Patents by Inventor Mingfei Peng
Mingfei Peng has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12665875Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.Type: GrantFiled: July 16, 2024Date of Patent: June 23, 2026Assignee: Palo Alto Networks, Inc.Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
-
Patent number: 12647388Abstract: Anycast IP addressing and policy-based forwarding are implemented so that resources deployed in association with different accounts of a tenant but have overlapping IP addresses appear distinct to the tenant. A service that executes on a network controller configures a DHCP address pool for an account for which associated resources are indicated for deployment. The service also orchestrates instantiation of one or more connectors configured to front the resource(s) and allocates an anycast IP address to the connector(s) that is unique with respect to other connectors that front resources associated with the same account or different accounts. The service then creates a policy-based forwarding rule to forward network traffic originating from an IP address within the account's DHCP address pool and with a destination address that matches the resource(s) IP address to the anycast IP address allocated to the connector(s) that fronts the resources.Type: GrantFiled: April 17, 2024Date of Patent: June 2, 2026Assignee: Palo Alto Networks, Inc.Inventors: Jayant Jain, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal, Uttam Ramesh, Ketan Gunawant Kulkarni
-
Publication number: 20260100933Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.Type: ApplicationFiled: October 17, 2025Publication date: April 9, 2026Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
-
Publication number: 20260032115Abstract: The present application discloses a method, system, and computer system for providing intelligent DNS load balancing using a combination of a dynamic DNAT pool and application providing in a connector-based solution for private application access. The method includes: (a) performing a DNS re-resolution for resolving an application Fully Qualified Domain Name (FQDN) to obtain a plurality of IP addresses for a plurality of application servers, (b) performing periodic application server probing, and (c) dynamically updating a destination network address translation (DNAT) to provide DNS load balancing for application traffic. The DNAT is updated based at least in part on one or more of the DNS re-resolution and the application server probing.Type: ApplicationFiled: July 26, 2024Publication date: January 29, 2026Inventors: Brian Russell Kean, Ketan Kulkarni, Jayant Jain, Mingfei Peng
-
Publication number: 20260005949Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address.Type: ApplicationFiled: September 4, 2025Publication date: January 1, 2026Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
-
Patent number: 12470520Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.Type: GrantFiled: July 28, 2023Date of Patent: November 11, 2025Assignee: Palo Alto Networks, Inc.Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
-
Publication number: 20250330442Abstract: Anycast IP addressing and policy-based forwarding are implemented so that resources deployed in association with different accounts of a tenant but have overlapping IP addresses appear distinct to the tenant. A service that executes on a network controller configures a DHCP address pool for an account for which associated resources are indicated for deployment. The service also orchestrates instantiation of one or more connectors configured to front the resource(s) and allocates an anycast IP address to the connector(s) that is unique with respect to other connectors that front resources associated with the same account or different accounts. The service then creates a policy-based forwarding rule to forward network traffic originating from an IP address within the account's DHCP address pool and with a destination address that matches the resource(s) IP address to the anycast IP address allocated to the connector(s) that fronts the resources.Type: ApplicationFiled: April 17, 2024Publication date: October 23, 2025Inventors: Jayant Jain, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal, Uttam Ramesh, Ketan Gunawant Kulkarni
-
Publication number: 20250323892Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.Type: ApplicationFiled: June 26, 2025Publication date: October 16, 2025Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
-
Patent number: 12425327Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address.Type: GrantFiled: October 31, 2023Date of Patent: September 23, 2025Assignee: Palo Alto Networks, Inc.Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
-
Patent number: 12401616Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.Type: GrantFiled: December 8, 2023Date of Patent: August 26, 2025Assignee: Palo Alto Networks, Inc.Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
-
Publication number: 20250193148Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.Type: ApplicationFiled: December 8, 2023Publication date: June 12, 2025Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
-
Publication number: 20250141778Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a network fabric of a tenant, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a DNS entry that resolves the application name to its virtual IP address and destination NAT rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.Type: ApplicationFiled: October 31, 2023Publication date: May 1, 2025Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
-
Publication number: 20250047632Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.Type: ApplicationFiled: October 18, 2024Publication date: February 6, 2025Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
-
Publication number: 20250039138Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.Type: ApplicationFiled: July 28, 2023Publication date: January 30, 2025Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
-
Publication number: 20240372829Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.Type: ApplicationFiled: July 16, 2024Publication date: November 7, 2024Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
-
Patent number: 12126590Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.Type: GrantFiled: July 31, 2023Date of Patent: October 22, 2024Assignee: Palo Alto Networks, Inc.Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
-
Patent number: 12069025Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.Type: GrantFiled: December 22, 2021Date of Patent: August 20, 2024Assignee: Palo Alto Networks, Inc.Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
-
Publication number: 20240187371Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.Type: ApplicationFiled: July 31, 2023Publication date: June 6, 2024Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
-
Patent number: 11757826Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.Type: GrantFiled: December 1, 2022Date of Patent: September 12, 2023Assignee: Palo Alto Networks, Inc.Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
-
Publication number: 20230198944Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.Type: ApplicationFiled: December 22, 2021Publication date: June 22, 2023Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng