Patents by Inventor Shu Lin
Shu Lin has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12665875Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.Type: GrantFiled: July 16, 2024Date of Patent: June 23, 2026Assignee: Palo Alto Networks, Inc.Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
-
Publication number: 20260121852Abstract: While organizations can employ IPsec based VPNs to securely connect different sites (e.g., branch sites, data centers, and/or virtual private clouds), the security can disrupt network performance by obfuscating information used for load balancing. Disclosed is technology that employs minimal decryption in a secure manner to load balance multiple network traffic flows within a secure connection (“tunnel”) across security appliances that effectively operate as alternative endpoints for the tunnel. The security appliances within a load balancing pool are configured/programmed to share tunnel keys with each other after tunnel establishment and with the load balancer. The load balancer uses the tunnel keys to minimally decrypt in a lookaside memory encrypted packets to ascertain N-tuples, The load balancer then uses the N-tuples to load balance the flows within a tunnel across the security appliances.Type: ApplicationFiled: December 26, 2025Publication date: April 30, 2026Inventors: Fang Lu, Peng Chen, Shu Lin
-
Publication number: 20260113304Abstract: An orchestrator that manages security appliances for an organization determines a sink configured for traffic mirroring and correspondingly configures components for the correlation and secure conveyance. The orchestrator also configures the security appliances. The orchestrator configures the security appliances to copy cryptographic keys (hereinafter “tunnel keys”) and identifiers associated with the keys of secure VPN tunnels established by the security appliances to a repository of the cloud-service provider. The orchestrator configures a virtual machine associated with the mirroring sink with correlation logic. The virtual machine correlates sets of packets aggregated across different mirroring streams and tunnel keys with the associated identifiers. Correlating the sets of packets and the tunnel keys allows an organization to efficiently access the content of the encrypted packets or facilitates secure conveyance.Type: ApplicationFiled: December 17, 2025Publication date: April 23, 2026Inventors: Tushar Vyankatesh Nargunde, Zhanglin He, Tripti Agarwal, Shu Lin, Jose Carlos Sagrero Dominguez
-
Publication number: 20260081894Abstract: Traffic log data generated by cloud firewalls executing in a cloud environment during a time period that indicate classes and corresponding amounts of network traffic detected across sessions as well as usage cost data recorded for the cloud firewalls during the time period are obtained. The traffic log data are preprocessed to generate training data comprising feature vectors indicating the aggregate amount of network traffic detected for each traffic class during a corresponding time interval within the time period and are labeled with the associated usage cost. A machine learning model is trained on the labeled traffic log data to learn the impact each traffic class has on the accumulated usage costs. The trained model generates predicted usage costs based on distributions of detected network traffic across traffic classes that are analyzed to correlate traffic patterns with usage costs to determine the optimal size(s) of cloud firewalls to deploy.Type: ApplicationFiled: November 21, 2025Publication date: March 19, 2026Inventors: Shangde Zhou, Sheng Meng, Shu Lin
-
Publication number: 20260067212Abstract: Techniques for deploying IPv6 routing are disclosed. A system, process, and/or computer program product for deploying IPv6 routing includes advertising in Border Gateway Protocol (BGP) a new address-family capability in combination with an existing address-family in a network that supports a plurality of address families, and undoing BGP filters to allow BGP routes to be exchanged at a time that a network administrator enables the new address-family capability in the network.Type: ApplicationFiled: September 5, 2025Publication date: March 5, 2026Inventors: Jia Chen, Shu Lin, Jining Tian, Enke Chen
-
