-
公开(公告)号:US10079812B1
公开(公告)日:2018-09-18
申请号:US15078908
申请日:2016-03-23
Applicant: Juniper Networks Inc.
Inventor: Venkanna Thadishetty , Ravindranath C. Kanakarajan
CPC classification number: H04L63/0471 , G06F21/6209 , H04L9/0877 , H04L9/0897 , H04L9/3234 , H04L67/06 , H04L67/1097
Abstract: Techniques are disclosed for intercepting, by a customer-premises equipment (CPE), a request for a content file. The request may originate from a computing device in a local area network for the CPE and may be destined for a destination device external to the local area network for the CPE. In response to determining that an encrypted content file for the content file is stored by a storage device for the CPE, the CPE may decrypt, using at least one cryptographic key obtained from a Trusted Platform Module (TPM) for the CPE, the encrypted content file to obtain the content file. The CPE may send the content file to the computing device.
-
公开(公告)号:US10038591B1
公开(公告)日:2018-07-31
申请号:US14594062
申请日:2015-01-09
Applicant: Juniper Networks, Inc.
Inventor: Ravindranath C Kanakarajan , Venkanna Thadishetty
IPC: G06F15/177 , H04L12/24 , H04W64/00 , H04L29/06 , H04L9/32
CPC classification number: H04L41/08 , H04L9/005 , H04L9/3247 , H04L9/3297 , H04L41/0813 , H04L41/0893 , H04L41/28 , H04L63/107 , H04L63/123 , H04L63/126 , H04L63/20 , H04W64/003
Abstract: The disclosed apparatus may include an encryption device that signs information exchanged between network devices to ensure the integrity of the information. The disclosed apparatus may also include a network device communicatively coupled to the encryption device, wherein the network device (1) obtains geo-location information that identifies the location of the network device, (2) directs the encryption device to sign the geo-location information to ensure the integrity of the geo-location information, (3) provides the signed geo-location information to a remote management system that manages the configuration of the network device based at least in part on the geo-location information, and (4) receives a configuration profile that modifies the configuration of the network device to account for the current location of the network device from the remote management system. Various other apparatuses, systems, and methods are also disclosed.
-
公开(公告)号:US20180176077A1
公开(公告)日:2018-06-21
申请号:US15898207
申请日:2018-02-15
Applicant: Juniper Networks, Inc.
Inventor: Ravindranath C. Kanakarajan , Venkanna Thadishetty
CPC classification number: H04L41/08 , H04L9/005 , H04L9/3247 , H04L9/3297 , H04L41/0813 , H04L41/0893 , H04L41/28 , H04L63/107 , H04L63/123 , H04L63/126 , H04L63/20 , H04W64/003
Abstract: The disclosed apparatus may include an encryption device that signs information exchanged between network devices to ensure the integrity of the information. The disclosed apparatus may also include a network device communicatively coupled to the encryption device, wherein the network device (1) obtains geo-location information that identifies the location of the network device, (2) directs the encryption device to sign the geo-location information to ensure the integrity of the geo-location information, (3) provides the signed geo-location information to a remote management system that manages the configuration of the network device based at least in part on the geo-location information, and (4) receives a configuration profile that modifies the configuration of the network device to account for the current location of the network device from the remote management system. Various other apparatuses, systems, and methods are also disclosed.
-
公开(公告)号:US09838870B2
公开(公告)日:2017-12-05
申请号:US14668834
申请日:2015-03-25
Applicant: Juniper Networks, Inc.
Inventor: Ravindranath C Kanakarajan , Venkanna Thadishetty
CPC classification number: H04W12/06 , H04B7/1851 , H04L9/0825 , H04L9/32 , H04L9/3247 , H04L63/0281 , H04L63/0442 , H04L63/0876 , H04L63/0884 , H04L63/126 , H04L2209/24 , H04L2209/72 , H04W12/04 , H04W76/12
Abstract: The disclosed apparatus may include (1) a reply-reception module, stored in memory, that receives, from a satellite device, an authentication reply that includes an original authentication message digitally signed by the aggregation device using a private key of the aggregation device and that is digitally signed by the satellite device using a private key of the satellite device, (2) a forwarding module, stored in memory, that forwards the authentication reply to a network management server, (3) a validation-reception module, stored in memory, that receives, from the network management server in response to forwarding the authentication reply, a validation message, and (4) an authentication module, stored in memory, that authenticates the satellite device based at least in part on receiving the validation message. Various other apparatuses, systems, and methods are also disclosed.
-
公开(公告)号:US10397047B2
公开(公告)日:2019-08-27
申请号:US15898207
申请日:2018-02-15
Applicant: Juniper Networks, Inc.
Inventor: Ravindranath C Kanakarajan , Venkanna Thadishetty
Abstract: The disclosed apparatus may include an encryption device that signs information exchanged between network devices to ensure the integrity of the information. The disclosed apparatus may also include a network device communicatively coupled to the encryption device, wherein the network device (1) obtains geo-location information that identifies the location of the network device, (2) directs the encryption device to sign the geo-location information to ensure the integrity of the geo-location information, (3) provides the signed geo-location information to a remote management system that manages the configuration of the network device based at least in part on the geo-location information, and (4) receives a configuration profile that modifies the configuration of the network device to account for the current location of the network device from the remote management system. Various other apparatuses, systems, and methods are also disclosed.
-
公开(公告)号:US09893882B1
公开(公告)日:2018-02-13
申请号:US14569494
申请日:2014-12-12
Applicant: Juniper Networks, Inc.
