Kousik Nandy 1 Summary * More than five years of industrial experience of working in system softwares like internet security protocols, real time operating system, and run-time libraries. * Expertise in IKE, IPSec VPNs and cryptographic algorithms. * C * M. Tech in Computer Sc. & Engg. from IIT Kanpur. 2 Professional experience 2.1 Working as a software engineer in Security Technology Group of Cisco Systems India Pvt. Ltd. since December 2000. 2.1.1 Work in progress I am the lead developer and maintainer of Cisco EzVPN solution. EzVPN solution is designed to simplify VPN deployment for SOHO offices and teleworkers. This is based on Cisco Unity protocol which is based on IKE and its extensions: extended authentication and configuration mode. In addition to IPSec connectivity, EzVPN allows the remote access client users to be authenticated, and also allows to put corporate policies and configurations to the remote client. My recent projects with EzVPN includes: - Defining mode configuration attributes for IKE version 2. I am working with Cisco unity working group for this. This involves extending IKE v2 draft suitably so that config can be pushed to remote access clients. - Pushing configuration out of band to remote clients. This is done by pushing a URL, which is used by the client for configuration. This will save software upgrades for both clients and headends when a new feature needs configuration. I am working with unity working group for this. - Intercepting HTTP traffic from user to prompt for XAuth credentials. HTTP connections from the users in SOHO lan are intercepted, and through web interface, they are prompted for extendend authentication username and password. This required working with firewall/auth-proxy team. - Assigning groups to remote access clients based on the contents of digital certificates. Remote access clients are classified in 'groups', which is generally based on IKE phase 1 ID payload. This enables concentrators to assign groups by specific fields of certificate presented for authentication. This project required close interaction with PKI team. I maintain IKE (version 1) implementation of Cisco IOS. Internet Key Exchange (IKE) is the most popular way for two devices to establish authenticity and cryptographic keying materials. Recent features added to IKE: - Support for runtime DNS resolution of IKE peer's ip address. - Introduction of isakmp profiles. This allows classification of ISAKMP peers based on the phase 1 identities. ISAKMP profiles, using regular expression matching capabilities, can classify peers and assign properties to them. - Support VRF in IPSec and ISAKMP. When multiple VRF address spaces are present in the router VRF awareness can seperate data and control traffic of different customers and can provide remote access to them with a single public address. - I wrote a IKE Harness Tool (IHT) which can test any IKE implementation for conformance and security bugs. It could reorder, replay, drop, insert, change content of all kinds of ISAKMP payloads. It could emulate any specific vendor implementation for testing interoperability. I maintain IKE-PKI interface of Cisco IOS. Public Key Interface (PKI) is used as an authentication mechanism in IKE. This involves public key management, digitial certificate processing and signature verification. Recent features added to IKE-PKI interface: - Multiple RSA keypair support. 2.1.2 Work in recent past I maintain Cisco Encryption Technology (CET). 2.2 Worked as a senior software engineer in DSP software team of Analog Devices India from April 1999 to December 2000. 2.2.1 Design & development of a RTOS (VDK) for ADSP processors Design and development of a real-time operating system for Analog Devices' general purpose DSP processors. The scalable embedded OS supports priority based pre-emptive and round robin scheduling of multiple threads of the application, it provides semaphores and event-flags for thread synchronization, it has advanced interrupt management, it is capable of periodic thread execution. Almost all system calls are deterministic. The initial version of the RTOS has been written in C++ to attain a modular and scalable architecture, and then it is being ported to the assembly language of various Analog Devices' general purpose DSP platforms to optimize size and speed. I designed and developed the entire thread management module, which manages the states of threads that are existing in the system and the resources the threads are using. The thread management features dynamic creation, lazy deletion and garbage collection, and supporting different time-quantum per priority level was one of my ideas. I was also responsible for the time management module which supported timeout mechanism when some thread awaits a resource with a time constraint. I have designed the event-flag module, the sleeping mechanisms of threads and have significant contribution towards the data structures and algorithms used in the RTOS. 2.2.2 Development of compiler libraries - Development of an optimized compiler hidden run-time library and complex matrix run-time library for ADSP-TigerSHARC processor in the assembly language of the respective processor. I was responsible for 64 bit IEEE-754 format floating point arithmetic operations and 64 bit integer operations. In the C run-time library I wrote the matrix operations with complex number elements. - Development of an optimized ANSI C Run-Time Library for ADSP-219x processor in the assembly language of ADSP-219x. I wrote the interrupt and signal management functions (installation/ deinstallation/ invocation of interrupt/ signal handlers), memory management functions (malloc, free and associated functions). 3 Patents 3.1 Continuing ISAKMP and IPSec security associations after address of one endpoint changes. [applied in USPTO] 4 Qualification 4.1 M. Tech. Department of Computer Science and Engineering, IIT Kanpur. 1999, C.P.I. 8.67 (max 10), ranked 4 of 23 Work on Graph Theory: M. Tech. thesis on "Algorithm on solving Stable Marriage Problem in Egalitarian Society" 4.2 B. E. Department of Electronics and Tele-Communication, Jadavpur University, Calcutta 1997, 84.8% 5 Personal details 5.1 Address Flat 306, Jyothi Meadows Apartments Ananthapura Main Road, S. L. Colony Bangalore 560017 5.2 Contact No. +91 80 5212306 [evening] +91 98452 46838 5.3 E-mail kousik (@) yahoo [.] com 5.4 Interests and Activities Linux and free softwares. 5.5 Hobbies Photography.