Publication number: 20260049481Abstract: The present application provides a locking assembly and a wooden slat device, the locking assembly comprising a locking body and a telescopic rod; the locking body is provided with a first through-hole, and the telescopic rod is telescopically attached to the locking body; the telescopic rod is provided with a second through-hole, the second through-hole penetrating the telescopic rod and selectively connected or spaced apart from the first through-hole; the second through-hole is provided with an opening, and the opening opens or closes with the telescopic rod's telescope so that the second through-hole is connected or spaced apart from the second through-hole is provided with an opening that opens or closes as the telescoping rod is telescoped, so that the second through-hole is connected or spaced apart from the first through-hole.Type: ApplicationFiled: September 20, 2024Publication date: February 19, 2026Inventor: Shu Lin
-
Patent number: 12549352Abstract: While organizations can employ IPsec based VPNs to securely connect different sites (e.g., branch sites, data centers, and/or virtual private clouds), the security can disrupt network performance by obfuscating information used for load balancing. Disclosed is technology that employs minimal decryption in a secure manner to load balance multiple network traffic flows within a secure connection (“tunnel”) across security appliances that effectively operate as alternative endpoints for the tunnel. The security appliances within a load balancing pool are configured/programmed to share tunnel keys with each other after tunnel establishment and with the load balancer. The load balancer uses the tunnel keys to minimally decrypt in a lookaside memory encrypted packets to ascertain N-tuples. The load balancer then uses the N-tuples to load balance the flows within a tunnel across the security appliances.Type: GrantFiled: July 27, 2023Date of Patent: February 10, 2026Assignee: Palo Alto Networks, Inc.Inventors: Fang Lu, Peng Chen, Shu Lin
-
Patent number: 12537797Abstract: An orchestrator that manages security appliances for an organization determines a sink configured for traffic mirroring and correspondingly configures components for the correlation and secure conveyance. The orchestrator also configures the security appliances. The orchestrator configures the security appliances to copy cryptographic keys (hereinafter “tunnel keys”) and identifiers associated with the keys of secure VPN tunnels established by the security appliances to a repository of the cloud-service provider. The orchestrator configures a virtual machine associated with the mirroring sink with correlation logic. The virtual machine correlates sets of packets aggregated across different mirroring streams and tunnel keys with the associated identifiers. Correlating the sets of packets and the tunnel keys allows an organization to efficiently access the content of the encrypted packets or facilitates secure conveyance.Type: GrantFiled: July 31, 2023Date of Patent: January 27, 2026Assignee: Palo Alto Networks, Inc.Inventors: Tushar Vyankatesh Nargunde, Zhanglin He, Tripti Agarwal, Shu Lin, Jose Carlos Sagrero Dominguez
-
Patent number: 12526256Abstract: Traffic log data generated by cloud firewalls executing in a cloud environment during a time period that indicate classes and corresponding amounts of network traffic detected across sessions as well as usage cost data recorded for the cloud firewalls during the time period are obtained. The traffic log data are preprocessed to generate training data comprising feature vectors indicating the aggregate amount of network traffic detected for each traffic class during a corresponding time interval within the time period and are labeled with the associated usage cost. A machine learning model is trained on the labeled traffic log data to learn the impact each traffic class has on the accumulated usage costs. The trained model generates predicted usage costs based on distributions of detected network traffic across traffic classes that are analyzed to correlate traffic patterns with usage costs to determine the optimal size(s) of cloud firewalls to deploy.Type: GrantFiled: December 21, 2021Date of Patent: January 13, 2026Assignee: Palo Alto Networks, Inc.Inventors: Shangde Zhou, Sheng Meng, Shu Lin
-
Publication number: 20250358214Abstract: Techniques for deploying symmetric routing are disclosed. A system, process, and/or computer program product for deploying symmetric routing includes routing network traffic from a client over a security access network provider virtual private network (VPN) access to a customer network, and enforcing symmetric routing crossing an autonomous system (AS) based on one or more prepended AS routing numbers in a first routing table for inbound traffic and/or based on one or more weights and one or more local preferences in a second routing table for outbound traffic.Type: ApplicationFiled: July 31, 2025Publication date: November 20, 2025Inventors: Jia Chen, Saurabh Dixit, Anil Saini, Shu Lin, Hao Long
