Patents by Inventor How Tung Lim

How Tung Lim has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12255874
    Abstract: Techniques for securing control and user plane separation in mobile networks (e.g., service provider networks for mobile subscribers, such as for 4G/5G networks) are disclosed. In some embodiments, a system/process/computer program product for securing control and user plane separation in mobile networks in accordance with some embodiments includes monitoring network traffic on a mobile network at a security platform to identify an Packet Forwarding Control Protocol (PFCP) message associated with a new session, in which the mobile network includes a 4G network or a 5G network; extracting a plurality of parameters from the PFCP message at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network.
    Type: Grant
    Filed: May 8, 2023
    Date of Patent: March 18, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Leonid Burakovsky, Sachin Verma, Fengliang Hu, I-Chun Chen, How Tung Lim
  • Publication number: 20230412566
    Abstract: Techniques for securing control and user plane separation in mobile networks (e.g., service provider networks for mobile subscribers, such as for 4G/5G networks) are disclosed. In some embodiments, a system/process/computer program product for securing control and user plane separation in mobile networks in accordance with some embodiments includes monitoring network traffic on a mobile network at a security platform to identify an Packet Forwarding Control Protocol (PFCP) message associated with a new session, in which the mobile network includes a 4G network or a 5G network; extracting a plurality of parameters from the PFCP message at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network.
    Type: Application
    Filed: May 8, 2023
    Publication date: December 21, 2023
    Inventors: Leonid Burakovsky, Sachin Verma, Fengliang Hu, I-Chun Chen, How Tung Lim
  • Patent number: 11689502
    Abstract: Techniques for securing control and user plane separation in mobile networks (e.g., service provider networks for mobile subscribers, such as for 4G/5G networks) are disclosed. In some embodiments, a system/process/computer program product for securing control and user plane separation in mobile networks in accordance with some embodiments includes monitoring network traffic on a mobile network at a security platform to identify an Packet Forwarding Control Protocol (PFCP) message associated with a new session, in which the mobile network includes a 4G network or a 5G network; extracting a plurality of parameters from the PFCP message at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network.
    Type: Grant
    Filed: June 30, 2020
    Date of Patent: June 27, 2023
    Assignee: Palo Alto Networks, Inc.
    Inventors: Leonid Burakovsky, Sachin Verma, Fengliang Hu, I-Chun Chen, How Tung Lim
  • Publication number: 20210409375
    Abstract: Techniques for securing control and user plane separation in mobile networks (e.g., service provider networks for mobile subscribers, such as for 4G/5G networks) are disclosed. In some embodiments, a system/process/computer program product for securing control and user plane separation in mobile networks in accordance with some embodiments includes monitoring network traffic on a mobile network at a security platform to identify an Packet Forwarding Control Protocol (PFCP) message associated with a new session, in which the mobile network includes a 4G network or a 5G network; extracting a plurality of parameters from the PFCP message at the security platform; and enforcing a security policy at the security platform on the new session based on one or more of the plurality of parameters to secure control and user plane separation in the mobile network.
    Type: Application
    Filed: June 30, 2020
    Publication date: December 30, 2021
    Inventors: Leonid Burakovsky, Sachin Verma, Fengliang Hu, I-Chun Chen, How Tung Lim
  • Patent number: 8880494
    Abstract: A LPM search engine includes a plurality of exact match (EXM) engines and a moderately sized TCAM. Each EXM engine uses a prefix bitmap scheme that allows the EXM engine to cover multiple consecutive prefix lengths. Thus, instead of covering one prefix length L per EXM engine, the prefix bitmap scheme enables each EXM engine to cover entries having prefix lengths of L, L+1, L+2 and L+3, for example. As a result, fewer EXM engines are potentially underutilized, which effectively reduces quantization loss. Each EXM engine provides a search result with a determined fixed latency when using the prefix bitmap scheme. The results of multiple EXM engines and the moderately sized TCAM are combined to provide a single search result, representative of the longest prefix match. In one embodiment, the LPM search engine supports 32-bit IPv4 (or 128-bit IPv6) search keys, each having associated 15-bit level 3 VPN identification values.
    Type: Grant
    Filed: October 28, 2011
    Date of Patent: November 4, 2014
    Assignee: Brocade Communications Systems, Inc.
    Inventors: Jian Liu, Philip Lynn Leichty, How Tung Lim, John Michael Terry, Mahesh Srinivasa Maddury, Wing Cheung, Kung Ling Ko
  • Patent number: 8457017
    Abstract: The present invention provides a system, apparatus and method for providing point-to-point inter-chassis connections within chassis systems and/or network nodes. Multi-chassis systems within a network employ a protocol wherein a peer discovery process is initiated and the discovered neighbors are authentically verified before establishing an active state between point-to-point inter-chassis links.
    Type: Grant
    Filed: June 26, 2006
    Date of Patent: June 4, 2013
    Assignee: Infinera Corporation
    Inventors: Biao Lu, Vinay Ravuri, How Tung Lim, Kamran Farshchi, Yatindra Chugh, Sharfuddin Syed
  • Publication number: 20130031077
    Abstract: A LPM search engine includes a plurality of exact match (EXM) engines and a moderately sized TCAM. Each EXM engine uses a prefix bitmap scheme that allows the EXM engine to cover multiple consecutive prefix lengths. Thus, instead of covering one prefix length L per EXM engine, the prefix bitmap scheme enables each EXM engine to cover entries having prefix lengths of L, L+1, L+2 and L+3, for example. As a result, fewer EXM engines are potentially underutilized, which effectively reduces quantization loss. Each EXM engine provides a search result with a determined fixed latency when using the prefix bitmap scheme. The results of multiple EXM engines and the moderately sized TCAM are combined to provide a single search result, representative of the longest prefix match. In one embodiment, the LPM search engine supports 32-bit IPv4 (or 128-bit IPv6) search keys, each having associated 15-bit level 3 VPN identification values.
