Patents by Inventor Mingfei Peng

Mingfei Peng has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12665875
    Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.
    Type: Grant
    Filed: July 16, 2024
    Date of Patent: June 23, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
  • Patent number: 12647388
    Abstract: Anycast IP addressing and policy-based forwarding are implemented so that resources deployed in association with different accounts of a tenant but have overlapping IP addresses appear distinct to the tenant. A service that executes on a network controller configures a DHCP address pool for an account for which associated resources are indicated for deployment. The service also orchestrates instantiation of one or more connectors configured to front the resource(s) and allocates an anycast IP address to the connector(s) that is unique with respect to other connectors that front resources associated with the same account or different accounts. The service then creates a policy-based forwarding rule to forward network traffic originating from an IP address within the account's DHCP address pool and with a destination address that matches the resource(s) IP address to the anycast IP address allocated to the connector(s) that fronts the resources.
    Type: Grant
    Filed: April 17, 2024
    Date of Patent: June 2, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal, Uttam Ramesh, Ketan Gunawant Kulkarni
  • Publication number: 20260100933
    Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
    Type: Application
    Filed: October 17, 2025
    Publication date: April 9, 2026
    Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
  • Publication number: 20260032115
    Abstract: The present application discloses a method, system, and computer system for providing intelligent DNS load balancing using a combination of a dynamic DNAT pool and application providing in a connector-based solution for private application access. The method includes: (a) performing a DNS re-resolution for resolving an application Fully Qualified Domain Name (FQDN) to obtain a plurality of IP addresses for a plurality of application servers, (b) performing periodic application server probing, and (c) dynamically updating a destination network address translation (DNAT) to provide DNS load balancing for application traffic. The DNAT is updated based at least in part on one or more of the DNS re-resolution and the application server probing.
    Type: Application
    Filed: July 26, 2024
    Publication date: January 29, 2026
    Inventors: Brian Russell Kean, Ketan Kulkarni, Jayant Jain, Mingfei Peng
  • Publication number: 20260005949
    Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address.
    Type: Application
    Filed: September 4, 2025
    Publication date: January 1, 2026
    Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
  • Patent number: 12470520
    Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
    Type: Grant
    Filed: July 28, 2023
    Date of Patent: November 11, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
  • Publication number: 20250330442
    Abstract: Anycast IP addressing and policy-based forwarding are implemented so that resources deployed in association with different accounts of a tenant but have overlapping IP addresses appear distinct to the tenant. A service that executes on a network controller configures a DHCP address pool for an account for which associated resources are indicated for deployment. The service also orchestrates instantiation of one or more connectors configured to front the resource(s) and allocates an anycast IP address to the connector(s) that is unique with respect to other connectors that front resources associated with the same account or different accounts. The service then creates a policy-based forwarding rule to forward network traffic originating from an IP address within the account's DHCP address pool and with a destination address that matches the resource(s) IP address to the anycast IP address allocated to the connector(s) that fronts the resources.
    Type: Application
    Filed: April 17, 2024
    Publication date: October 23, 2025
    Inventors: Jayant Jain, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal, Uttam Ramesh, Ketan Gunawant Kulkarni
  • Publication number: 20250323892
    Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.
    Type: Application
    Filed: June 26, 2025
    Publication date: October 16, 2025
    Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
  • Patent number: 12425327
    Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a tenant's network fabric, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a domain name system entry that resolves the application name to its virtual Internet Protocol (IP) address and destination network address translation rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address.
    Type: Grant
    Filed: October 31, 2023
    Date of Patent: September 23, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
  • Patent number: 12401616
    Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.
    Type: Grant
    Filed: December 8, 2023
    Date of Patent: August 26, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
  • Publication number: 20250193148
    Abstract: A network controller communicates a wildcard domain name defined by a tenant and IP addresses of data centers for which a tenant has configured that wildcard to network elements of a network fabric through which the data centers are accessible. Each network element creates a rule to forward DNS requests with FQDNs that match the wildcard to each data center IP address. When a network element receives a DNS request indicating a FQDN that matches the wildcard, the network element forwards the DNS request to each data center IP address. Each data center element associated with one of the IP addresses receives the DNS request and determines if the FQDN can be resolved to an IP address in that data center. Data center elements for which domain name resolution is successful notify the network controller, which onboards the resource corresponding to the FQDN in that data center.