Inventor: Venkanna Thadishetty
CPC classification number: G06F9/4406 , H04L9/0825 , H04L9/0897 , H04L9/3236 , H04L9/3247
Abstract: The disclosed apparatus may include a storage device that stores an asymmetric key pair including a public encryption key and a private encryption key assigned to a computing device. This apparatus may also include at least one processing unit communicatively coupled to the storage device. The processing unit may encrypt, via one key within the asymmetric key pair, a copy of identification information that identifies the computing device. The processing unit may then maintain the encrypted copy of the identification information and an unencrypted copy of the identification information in connection with the computing device. Next, the processing unit may detect evidence of device tampering in connection with the computing device by (1) decrypting, via another key within the asymmetric key pair, the encrypted copy of the identification information and (2) determining that the decrypted copy of the identification information differs from the unencrypted copy of the identification information.
-
公开(公告)号:US09647841B1
公开(公告)日:2017-05-09
申请号:US14871228
申请日:2015-09-30
Applicant: Juniper Networks, Inc.
Inventor: Venkanna Thadishetty , Ravindranath C. Kanakarajan
CPC classification number: H04L9/3234 , H04L9/3247 , H04L63/0442 , H04L63/08 , H04L63/083
Abstract: The disclosed system may include (1) a detection module, stored in memory, that detects that a user is attempting to operate a network peripheral device configured for connecting into a base network device, at least one of the network peripheral device and the base network device including a trusted platform module that further includes an endorsement key that identifies the trusted platform module, (2) an obtaining module, stored in memory, that obtains a digitally signed indication that the user is authorized by a vendor to operate the network peripheral device, (3) an enablement module, stored in memory, that enables the user to operate the network peripheral device based on obtaining the digitally signed indication that the user is authorized by the vendor to operate the network peripheral device, and (4) at least one physical processor configured to execute these modules. Various other systems and methods are also disclosed.
-
8.
公开(公告)号:US20160286392A1
公开(公告)日:2016-09-29
申请号:US14668834
申请日:2015-03-25
Applicant: Juniper Networks, Inc.
Inventor: Ravindranath C. Kanakarajan , Venkanna Thadishetty
CPC classification number: H04W12/06 , H04B7/1851 , H04L9/0825 , H04L9/32 , H04L9/3247 , H04L63/0281 , H04L63/0442 , H04L63/0876 , H04L63/0884 , H04L63/126 , H04L2209/24 , H04L2209/72 , H04W12/04 , H04W76/12
Abstract: The disclosed apparatus may include (1) a reply-reception module, stored in memory, that receives, from a satellite device, an authentication reply that includes an original authentication message digitally signed by the aggregation device using a private key of the aggregation device and that is digitally signed by the satellite device using a private key of the satellite device, (2) a forwarding module, stored in memory, that forwards the authentication reply to a network management server, (3) a validation-reception module, stored in memory, that receives, from the network management server in response to forwarding the authentication reply, a validation message, and (4) an authentication module, stored in memory, that authenticates the satellite device based at least in part on receiving the validation message. Various other apparatuses, systems, and methods are also disclosed.
Abstract translation: 所公开的装置可以包括:(1)存储在存储器中的应答接收模块,其从卫星设备接收包括由聚合设备使用聚合设备的私钥进行数字签名的原始认证消息的认证回复,以及 由卫星设备使用卫星设备的私钥进行数字签名,(2)存储在存储器中的转发模块,其将认证回复转发给网络管理服务器,(3)验证接收模块,存储在 存储器,其从网络管理服务器接收响应于转发认证答复的验证消息,以及(4)存储在存储器中的至少部分地基于接收验证消息来认证卫星设备的认证模块。 还公开了各种其它装置,系统和方法。
-
公开(公告)号:US10250634B2
公开(公告)日:2019-04-02
申请号:US15349157
申请日:2016-11-11
Applicant: Juniper Networks, Inc.
Inventor: Ravindranath C. Kanakarajan , Venkanna Thadishetty
Abstract: The disclosed apparatus may include (1) a storage device that stores a set of cookies that facilitate authenticating packets received from a node within a network and (2) a processing unit communicatively coupled to the storage device, wherein the processing unit (A) receives at least one packet from the node, (B) identifies a cookie included in the packet received from the node, (C) searches the set of cookies stored in the storage device for the cookie included in the packet received from the node, (D) identifies, during the search of the set of cookies, the cookie included in the packet and (E) protects against a DoS attack by authenticating the legitimacy of the packet based at least in part on the cookie included in the packet being identified in the set of cookies stored in the storage device. Various other apparatuses, systems, and methods are also disclosed.
-
公开(公告)号:US10013584B2
公开(公告)日:2018-07-03
申请号:US15470534
申请日:2017-03-27
Applicant: Juniper Networks, Inc.
Inventor: Ravindranath C. Kanakarajan , Venkanna Thadishetty
CPC classification number: G06F21/88 , G06F2221/2111 , G06F2221/2149 , G08B13/1418 , H04L41/12 , H04L41/28 , H04L63/107 , H04W12/12 , H04W12/1206
Abstract: The disclosed apparatus may include a secure storage device that securely stores an initial geographic location of a network device that facilitates network traffic within a network. This apparatus may also include a processing unit communicatively coupled to the secure storage device. The processing unit may determine a current geographic location of the network device. The policy-enforcement unit may then detect evidence of theft of the network device by (1) comparing the current geographic location of the network device with the initial geographic location of the network device and (2) determining, based at least in part on the comparison, that the current geographic location of the network device does not match the initial geographic location of the network device. Finally, the processing unit may perform at least one security action in response to detecting the evidence of theft of the network device.
-
-
-
-
-
-
-
-
-