Patents by Inventor Vijay Chander
Vijay Chander has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12683929Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for configuring resources of a service distributed across multiple cloud service providers. A method includes: receiving a request to configure a firewall in a cloud service provider, the request including a tag including a name that identifies a single firewall configuration information; and providing derived firewall information from the single firewall configuration information based on an identity of the cloud service provider and the tag, wherein the single firewall configuration information includes network information for connecting the firewall to a private network in the cloud service provider.Type: GrantFiled: April 3, 2024Date of Patent: July 14, 2026Assignee: Cisco Technology, Inc.Inventors: Ganesh Narayanaswamy, Praveen Kumar Patnala, Sreenivasa Kiran Madabhushi, Vijay Chander
-
Patent number: 12647396Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for inventory monitoring in a multi-cloud network environment. A method includes receiving user input via a controller's interface, wherein the input includes first account information granting access to a first virtual private cloud and a second virtual private cloud, both hosted by a cloud service provider (CSP). The controller queries the first and second virtual private clouds using the respective account information and the CSP's APIs to identify resources, gathering them into an inventory, and maintains a mapping of tags to the resources, associating each tag with a specific security policy. The controller forwards a first subset of tag-resource mappings to a first security gateway in the first virtual private cloud, enabling automatic application of corresponding security policies upon instantiation of tagged resources.Type: GrantFiled: April 3, 2024Date of Patent: June 2, 2026Assignee: Cisco Technology, Inc.Inventors: Praveen Kumar Patnala, Ganesh Narayanaswamy, Shaobo Liu, Mark Landgrebe, Vijay Chander, Vishal Jain
-
Patent number: 12574395Abstract: A method is described for inspecting data flows within a cloud-based gateway. The method involves receiving a data flow containing data packets at the gateway and subjecting the data packets to analysis using one or more inspection services to identify a threat signature. Upon detection of the threat signature, the method includes capturing the data packets marked with the threat signature in a temporary storage, specifically, a packet capture file within the gateway. Subsequently, the data packets bearing the detected threat signature in the temporary storage are transmitted to a persistent cloud storage. The temporary storage is purged of any remaining data packets unrelated to the threat signature, ensuring that data packets associated with the identified threat signature are preserved in the persistent cloud storage. The stored data packets are formatted in any format, including a HAR or PCAP format within the persistent cloud storage.Type: GrantFiled: April 2, 2024Date of Patent: March 10, 2026Assignee: Cisco Technology, Inc.Inventors: Ganesh Narayanaswamy, Vijay Chander, Mark Landgrebe
-
Publication number: 20250379811Abstract: The present technology provides intercloud connectivity as a service by discovering components of the organization's deployment in various sites, irrespective of the cloud provider, such that two sites can merely be selected along with a few standard options, and the controller can handle the complexity of instantiating a tunnel between the cloud sites automatically. Further, the controller can monitor the health of one or more tunnels between the cloud sites to automatically scale bandwidth up or down.Type: ApplicationFiled: August 25, 2025Publication date: December 11, 2025Inventors: Vijay Chander, Raghu Ram Duddumpudi, Ganesh Narayanaswamy, Sunil Kumar, Michael Chan, Praveen Kumar Patnala
-
Publication number: 20250317419Abstract: A network device may receive one or more first user inputs in a security gateway creation user interface (UI) provided by a controller. A network device may query, by the controller, the CSP using Application Programming Interfaces (APIs) to retrieve information about applications within the at least one virtualized network environment including any services deployed within the at least one virtualized network environment. A network device may present a security status user interface that identifies the at least one virtualized network environment applications configured in the CSP account and a respective status indicating whether the at least one virtualized network environment is protected by the security gateway. A network device may receive a second user input within the security status user interface, the second user input is effective to enable protection of the at least one virtualized network environment by the security gateway.Type: ApplicationFiled: April 3, 2024Publication date: October 9, 2025Inventors: Ganesh Narayanaswamy, Praveen Kumar Patnala, Sreenivasa Kiran Madabhushi, Vijay Chander
-
Publication number: 20250310353Abstract: A method is described for inspecting data flows within a cloud-based gateway. The method involves receiving a data flow containing data packets at the gateway and subjecting the data packets to analysis using one or more inspection services to identify a threat signature. Upon detection of the threat signature, the method includes capturing the data packets marked with the threat signature in a temporary storage, specifically, a packet capture file within the gateway. Subsequently, the data packets bearing the detected threat signature in the temporary storage are transmitted to a persistent cloud storage. The temporary storage is purged of any remaining data packets unrelated to the threat signature, ensuring that data packets associated with the identified threat signature are preserved in the persistent cloud storage. The stored data packets are formatted in any format, including a HAR or PCAP format within the persistent cloud storage.Type: ApplicationFiled: April 2, 2024Publication date: October 2, 2025Inventors: Ganesh Narayanaswamy, Vijay Chander, Mark Landgrebe