-
Publication number: 20250348386Abstract: Support for distributed database backtracking, in which the database is reverted or iteratively reverted to a previous state, is provided. Log sequence number ranges and storage offset ranges for use in reconstructing the previous state are determined and used in the reconstruction. Clock sampling records can be generated indicating a feasible backtracking window with time points indicating allowable times to which backtracking can be performed. Appropriate log records, snapshots and checkpoints for database states are identified and organized with backtracking information record and timeline. A minimal and necessary set of log records, snapshots and checkpoints enabling database reconstruction within a time window is maintained. Measures are taken to maintain the necessary data to support backtracking even after prior backtrackings have occurred in the backtracking time window.Type: ApplicationFiled: May 9, 2024Publication date: November 13, 2025Applicant: HUAWEI CLOUD COMPUTING TECHNOLOGIES CO., LTD.Inventors: Guanzhu XIONG, Alexandre DEPOUTOVITCH, Lengdong WU, Chong CHEN, Cheng ZHAO, Jack Hon Wai NG, Shu LIN
-
Patent number: 12463902Abstract: Techniques for deploying IPv6 routing are disclosed. A system, process, and/or computer program product for deploying IPv6 routing includes advertising in Border Gateway Protocol (BGP) a new address-family capability in combination with an existing address-family in a network that supports a plurality of address families, and undoing BGP filters to allow BGP routes to be exchanged at a time that a network administrator enables the new address-family capability in the network.Type: GrantFiled: October 6, 2022Date of Patent: November 4, 2025Assignee: Palo Alto Networks, Inc.Inventors: Jia Chen, Shu Lin, Jining Tian, Enke Chen
-
Publication number: 20250330441Abstract: Described herein are systems, methods, and software to enhance failover operations in a cloud computing environment. In one implementation, a method of operating a first service instance in a cloud computing environment includes obtaining a communication from a computing asset, wherein the communication comprises a first destination address. The method further provides replacing the first destination address with a second destination address in the communication, wherein the second destination address comprises a shared address for failover from a second service instance. After replacing the address, the method determines whether the communication is permitted based on the second destination address, and if permitted, processes the communication in accordance with a service executing on the service instance.Type: ApplicationFiled: June 30, 2025Publication date: October 23, 2025Inventors: Shu Lin, Patrick Xu, Eswar Rao Sadaram, Hao Long
-
Patent number: 12411847Abstract: There is provided a method and apparatus for optimizing a database query. Embodiments expand the scope of query optimization to two or more query optimizers. Therefore, a larger class of plan trees can be explored, and a more optimal (for example faster) physical plan may be chosen for execution. The query will continue to be executed by the “original”, “home” or “first” query execution engine, and therefore, a translation or conversion mechanism is be put into place that is able to convert the chosen physical plan into a format that is acceptable to the original optimizer.Type: GrantFiled: December 29, 2022Date of Patent: September 9, 2025Assignee: HUAWEI CLOUD COMPUTING TECHNOLOGIES CO., LTD.Inventors: Arunprasad P. Marathe, Shu Lin
-
Publication number: 20250279961Abstract: Techniques for supporting overlapping network addresses universally are disclosed. A system, process, and/or computer program product for supporting overlapping network addresses universally includes generating at least two virtual routers for a cloud security service, the at least two virtual routers including a first virtual router and a second virtual router, routing cloud security service packets using the first virtual router, and routing enterprise subscriber packets using the second virtual router.Type: ApplicationFiled: May 15, 2025Publication date: September 4, 2025Inventors: Jia Chen, Hao Long, Shu Lin
-