    Type: Application
    Filed: December 8, 2023
    Publication date: June 12, 2025
    Inventors: Jayant Jain, Brian Russell Kean, Mingfei Peng, Harieasswar Lakshmidevi, Harish Kumar Lohar
  • Publication number: 20250141778
    Abstract: Anycast addressing is utilized to support the connection of multiple application connectors fronting an application(s) to a network element and anycast routing of network traffic destined for the application(s). When an application is indicated for onboarding in a network fabric of a tenant, a network controller allocates virtual and anycast addresses to the application. Allocation of anycast addresses is per domain name and port/protocol combination. Upon determining that the application is available, the application connector(s) advertises reachability of the application via the anycast address. The network controller orchestrates configuration of a DNS entry that resolves the application name to its virtual IP address and destination NAT rules that translate the virtual IP address to the anycast address and the anycast address to the application's private IP address. Application network traffic can thus be forwarded to the application via any application connector that advertised the anycast address.
    Type: Application
    Filed: October 31, 2023
    Publication date: May 1, 2025
    Inventors: Jacob Rameen Chitsaz, Jayant Jain, Brian Russell Kean, Uttam Ramesh, Mingfei Peng
  • Publication number: 20250047632
    Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.
    Type: Application
    Filed: October 18, 2024
    Publication date: February 6, 2025
    Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
  • Publication number: 20250039138
    Abstract: Techniques for wildcard based private application access are disclosed. In some embodiments, a system, a process, and/or a computer program product for wildcard based private application access includes receiving a request for access to an application over a secure access service edge (SASE) network for a user associated with an enterprise; determining if the request for access to the application matches a wildcard (e.g., the wildcard can be configured by an administrator of the enterprise for matching a fully qualified domain name (FQDN) for the application); and automatically configuring access information (e.g., IP address, protocol, and destination port) for the application that matches the wildcard.
    Type: Application
    Filed: July 28, 2023
    Publication date: January 30, 2025
    Inventors: Jayant Jain, Harieasswar Lakshmidevi, Mingfei Peng, Brian Russell Kean, Srivatsan Rajagopal
  • Publication number: 20240372829
    Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.
    Type: Application
    Filed: July 16, 2024
    Publication date: November 7, 2024
    Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
  • Patent number: 12126590
    Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.
    Type: Grant
    Filed: July 31, 2023
    Date of Patent: October 22, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
  • Patent number: 12069025
    Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.
    Type: Grant
    Filed: December 22, 2021
    Date of Patent: August 20, 2024
    Assignee: Palo Alto Networks, Inc.
    Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
  • Publication number: 20240187371
    Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.
    Type: Application
    Filed: July 31, 2023
    Publication date: June 6, 2024
    Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
  • Patent number: 11757826
    Abstract: A controller can securely publish an application of a tenant by securely extending a network fabric into the networks of the tenant with virtual private networks and NAT. After a tenant deploys an application into one or more networks of the tenant, the tenant can indicate select applications to publish. The network controller assigns a network address from the routable address space of the network fabric to the application and a network address aggregate to each application connector that will front an instance of the application, which securely extends the network fabric into the tenant network. The network controller configures NAT rules in the network fabric and on the application connector to create a route for traffic of the application through the network fabric to the application instance using a fully qualified domain name assigned to the application without exposing a private network address of the application instance and preserving security of other resource on the tenant network.
    Type: Grant
    Filed: December 1, 2022
    Date of Patent: September 12, 2023
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jayant Jain, Brian Russell Kean, Aditya Srinivasa Ivaturi, Mohit Sahni, Mingfei Peng
  • Publication number: 20230198944
    Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.
    Type: Application
    Filed: December 22, 2021
    Publication date: June 22, 2023
    Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng