Patents by Inventor Jayant JAIN

Jayant JAIN has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Publication number: 20260261544
    Abstract: The present application discloses a method, system, and computer system for causing network traffic handling policies to be enforced with respect to a network traffic sample. An example of the method includes (i) configuring a wildcard application group with a wildcard Fully Qualified Domain Name (FQDN) for a set of one or more applications, and (ii) allocating an internet protocol (IP) address from an address pool to an application matching the wildcard FQDN. Another example of the method includes (a) configuring a wildcard application group with a wildcard FQDN for a set of one or more applications, (b) allocating an IP address from an IP address pool to a particular application matching the wildcard FQDN, (c) associating the allocated IP address with the wildcard application group; and (d) providing an indication that the allocated IP address is associated with the wildcard application group.
    Type: Application
    Filed: February 28, 2025
    Publication date: September 3, 2026
    Inventors: Jayant Jain, Mingfei Peng, Ketan Kulkarni, Anal Srivastava, Brian Russell Kean, Brian David Levin, Uttam Ramesh
  • Publication number: 20260261583
    Abstract: A plurality of applications that have been onboarded are determined. The plurality of applications that are inactive are determined based in part on the telemetry flow records data associated with the plurality of applications. One or more applications of the plurality of applications determined to be inactive are disabled.
    Type: Application
    Filed: March 3, 2025
    Publication date: September 3, 2026
    Inventors: Ketan Kulkarni, Brian Russell Kean, Jayant Jain, Mingfei Peng, Uttam Ramesh
  • Patent number: 12726402
    Abstract: Some embodiments provide an elastic architecture for providing a service in a computing system. To perform a service on the data messages, the service architecture uses a service node (SN) group that includes one primary service node (PSN) and zero or more secondary service nodes (SSNs). The service can be performed on a data message by either the PSN or one of the SSN. However, in addition to performing the service, the PSN also performs a load balancing operation that assesses the load on each service node (i.e., on the PSN or each SSN), and based on this assessment, has the data messages distributed to the service node(s) in its SN group. Based on the assessed load, the PSN in some embodiments also has one or more SSNs added to or removed from its SN group. To add or remove an SSN to or from the service node group, the PSN in some embodiments directs a set of controllers to add (e.g., instantiate or allocate) or remove the SSN to or from the SN group.
    Type: Grant
    Filed: June 19, 2023
    Date of Patent: September 1, 2026
    Assignee: VMware LLC
    Inventors: Jayant Jain, Anirban Sengupta, Mohan Parthasarathy
  • Patent number: 12706820
    Abstract: A method of collecting health check metrics for a network is provided. The method, at a deep packet inspector on a physical host in a datacenter, receives a copy of a network packet from a load balancer. The packet includes a plurality of layers. Each layer corresponds to a communication protocol in a plurality of communication protocols. The method identifies an application referenced in the packet. The method analyzes the information in one or more layers of the packet to determine metrics for the source application. The method sends the determined metrics to the load balancer.
    Type: Grant
    Filed: August 30, 2024
    Date of Patent: August 11, 2026
    Assignee: VMware LLC
    Inventors: Alok S. Tiagi, Jayant Jain, Anirban Sengupta, Srinivas Nimmagadda, Rick Lund
  • Patent number: 12659299
    Abstract: A method comprises: in response to detecting a new expression in a policy rule, updating a global version number to a new value; identifying a particular IP address that corresponds to an FQDN matching on the new expression; storing an entry comprising the particular IP address, the new expression, and an entry version number in a first data structure, the entry version number being assigned the new value; in response to detecting a new connection to a destination IP address: finding a matching entry in the first data structure corresponding to the destination IP address; determining whether the global version number matches the entry version number for the matching entry; and in response to determining that the global version number does not match the entry version number for the matching entry, sending update information to a slowpath process that associates an updated configuration information for the matching entry.
    Type: Grant
    Filed: July 9, 2024
    Date of Patent: June 16, 2026
    Assignee: VMware LLC
    Inventors: Sushruth Gopal, Jayant Jain, Davide Celotto, Josh Swerdlow
  • Publication number: 20260163846
    Abstract: Described herein are systems, methods, and software to enhance network traffic management. In one implementation, a first host identifies a packet to be transferred from a first virtual machine on the first host to a second virtual machine on a second host. In response to identifying the packet, the first host identifies a source logical port for the first virtual machine, and transferring a communication to the second host, wherein the communication encapsulates the data packet and the source logical port. Once the packet is received by the second host, the second host may use the source logical port to determine a forwarding action for the packet.
    Type: Application
    Filed: April 15, 2025
    Publication date: June 11, 2026
    Inventors: Jayant Jain, Ganesan Chandrashekhar, Anirban Sengupta, Pankaj Thakkar, Alexander Tessmer
  • Patent number: 12647388
    Abstract: Anycast IP addressing and policy-based forwarding are implemented so that resources deployed in association with different accounts of a tenant but have overlapping IP addresses appear distinct to the tenant. A service that executes on a network controller configures a DHCP address pool for an account for which associated resources are indicated for deployment. The service also orchestrates instantiation of one or more connectors configured to front the resource(s) and allocates an anycast IP address to the connector(s) that is unique with respect to other connectors that front resources associated with the same account or different accounts. The service then creates a policy-based forwarding rule to forward network traffic originating from an IP address within the account's DHCP address pool and with a destination address that matches the resource(s) IP address to the anycast IP address allocated to the connector(s) that fronts the resources.