Patent number: 12401585Abstract: Techniques for deploying symmetric routing are disclosed. A system, process, and/or computer program product for deploying symmetric routing includes routing network traffic from a client over a security access network provider virtual private network (VPN) access to a customer network, and enforcing symmetric routing crossing an autonomous system (AS) based on one or more prepended AS routing numbers in a first routing table for inbound traffic and/or based on one or more weights and one or more local preferences in a second routing table for outbound traffic.Type: GrantFiled: January 31, 2023Date of Patent: August 26, 2025Assignee: Palo Alto Networks, Inc.Inventors: Jia Chen, Saurabh Dixit, Anil Saini, Shu Lin, Hao Long
-
Device for in-situ measurement of substance migration and transformation on sediment-water interface
Patent number: 12385810Abstract: A device for in-situ measurement of substance migration and transformation on a sediment-water interface includes a floating platform. Three take-up and pay-off components are fixedly connected to the edge of a top surface of the floating platform. Each take-up and pay-off component comprises an L-shaped base, a cable take-up and pay-off assembly, vertical rods, a guide sheave wheel, an adjustment assembly and a first cable. Two DGT samplers are fixedly connected to bottom ends of two three take-up and pay-off components. Water quality monitoring sensors are fixedly connected to the two first cables fixedly connected to the two DGT samplers, respectively. A sediment collector is fixedly connected to a bottom end of the other take-up and pay-off component. Sampling can be performed in-situ directly through DGT flat plates to avoid the impact of environmental changes.Type: GrantFiled: March 9, 2023Date of Patent: August 12, 2025Assignee: SOUTH CHINA INSTITUTE OF ENVIRONMENTAL SCIENCE, MEE (ECOLOGICAL AND ENVIRONMENTAL EMERGENCY RESEARCH INSTITUTE, MEE)Inventors: Weijie Li, Shu Lin, Jiale Chen, Runmian Yang, Huaiyang Fang, Xiaobao Li -
Patent number: 12363062Abstract: Described herein are systems, methods, and software to enhance failover operations in a cloud computing environment. In one implementation, a method of operating a first service instance in a cloud computing environment includes obtaining a communication from a computing asset, wherein the communication comprises a first destination address. The method further provides replacing the first destination address with a second destination address in the communication, wherein the second destination address comprises a shared address for failover from a second service instance. After replacing the address, the method determines whether the communication is permitted based on the second destination address, and if permitted, processes the communication in accordance with a service executing on the service instance.Type: GrantFiled: September 12, 2023Date of Patent: July 15, 2025Assignee: Palo Alto Networks, Inc.Inventors: Shu Lin, Patrick Xu, Eswar Rao Sadaram, Hao Long
-
Patent number: 12328256Abstract: Techniques for supporting overlapping network addresses universally are disclosed. A system, process, and/or computer program product for supporting overlapping network addresses universally includes generating at least two virtual routers for a cloud security service, the at least two virtual routers including a first virtual router and a second virtual router, routing cloud security service packets using the first virtual router, and routing enterprise subscriber packets using the second virtual router.Type: GrantFiled: August 10, 2022Date of Patent: June 10, 2025Assignee: Palo Alto Networks, Inc.Inventors: Jia Chen, Hao Long, Shu Lin
-
Patent number: 12313500Abstract: A leakage quick-detection device for drainage pipes comprises an operating rod assembly, a development module and a probe assembly. The development module comprises a receiving shell. A development board is fixedly connected into the receiving shell. A receiving and transmitting antenna is fixedly connected to the receiving shell and is electrically connected to the development board. The probe assembly comprises a composite platform. Four threaded through-holes are vertically and regularly formed in the composite platform. The change of water flow and water quality can be quickly reflected by ultrasonic data, conductivity data and flow data; compared with a traditional visual detection method, the detection dimensions are richer, the working time of personnel is shortened, more water flow information can be obtained, the labor intensity is reduced, and the troubleshooting accuracy is improved.Type: GrantFiled: March 9, 2023Date of Patent: May 27, 2025Assignee: SOUTH CHINA INSTITUTE OF ENVIRONMENTAL SCIENCE, MEE (ECOLOGICAL AND ENVIRONMENTAL EMERGENCYInventors: Huaiyang Fang, Weijie Li, Jiale Chen, Zhiwei Huang, Shu Lin, Fantang Zeng