Patents by Inventor Sulay Shah

Sulay Shah has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 11812273
    Abstract: Disclosed are various examples for managing network resource permissions for applications through the use of an application catalog. An identification of a particular application from the application catalog is received from a managed client device. The identification indicates a particular security group of multiple security groups. A network of the organization is configured to provide the particular application on the managed client device with access to a set of resources corresponding to the particular security group.
    Type: Grant
    Filed: May 10, 2021
    Date of Patent: November 7, 2023
    Assignee: AirWatch, LLC
    Inventors: Sulay Shah, Noah Wasmer
  • Patent number: 11546335
    Abstract: Techniques for managing permissions to cloud-based resources with session-specific attributes are described. A first request to create a first session to permit access to resources of a provider network is received under an assumed role. The first request is permitted based on an evaluation of a rule associated with the role. Session data including a user-specified attribute included with the first request is generated. A second request to perform an action with a resource hosted by the provider network is received. The user-specified attribute is obtained from the session data based at least in part on the second request. The second request is permitted based on an evaluation of another rule with the user-specified attribute.
    Type: Grant
    Filed: September 27, 2019
    Date of Patent: January 3, 2023
    Assignee: Amazon Technologies, Inc.
    Inventors: Rachit Jain, Sulay Shah, Conor Cahill, Praveen Akinapally, Ian Leung, Rohit Raj, Brigid Johnson
  • Publication number: 20220174046
    Abstract: Disclosed are various examples for configuring network security based on device management characteristics. In one example, a specification of a set of network resources on an internal network is received from an administrator client. The set of network resources are those network resources that a particular application executed in client devices on an external network should be authorized to access. A gateway from the external network to the internal network is then configured to permit the particular application to have access to the set of network resources.
    Type: Application
    Filed: February 21, 2022
    Publication date: June 2, 2022
    Inventors: CRAIG FARLEY NEWELL, SULAY SHAH, LEUNG TAO KWOK, ADAM RYKOWSKI
  • Patent number: 11290425
    Abstract: Disclosed are various examples for configuring network security based on device management characteristics. In one example, a specification of a set of network resources on an internal network is received from an administrator client. The set of network resources are those network resources that a particular application executed in client devices on an external network should be authorized to access. A gateway from the external network to the internal network is then configured to permit the particular application to have access to the set of network resources.
    Type: Grant
    Filed: February 1, 2016
    Date of Patent: March 29, 2022
    Assignee: AirWatch LLC
    Inventors: Craig Farley Newell, Sulay Shah, Leung Tao Kwok, Adam Rykowski
  • Publication number: 20210266749
    Abstract: Disclosed are various examples for managing network resource permissions for applications through the use of an application catalog. An identification of a particular application from the application catalog is received from a managed client device. The identification indicates a particular security group of multiple security groups. A network of the organization is configured to provide the particular application on the managed client device with access to a set of resources corresponding to the particular security group.
    Type: Application
    Filed: May 10, 2021
    Publication date: August 26, 2021
    Inventors: Sulay Shah, Noah Wasmer
  • Patent number: 11075777
    Abstract: Disclosed are various approaches for providing on-demand virtual private network (VPN) connectivity on a per-application basis. An application is determined to have begun execution on a computing device. The application is identified. A determination that the application is authorized to access a VPN connection is made, and the VPN connection is created.
    Type: Grant
    Filed: October 15, 2019
    Date of Patent: July 27, 2021
    Assignee: AIRWATCH LLC
    Inventors: Suman Aluvala, Craig Farley Newell, Naga Sandeep Reddy Kaipu, Sulay Shah
  • Patent number: 11032247
    Abstract: Disclosed are various examples for the use of network micro-segmentation in enterprise mobility management. In one example, a network device receives a packet with one or mote device management attribute embedded in its header. The network device extracts the device management attribute from the packet header. A compliance status of a client device in an external network is determined based on the device management attribute. The network device forwards the packet based on the compliance status.