    Type: Grant
    Filed: April 17, 2024
    Date of Patent: June 2, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal, Uttam Ramesh, Ketan Gunawant Kulkarni
  • Publication number: 20260100933
    Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
    Type: Application
    Filed: October 17, 2025
    Publication date: April 9, 2026
    Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
  • Publication number: 20260075036
    Abstract: A data packet is received. It is determined whether the data packet is encapsulated. One or more security policies are applied to the data packet based on whether the data packet is encapsulated.
    Type: Application
    Filed: August 26, 2025
    Publication date: March 12, 2026
    Inventors: Uttam Ramesh, Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Srikanth Ramachandran, Nidhi Shah, Srikanth Mulakaluri
  • Publication number: 20260032115
    Abstract: The present application discloses a method, system, and computer system for providing intelligent DNS load balancing using a combination of a dynamic DNAT pool and application providing in a connector-based solution for private application access. The method includes: (a) performing a DNS re-resolution for resolving an application Fully Qualified Domain Name (FQDN) to obtain a plurality of IP addresses for a plurality of application servers, (b) performing periodic application server probing, and (c) dynamically updating a destination network address translation (DNAT) to provide DNS load balancing for application traffic. The DNAT is updated based at least in part on one or more of the DNS re-resolution and the application server probing.
    Type: Application
    Filed: July 26, 2024
    Publication date: January 29, 2026
    Inventors: Brian Russell Kean, Ketan Kulkarni, Jayant Jain, Mingfei Peng
  • Publication number: 20260005949
    Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address.
    Type: Application
    Filed: September 4, 2025
    Publication date: January 1, 2026
    Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
  • Publication number: 20250371092
    Abstract: The present application discloses a method, system, and computer system for providing secure access to links embedded in an email. The method includes (i) parsing an email, (ii) identifying a URL link in the email, and (iii) rewriting the URL link for execution in an isolation context based at least in part on a policy.
    Type: Application
    Filed: May 31, 2024
    Publication date: December 4, 2025
    Inventors: Jayant Jain, Yanggui Chen, Fred Philip Stanley, Priyanka Tiwari, Shyam Prasad Nukala, Nitish Kishore Khadke
  • Patent number: 12470520
    Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
    Type: Grant
    Filed: July 28, 2023
    Date of Patent: November 11, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
  • Publication number: 20250330442
    Abstract: Anycast IP addressing and policy-based forwarding are implemented so that resources deployed in association with different accounts of a tenant but have overlapping IP addresses appear distinct to the tenant. A service that executes on a network controller configures a DHCP address pool for an account for which associated resources are indicated for deployment. The service also orchestrates instantiation of one or more connectors configured to front the resource(s) and allocates an anycast IP address to the connector(s) that is unique with respect to other connectors that front resources associated with the same account or different accounts. The service then creates a policy-based forwarding rule to forward network traffic originating from an IP address within the account's DHCP address pool and with a destination address that matches the resource(s) IP address to the anycast IP address allocated to the connector(s) that fronts the resources.
    Type: Application
    Filed: April 17, 2024
    Publication date: October 23, 2025
    Inventors: Jayant Jain, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal, Uttam Ramesh, Ketan Gunawant Kulkarni
  • Publication number: 20250323892
    Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.
    Type: Application
    Filed: June 26, 2025
    Publication date: October 16, 2025
    Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
  • Patent number: 12425370
    Abstract: A data packet is received. It is determined whether the data packet is encapsulated. One or more security policies are applied to the data packet based on whether the data packet is encapsulated.
    Type: Grant
    Filed: September 12, 2024
    Date of Patent: September 23, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Uttam Ramesh, Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Srikanth Ramachandran, Nidhi Shah, Srikanth Mulakaluri
  • Patent number: 12425327
    Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address.
    Type: Grant
    Filed: October 31, 2023
    Date of Patent: September 23, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
  • Patent number: 12401616
    Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.
    Type: Grant
    Filed: December 8, 2023
    Date of Patent: August 26, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
  • Publication number: 20250254132
    Abstract: A novel method for dynamic network service allocation that maps generic services into specific configurations of service resources in a network is provided. An application that is assigned to be performed by computing resources in the network is associated with a set of generic services, and the method maps the set of generic services to the service resources based on the assignment of the application to the computing resources. The mapping of generic services is further based on a level of service that is chosen for the application, where the set of generic services are mapped to different sets of network resources according to different levels of services.
    Type: Application
    Filed: April 22, 2025
    Publication date: August 7, 2025
    Inventors: Jayant Jain, Raju Koganty, Anirban Sengupta
  • Patent number: 12375533
    Abstract: Some embodiments provide a method for forwarding data messages at multiple edge gateways of a logical network that process data messages between the logical network and an external network. At a first edge gateway, the method receives a data message, having an external address as a destination address, from the logical network. Based on the destination address, the method applies a default route to the data message that routes the data message to a second edge gateway and specifies a first output interface of the first edge gateway for the data message. After routing the data message, the method applies a stored NAT entry that (i) modifies a source address of the data message to be a public NAT address associated with the first edge gateway and (ii) redirects the modified data message to a second output interface of the first edge gateway instead of the first output interface.
    Type: Grant
    Filed: March 14, 2024
    Date of Patent: July 29, 2025
    Assignee: VMware LLC
    Inventors: Yong Wang, Jayant Jain, Ganesh Sadasivan, Abhishek Goliya