Patents by Inventor Tal Shustak

Tal Shustak has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 9239915
    Abstract: In network access controlled networks, it is desirable to prevent access to the network by any non-authenticated entities. Access control may be established through a trusted agent that, in some embodiments, may be implemented with a management co-processor. In some cases, active management technology may establish a connection while a host is inactive. Then, after the host becomes active, the host can attempt to use the management co-processor connection without obtaining the necessary authentications. This may be prevented, in some embodiments, by scanning for an active host and, if such an active host is found, blocking the host from using a layer 2 authentication channel unless the host is properly authenticated and has a proper Internet Protocol address.
    Type: Grant
    Filed: September 26, 2007
    Date of Patent: January 19, 2016
    Assignee: Intel Corporation
    Inventors: Avigdor Eldar, Tal Roth, Hormuzd Khosravi, Tal Shustak, Yael Yanai
  • Patent number: 9178884
    Abstract: In network access control networks, it may be difficult to provide certain remote accesses such as remote boot or remote storage access. An available network connection established through chipset firmware (e.g. active management technology (AMT)) may be utilized to establish a connection and to enable the remote access. Then as soon the completion of the activity is detected, such as remote booting, then the connection may be immediately terminated to prevent access by improper agents.
    Type: Grant
    Filed: September 7, 2007
    Date of Patent: November 3, 2015
    Assignee: Intel Corporation
    Inventors: Hormuzd Khosravi, Venkat R. Gokulrangan, Tal Shustak, Avigdor Eldar
  • Patent number: 8607058
    Abstract: In an embodiment, a method is provided. The method of this embodiment provides detecting failure of a first device on a system to authenticate the system through a controlled port from which a service is requested; and using a second device on the system to authenticate the system through the controlled port, the second device sharing a link with the first device.
    Type: Grant
    Filed: September 29, 2006
    Date of Patent: December 10, 2013
    Assignee: Intel Corporation
    Inventors: Avigdor Eldar, Eran Rousseau, Tal Shustak
  • Publication number: 20090083844
    Abstract: In network access controlled networks, it is desirable to prevent access to the network by any non-authenticated entities. Access control may be established through a trusted agent that, in some embodiments, may be implemented with a management co-processor. In some cases, active management technology may establish a connection while a host is inactive. Then, after the host becomes active, the host can attempt to use the management co-processor connection without obtaining the necessary authentications. This may be prevented, in some embodiments, by scanning for an active host and, if such an active host is found, blocking the host from using a layer 2 authentication channel unless the host is properly authenticated and has a proper Internet Protocol address.
    Type: Application
    Filed: September 26, 2007
    Publication date: March 26, 2009
    Inventors: Avigdor Eldar, Tal Roth, Hormuzd Khosravi, Tal Shustak, Yael Yanai
  • Publication number: 20090070467
    Abstract: In network access control networks, it may be difficult to provide certain remote accesses such as remote boot or remote storage access. An available network connection established through chipset firmware (e.g. active management technology (AMT)) may be utilized to establish a connection and to enable the remote access. Then as soon the completion of the activity is detected, such as remote booting, then the connection may be immediately terminated to prevent access by improper agents.
    Type: Application
    Filed: September 7, 2007
    Publication date: March 12, 2009
    Inventors: Hormuzd Khosravi, Venkat R. Gokulrangan, Tal Shustak, Avigdor Eldar
  • Publication number: 20080080373
    Abstract: In an embodiment, a method is provided. The method of this embodiment provides detecting failure of a first device on a system to authenticate the system through a controlled port from which a service is requested; and using a second device on the system to authenticate the system through the controlled port, the second device sharing a link with the first device.
    Type: Application
    Filed: September 29, 2006
    Publication date: April 3, 2008
    Inventors: Avigdor Eldar, Eran Rousseau, Tal Shustak
  • Patent number: 7181527
    Abstract: A method for transmitting load balancing in mixed speed environments such as physical interface speed changes and client flow speed changes is disclosed. Components such as an association module, a flow redirector, a channel assignment module, and a balancing timer are employed. The association module is a data structure that contains an association between client connections and a network interface. The flow redirector redirects transmitted network packets to the network interfaces based on the data, which is provided by the load balancing association. The channel assignment module is advised when such association data does not exist. The channel assignment module creates the association between the client connection- and the network interface, which is stored in the load balancing association. The decisions that this module makes affect the actual balancing between the network interfaces. The balancing timer computes throughput for client flows and re-associates client flows to the network interfaces.
    Type: Grant
    Filed: March 29, 2002
    Date of Patent: February 20, 2007
    Assignee: Intel Corporation
    Inventors: Moshe Valenci, Tal Shustak, Gil Baruch, Rony Bitan
  • Publication number: 20030217172
    Abstract: A method for transmitting load balancing in mixed speed environments such as physical interface speed changes and client flow speed changes is disclosed. Components such as an association module, a flow redirector, a channel assignment module, and a balancing timer are employed. The association module is a data structure that contains an association between client connections and a network interface. The flow redirector redirects transmitted network packets to the network interfaces based on the data, which is provided by the load balancing association. The channel assignment module is advised when such association data does not exist. The channel assignment module creates the association between the client connection- and the network interface, which is stored in the load balancing association. The decisions that this module makes affect the actual balancing between the network interfaces. The balancing timer computes throughput for client flows and re-associates client flows to the network interfaces.
    Type: Application
    Filed: March 29, 2002
    Publication date: November 20, 2003
    Applicant: INTEL CORPORATION
    Inventors: Moshe Valenci, Tal Shustak, Gil Baruch, Rony Bitan