attestation information from one or more fields of the time reference signal and determine whether the source device is authentic and trustworthy based on the attestation information. The destination device can also determine reliability or freshness of the time reference signal based on the attestation information. The time reference signal can be based on a Network Time Protocol (NTP), a Precision Time Protocol (NTP), or other protocol.Type: GrantFiled: February 14, 2020Date of Patent: February 8, 2022Assignee: CISCO TECHNOLOGY, INC.Inventors: Shwetha Subray Bhandari, Frank Brockners, Srihari Raghavan
-
Publication number: 20200322075Abstract: Systems, methods, and computer-readable media for authenticating time sources using attestation-based techniques include receiving, at a destination device, a time reference signal from a source device, the source and destination devices being network devices. The time reference signal can include a time synchronization signal or a time distribution signal. The destination device can obtain attestation information from one or more fields of the time reference signal and determine whether the source device is authentic and trustworthy based on the attestation information. The destination device can also determine reliability or freshness of the time reference signal based on the attestation information. The time reference signal can be based on a Network Time Protocol (NTP), a Precision Time Protocol (NTP), or other protocol.Type: ApplicationFiled: February 14, 2020Publication date: October 8, 2020Inventors: Shwetha Subray Bhandari, Frank Brockners, Srihari Raghavan
-
Patent number: 10069708Abstract: In one embodiment, a method includes assigning a discriminator to a target in communication with a reflector at a network device, identifying at the reflector, a packet comprising the discriminator, the packet transmitted from an initiator in a seamless bidirectional forwarding detection (S-BFD) session, and transmitting a response packet from the reflector to the initiator. The response packet includes information for the target obtained by the reflector through monitoring of the target. The target may comprise a plurality of entities. An apparatus and logic are also disclosed herein.Type: GrantFiled: March 2, 2015Date of Patent: September 4, 2018Assignee: Cisco Technology, Inc.Inventors: Srihari Raghavan, Nobushige Akiya, Carlos M. Pignataro, Mallik Mudigonda, Nagendra Kumar Nainar
-
Publication number: 20160261474Abstract: In one embodiment, a method includes assigning a discriminator to a target in communication with a reflector at a network device, identifying at the reflector, a packet comprising the discriminator, the packet transmitted from an initiator in a seamless bidirectional forwarding detection (S-BFD) session, and transmitting a response packet from the reflector to the initiator. The response packet includes information for the target obtained by the reflector through monitoring of the target. The target may comprise a plurality of entities. An apparatus and logic are also disclosed herein.Type: ApplicationFiled: March 2, 2015Publication date: September 8, 2016Applicant: CISCO TECHNOLOGY, INC.Inventors: Srihari Raghavan, Nobushige Akiya, Carlos M. Pignataro, Mallik Mudigonda, Nagendra Kumar Nainar