    Type: Grant
    Filed: December 3, 2019
    Date of Patent: June 8, 2021
    Assignee: AIRWATCH LLC
    Inventors: Craig Farley Newell, Sulay Shah, Adam Rykowski, Leung Tao Kwok
  • Patent number: 11006278
    Abstract: Disclosed are various examples for managing network resource permissions for applications through the use of an application catalog. A user interface presenting an application catalog is generated that includes a listing of applications that are available to managed client devices in an organization. A selection of a particular application from the application catalog is received from a managed client device. The selection indicates a particular security group of multiple security groups. A network of the organization is configured to provide the particular application on the managed client device with access to a set of resources corresponding to the particular security group.
    Type: Grant
    Filed: November 19, 2015
    Date of Patent: May 11, 2021
    Assignee: AirWatch LLC
    Inventors: Sulay Shah, Noah Wasmer
  • Publication number: 20210099450
    Abstract: Techniques for managing permissions to cloud-based resources with session-specific attributes are described. A first request to create a first session to permit access to resources of a provider network is received under an assumed role. The first request is permitted based on an evaluation of a rule associated with the role. Session data including a user-specified attribute included with the first request is generated. A second request to perform an action with a resource hosted by the provider network is received. The user-specified attribute is obtained from the session data based at least in part on the second request. The second request is permitted based on an evaluation of another rule with the user-specified attribute.
    Type: Application
    Filed: September 27, 2019
    Publication date: April 1, 2021
    Inventors: Rachit JAIN, Sulay SHAH, Conor CAHILL, Praveen AKINAPALLY, Ian LEUNG, Rohit RAJ, Brigid Johnson
  • Publication number: 20200106748
    Abstract: Disclosed are various examples for the use of network micro-segmentation in enterprise mobility management. In one example, a network device receives a packet with one or mote device management attribute embedded in its header. The network device extracts the device management attribute from the packet header. A compliance status of a client device in an external network is determined based on the device management attribute. The network device forwards the packet based on the compliance status.
    Type: Application
    Filed: December 3, 2019
    Publication date: April 2, 2020
    Inventors: CRAIG FARLEY NEWELL, SULAY SHAH, ADAM RYKOWSKI, LEUNG TAO KWOK
  • Publication number: 20200044893
    Abstract: Disclosed are various approaches for providing on-demand virtual private network (VPN) connectivity on a per-application basis. An application is determined to have begun execution on a computing device. The application is identified. A determination that the application is authorized to access a VPN connection is made, and the VPN connection is created.
    Type: Application
    Filed: October 15, 2019
    Publication date: February 6, 2020
    Inventors: Suman Aluvala, Craig Farley Newell, Naga Sandeep Reddy Kaipu, Sulay Shah
  • Patent number: 10523636
    Abstract: Disclosed are various examples for the use of network micro-segmentation in enterprise mobility management. In one example, a gateway receives network traffic from a client device through a virtual private network (VPN) tunnel. The gateway determines one or more device management attributes associated with the client device in response to receiving the network traffic. The gateway then determines a particular network virtual segment based at least in part on the device management attribute(s). The gateway forwards the network traffic to the particular virtual network segment.
    Type: Grant
    Filed: February 4, 2016
    Date of Patent: December 31, 2019
    Assignee: AIRWATCH LLC
    Inventors: Craig Farley Newell, Sulay Shah, Adam Rykowski, Leung Tao Kwok
  • Patent number: 10476916
    Abstract: Disclosed are various approaches for providing on-demand virtual private network (VPN) connectivity on a per-application basis. First, an application is determined to have begun execution on a computing device. The application is then identified. A determination that the application is authorized to access a VPN connection is made. Subsequently, the VPN connection is initiated.
    Type: Grant
    Filed: February 18, 2016
    Date of Patent: November 12, 2019
    Assignee: AIRWATCH LLC
    Inventors: Suman Aluvala, Craig Farley Newell, Naga Sandeep Reddy Kaipu, Sulay Shah
  • Patent number: 9894103
    Abstract: Some embodiments provide novel methods for processing remote-device data messages in a network based on data-message attributes from a remote device management (RDM) system. For instance, the method of some embodiments identifies a set of RDM attributes associated with a data message, and then performs one or more service operations based on identified RDM attribute set.
    Type: Grant
    Filed: November 1, 2015
    Date of Patent: February 13, 2018
    Assignee: NICIRA, INC.