-
Patent number: 12425329Abstract: The present technology provides intercloud connectivity as a service by discovering components of the organization's deployment in various sites, irrespective of the cloud provider, such that two sites can merely be selected along with a few standard options, and the controller can handle the complexity of instantiating a tunnel between the cloud sites automatically. Further, the controller can monitor the health of one or more tunnels between the cloud sites to automatically scale bandwidth up or down.Type: GrantFiled: April 2, 2024Date of Patent: September 23, 2025Assignee: Cisco Technology, Inc.Inventors: Vijay Chander, Raghu Ram Duddumpudi, Ganesh Narayanaswamy, Sunil Kumar, Michael Chan, Praveen Kumar Patnala
-
Publication number: 20250193020Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for secure cluster membership for a multi-cloud security platform. A method includes: in response to receiving a start message to start a first instance of a gateway service, transmitting a boot message to a cloud service provider to cause the cloud service provider to boot an image corresponding to the gateway service, the boot message including boot script information; receiving a join message from the first instance to join a gateway service cluster; and configuring the first instance with the gateway service cluster based on credentials included in the join message.Type: ApplicationFiled: April 22, 2024Publication date: June 12, 2025Inventors: Praveen Kumar Patnala, Ganesh Narayanaswamy, Sunil Kumar, Vijay Chander, Radha Krishna Pagadala
-
Publication number: 20250193155Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for configuring resources of a service distributed across multiple cloud service providers. A method includes: receiving a request to configure a firewall in a cloud service provider, the request including a tag including a name that identifies a single firewall configuration information; and providing derived firewall information from the single firewall configuration information based on an identity of the cloud service provider and the tag, wherein the single firewall configuration information includes network information for connecting the firewall to a private network in the cloud service provider.Type: ApplicationFiled: April 3, 2024Publication date: June 12, 2025Inventors: Ganesh Narayanaswamy, Praveen Kumar Patnala, Sreenivasa Kiran Madabhushi, Vijay Chander
-
Publication number: 20250193249Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for inventory monitoring in a multi-cloud network environment. A method includes receiving user input via a controller's interface, wherein the input includes first account information granting access to a first virtual private cloud and a second virtual private cloud, both hosted by a cloud service provider (CSP). The controller queries the first and second virtual private clouds using the respective account information and the CSP's APIs to identify resources, gathering them into an inventory, and maintains a mapping of tags to the resources, associating each tag with a specific security policy. The controller forwards a first subset of tag-resource mappings to a first security gateway in the first virtual private cloud, enabling automatic application of corresponding security policies upon instantiation of tagged resources.Type: ApplicationFiled: April 3, 2024Publication date: June 12, 2025Inventors: Praveen Kumar Patnala, Ganesh Narayanaswamy, Shaobo Liu, Mark Landgrebe, Vijay Chander, Vishal Jain
-
Publication number: 20250193152Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for zero-trust IP address resolution in cloud services. A method includes: receiving, at an egress node of a network, a network request from a client device within the network, the network request including a first domain name and a first IP address; in response to receiving the network request, resolving a second IP address based on the first domain name; and inserting the second IP address into the network request in place of the first IP address.Type: ApplicationFiled: April 26, 2024Publication date: June 12, 2025Inventors: Sreenivasa Kiran Madabhushi, Vijay Chander, Ganesh Narayanaswamy, Praveen Kumar Patnala, Sunil Kumar
-
Publication number: 20250193151Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for machine learning of data path rules for gateway services.Type: ApplicationFiled: March 26, 2024Publication date: June 12, 2025Inventors: Sunil Kumar, Praveen Kumar Patnala, Vijay Chander
-
Publication number: 20250193561Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for asynchronous execution of data path service using network fibers. A method includes: based on receiving a first packet within a service for transmitting the first packet to a destination location, processing a first portion of the first packet in a processor based on execution of a first fiber until a first hardware call is reached; sending the first packet to a first circuit for processing the first packet based on the first hardware call; and processing a portion of a second packet associated with a second fiber while the first packet is processing in the first circuit. The systems and apparatuses prevent heavy processing of content from blocking other content.Type: ApplicationFiled: April 2, 2024Publication date: June 12, 2025Inventors: Sunil Kumar, Vijay Chander
-
Publication number: 20250193231Abstract: Disclosed are systems, apparatuses, methods, and computer-readable media for line rate inspection of hypertext transfer protocol (HTTP) content in a network appliance. A method includes: receiving packets in a data center that are in transit to an application programming interface (API) endpoint of an application; analyzing content in an HTTP request in each packet for malicious content; and dropping at least one packet based on identification of the malicious content in the content. The systems and apparatuses can inspect HTTP at line rate based on the disclosed analyses.Type: ApplicationFiled: March 26, 2024Publication date: June 12, 2025Inventors: Vijay Chander, Praveen Kumar Patnala, Anshu Sanghi