    Type: Application
    Filed: October 28, 2011
    Publication date: January 31, 2013
    Applicant: Brocade Communications Systems, Inc.
    Inventors: Jian Liu, Philip Lynn Leichty, How Tung Lim, John Michael Terry, Mahesh Srinivasa Maddury, Wing Cheung, Kung Ling Ko
  • Patent number: 7970114
    Abstract: A system, apparatus and method are described for displaying multiple attributes relative to objects in a network management program. In one embodiment, multiple attributes from a plurality of different standards are coalesced together and the coalesced attributes are displayed by a user interface. These coalesced attributes may be shown in such a manner so that inconsistencies between attributes of objects from different standards are reduced or obviated.
    Type: Grant
    Filed: June 26, 2006
    Date of Patent: June 28, 2011
    Assignee: Infinera Corporation
    Inventors: Sriram Subramanian, Rajasekar Venkatesan, Christopher C. Liou, Anthony W. Jorgenson, How Tung Lim, Sharfuddin Syed, Daniel P. Murphy, Steven Joseph Hand
  • Patent number: 7792017
    Abstract: A system, apparatus, and method for providing a plurality of internal VLANs within a networking element/node are described. Internal VLAN topologies are provisioned so that a particular VLAN(S) communicate traffic to corresponding applications. This segregation of internal traffic across a VLAN topology reduces the amount of interference between the traffic. Redundancy across the VLAN topology is provided so that traffic may be switched to another path in the event of a failure.
    Type: Grant
    Filed: April 28, 2006
    Date of Patent: September 7, 2010
    Assignee: Infinera Corporation
    Inventors: Biao Lu, Vinay Ravuri, How Tung Lim, Kamran Farshchi
  • Patent number: 7783746
    Abstract: A system, apparatus and a method are described that synchronizes multiple element management systems with a network element. The synchronization between the management entities within the element is maintained by employing special attributes, such as sentry identification for managed objects and guard attributes for managed object tables. Using these attributes, resynchronization between the management systems is improved by reducing the amount of data retrieved by the systems and reducing the processing load caused by the resynchronization process.
    Type: Grant
    Filed: June 26, 2006
    Date of Patent: August 24, 2010
    Assignee: Infinera Corporation
    Inventors: Steven Joseph Hand, How Tung Lim, Kasi Pydi Viswanadham, Kiran Dintakurthi
  • Publication number: 20070150620
    Abstract: A system, apparatus and a method are described that synchronizes multiple element management systems with a network element. The synchronization between the management entities within the element is maintained by employing special attributes, such as sentry identification for managed objects and guard attributes for managed object tables. Using these attributes, resynchronization between the management systems is improved by reducing the amount of data retrieved by the systems and reducing the processing load caused by the resynchronization process.
    Type: Application
    Filed: June 26, 2006
    Publication date: June 28, 2007
    Applicant: INFINERA CORPORATION
    Inventors: Steven Hand, How Tung Lim, Kasi Pydi Viswanadham, Kiran Dintakurthi
  • Publication number: 20070100887
    Abstract: A system, apparatus and method are described for displaying multiple attributes relative to objects in a network management program. In one embodiment, multiple attributes from a plurality of different standards are coalesced together and the coalesced attributes are displayed by a user interface. These coalesced attributes may be shown in such a manner so that inconsistencies between attributes of objects from different standards are reduced or obviated.
    Type: Application
    Filed: June 26, 2006
    Publication date: May 3, 2007
    Applicant: Infinera Corporation
    Inventors: Sriram Subramanian, Rajasekar Venkatesan, Christopher Liou, Anthony Jorgenson, How Tung Lim, Sharfuddin Syed, Daniel Murphy, Steven Hand
  • Publication number: 20070019642
    Abstract: A system, apparatus, and method for providing a plurality of internal VLANs within a networking element/node are described. Internal VLAN topologies are provisioned so that a particular VLAN(S) communicate traffic to corresponding applications. This segregation of internal traffic across a VLAN topology reduces the amount of interference between the traffic. Redundancy across the VLAN topology is provided so that traffic may be switched to another path in the event of a failure.
    Type: Application
    Filed: April 28, 2006
    Publication date: January 25, 2007
    Applicant: Infinera Corporation
    Inventors: Biao Lu, Vinay Ravuri, How Tung Lim, Kamran Farshchi
  • Publication number: 20070005968
    Abstract: The present invention provides a system, apparatus and method for providing point-to-point inter-chassis connections within chassis systems and/or network nodes. Multi-chassis systems within a network employ a protocol wherein a peer discovery process is initiated and the discovered neighbors are authentically verified before establishing an active state between point-to-point inter-chassis links.
    Type: Application
    Filed: June 26, 2006
    Publication date: January 4, 2007
    Applicant: INFINERA CORPORATION
    Inventors: Biao Lu, Vinay Ravuri, How Tung Lim, Kamran Farshchi, Yatindra Chugh, Sharfuddin Syed