    Inventors: Leung Tao Kwok, Sulay Shah, Craig Newell, Adam Rykowski, Sridhar Kommireddy, Utkarsh Singh, Sagar Date, Kausum Kumar, Anirban Sengupta, Srinivas Nimmagadda, Jayant Jain, Uday Masurekar, Ravishankar Chamarajnagar
  • Publication number: 20170230334
    Abstract: Disclosed are various examples for the use of network micro-segmentation in enterprise mobility management. In one example, a gateway receives network traffic from a client device through a virtual private network (VPN) tunnel. The gateway determines one or more device management attributes associated with the client device in response to receiving the network traffic. The gateway then determines a particular network virtual segment based at least in part on the device management attribute(s). The gateway forwards the network traffic to the particular virtual network segment.
    Type: Application
    Filed: February 4, 2016
    Publication date: August 10, 2017
    Inventors: CRAIG FARLEY NEWELL, SULAY SHAH, ADAM RYKOWSKI, LEUNG TAO KWOK
  • Publication number: 20170222977
    Abstract: Disclosed are various examples for configuring network security based on device management characteristics. In one example, a specification of a set of network resources on an internal network is received from an administrator client. The set of network resources are those network resources that a particular application executed in client devices on an external network should be authorized to access. A gateway from the external network to the internal network is then configured to permit the particular application to have access to the set of network resources.
    Type: Application
    Filed: February 1, 2016
    Publication date: August 3, 2017
    Inventors: CRAIG FARLEY NEWELL, SULAY SHAH, LEUNG TAO KWOK, ADAM RYKOWSKI
  • Publication number: 20170147157
    Abstract: Disclosed are various examples for managing network resource permissions for applications through the use of an application catalog. A user interface presenting an application catalog is generated that includes a listing of applications that are available to managed client devices in an organization. A selection of a particular application from the application catalog is received from a managed client device. The selection indicates a particular security group of multiple security groups. A network of the organization is configured to provide the particular application on the managed client device with access to a set of resources corresponding to the particular security group.
    Type: Application
    Filed: November 19, 2015
    Publication date: May 25, 2017
    Inventors: Sulay Shah, Noah Wasmer
  • Publication number: 20170078336
    Abstract: Disclosed are various approaches for providing on-demand virtual private network (VPN) connectivity on a per-application basis. First, an application is determined to have begun execution on a computing device. The application is then identified. A determination that the application is authorized to access a VPN connection is made. Subsequently, the VPN connection is initiated.
    Type: Application
    Filed: February 18, 2016
    Publication date: March 16, 2017
    Inventors: SUMAN ALUVALA, CRAIG FARLEY NEWELL, NAGA SAN DEEP REDDY KAIPU, SULAY SHAH
  • Publication number: 20170063787
    Abstract: Some embodiments provide novel methods for processing remote-device data messages in a network based on data-message attributes from a remote device management (RDM) system. For instance, the method of some embodiments identifies a set of RDM attributes associated with a data message, and then performs one or more service operations based on identified RDM attribute set.
    Type: Application
    Filed: November 1, 2015
    Publication date: March 2, 2017
    Inventors: Leung Tao Kwok, Sulay Shah, Craig Newell, Adam Rykowski, Sridhar Kommireddy, Utkarsh Singh, Sagar Date, Kausum Kumar, Anirban Sengupta, Srinivas Nimmagadda, Jayant Jain, Uday Masurekar, Ravishankar Chamarajnagar
  • Publication number: 20050180326
    Abstract: A system and method for providing services such as Wake-on-LAN and PXE Boot services to a multi-subnet network system which includes router and/or firewalls between different subnets. This is accomplished by using a peer computer to provide the service when performing such service is required to be transmitted across the router and/or firewall. That is, the system determines whether the service is required to go across the router and/or firewall, and, if so, to identify a computer (a peer computer) which is located on the appropriate subnet, then deliver the service to that peer computer (if necessary) and have that peer computer perform the selected service, such as Wake-on-LAN.
    Type: Application
    Filed: February 13, 2004
    Publication date: August 18, 2005
    Inventors: Michael Goldflam, Jan Roger Jonsson, Juliano Maldaner, Sulay Shah, Frank Wang