-
Publication number: 20250112849Abstract: The present technology provides intercloud connectivity as a service by discovering components of the organization's deployment in various sites, irrespective of the cloud provider, such that two sites can merely be selected along with a few standard options, and the controller can handle the complexity of instantiating a tunnel between the cloud sites automatically. Further, the controller can monitor the health of one or more tunnels between the cloud sites to automatically scale bandwidth up or down.Type: ApplicationFiled: April 2, 2024Publication date: April 3, 2025Inventors: Vijay Chander, Raghu Ram Duddumpudi, Ganesh Narayanaswamy, Sunil Kumar, Michael Chan, Praveen Kumar Patnala
-
Patent number: 12021826Abstract: According to one or more embodiments of this disclosure, a network controller in a data center network establishes a translation table for in-band traffic in a data center network, the translation table resolves ambiguous network addresses based on one or more of a virtual network identifier (VNID), a routable tenant address, or a unique loopback address. The network controller device receives packets originating from applications and/or an endpoints operating in a network segment associated with a VNID. The network controller device translates, using the translation table, unique loopback addresses and/or routable tenant addresses associated with the packets into routable tenant addresses and/or unique loopback addresses, respectively.Type: GrantFiled: December 21, 2022Date of Patent: June 25, 2024Assignee: Cisco Technology, Inc.Inventors: Vijay Chander, Yibin Yang, Praveen Jain, Munish Mehta
-
Publication number: 20230300105Abstract: According to one or more embodiments of this disclosure, a network controller in a data center network establishes a translation table for in-band traffic in a data center network, the translation table resolves ambiguous network addresses based on one or more of a virtual network identifier (VNID), a routable tenant address, or a unique loopback address. The network controller device receives packets originating from applications and/or an endpoints operating in a network segment associated with a VNID. The network controller device translates, using the translation table, unique loopback addresses and/or routable tenant addresses associated with the packets into routable tenant addresses and/or unique loopback addresses, respectively.Type: ApplicationFiled: December 21, 2022Publication date: September 21, 2023Inventors: Vijay Chander, Yibin Yang, Praveen Jain, Munish Mehta
-
Patent number: 11546288Abstract: According to one or more embodiments of this disclosure, a network controller in a data center network establishes a translation table for in-band traffic in a data center network, the translation table resolves ambiguous network addresses based on one or more of a virtual network identifier (VNID), a routable tenant address, or a unique loopback address. The network controller device receives packets originating from applications and/or an endpoints operating in a network segment associated with a VNID. The network controller device translates, using the translation table, unique loopback addresses and/or routable tenant addresses associated with the packets into routable tenant addresses and/or unique loopback addresses, respectively.Type: GrantFiled: February 11, 2021Date of Patent: January 3, 2023Assignee: Cisco Technology, Inc.Inventors: Vijay Chander, Yibin Yang, Praveen Jain, Munish Mehta
-
Patent number: 11457047Abstract: A computer-implemented method of managing security services for one or more cloud computing platforms is disclosed. The method comprises receiving, by a security gateway system having a processor, a digital communication related to one of one or more computing applications hosted by a virtual cluster for private use on a cloud computing platform, the security gateway system residing within the cloud computing platform, the security gateway system performing network security gateway functions for the one or more computing applications. The method also comprises storing the digital communication in association with a timestamp in a storage device. The method further comprises receiving a piece of threat intelligence data indicating a security threat from a main controller residing outside the virtual cluster; storing the piece of threat intelligence data in a database; and determining whether the piece of threat intelligence data applies to any of the digital communications in the storage device.Type: GrantFiled: March 9, 2021Date of Patent: September 27, 2022Assignee: VALTIX, INC.Inventors: Vijay Chander, Praveen Patnala, Vishal Jain
-
Publication number: 20210218777Abstract: A computer-implemented method of managing security services for one or more cloud computing platforms is disclosed. The method comprises receiving, by a security gateway system having a processor, a digital communication related to one of one or more computing applications hosted by a virtual cluster for private use on a cloud computing platform, the security gateway system residing within the cloud computing platform, the security gateway system performing network security gateway functions for the one or more computing applications. The method also comprises storing the digital communication in association with a timestamp in a storage device. The method further comprises receiving a piece of threat intelligence data indicating a security threat from a main controller residing outside the virtual cluster; storing the piece of threat intelligence data in a database; and determining whether the piece of threat intelligence data applies to any of the digital communications in the storage device.Type: ApplicationFiled: March 9, 2021Publication date: July 15, 2021Inventors: Vijay CHANDER, Praveen PATNALA, Vishal JAIN