Patents by Inventor Shu Lin

Shu Lin has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12665875
    Abstract: Techniques for providing a networking and security split architecture are disclosed. In some embodiments, a system, process, and/or computer program product for providing a networking and security split architecture includes receiving a flow at a security service; processing the flow at a network layer of the security service to perform one or more networking functions; and offloading the flow to a security layer of the security service to perform security enforcement based on a policy.
    Type: Grant
    Filed: July 16, 2024
    Date of Patent: June 23, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Thomas Arthur Warburton, Hao Long, Shu Lin, Mingfei Peng
  • Publication number: 20260121852
    Abstract: While organizations can employ IPsec based VPNs to securely connect different sites (e.g., branch sites, data centers, and/or virtual private clouds), the security can disrupt network performance by obfuscating information used for load balancing. Disclosed is technology that employs minimal decryption in a secure manner to load balance multiple network traffic flows within a secure connection (“tunnel”) across security appliances that effectively operate as alternative endpoints for the tunnel. The security appliances within a load balancing pool are configured/programmed to share tunnel keys with each other after tunnel establishment and with the load balancer. The load balancer uses the tunnel keys to minimally decrypt in a lookaside memory encrypted packets to ascertain N-tuples, The load balancer then uses the N-tuples to load balance the flows within a tunnel across the security appliances.
    Type: Application
    Filed: December 26, 2025
    Publication date: April 30, 2026
    Inventors: Fang Lu, Peng Chen, Shu Lin
  • Publication number: 20260113304
    Abstract: An orchestrator that manages security appliances for an organization determines a sink configured for traffic mirroring and correspondingly configures components for the correlation and secure conveyance. The orchestrator also configures the security appliances. The orchestrator configures the security appliances to copy cryptographic keys (hereinafter “tunnel keys”) and identifiers associated with the keys of secure VPN tunnels established by the security appliances to a repository of the cloud-service provider. The orchestrator configures a virtual machine associated with the mirroring sink with correlation logic. The virtual machine correlates sets of packets aggregated across different mirroring streams and tunnel keys with the associated identifiers. Correlating the sets of packets and the tunnel keys allows an organization to efficiently access the content of the encrypted packets or facilitates secure conveyance.
    Type: Application
    Filed: December 17, 2025
    Publication date: April 23, 2026
    Inventors: Tushar Vyankatesh Nargunde, Zhanglin He, Tripti Agarwal, Shu Lin, Jose Carlos Sagrero Dominguez
  • Publication number: 20260081894
    Abstract: Traffic log data generated by cloud firewalls executing in a cloud environment during a time period that indicate classes and corresponding amounts of network traffic detected across sessions as well as usage cost data recorded for the cloud firewalls during the time period are obtained. The traffic log data are preprocessed to generate training data comprising feature vectors indicating the aggregate amount of network traffic detected for each traffic class during a corresponding time interval within the time period and are labeled with the associated usage cost. A machine learning model is trained on the labeled traffic log data to learn the impact each traffic class has on the accumulated usage costs. The trained model generates predicted usage costs based on distributions of detected network traffic across traffic classes that are analyzed to correlate traffic patterns with usage costs to determine the optimal size(s) of cloud firewalls to deploy.
    Type: Application
    Filed: November 21, 2025
    Publication date: March 19, 2026
    Inventors: Shangde Zhou, Sheng Meng, Shu Lin
  • Publication number: 20260067212
    Abstract: Techniques for deploying IPv6 routing are disclosed. A system, process, and/or computer program product for deploying IPv6 routing includes advertising in Border Gateway Protocol (BGP) a new address-family capability in combination with an existing address-family in a network that supports a plurality of address families, and undoing BGP filters to allow BGP routes to be exchanged at a time that a network administrator enables the new address-family capability in the network.
    Type: Application
    Filed: September 5, 2025
    Publication date: March 5, 2026
    Inventors: Jia Chen, Shu Lin, Jining Tian, Enke Chen
  • Publication number: 20260049481
    Abstract: The present application provides a locking assembly and a wooden slat device, the locking assembly comprising a locking body and a telescopic rod; the locking body is provided with a first through-hole, and the telescopic rod is telescopically attached to the locking body; the telescopic rod is provided with a second through-hole, the second through-hole penetrating the telescopic rod and selectively connected or spaced apart from the first through-hole; the second through-hole is provided with an opening, and the opening opens or closes with the telescopic rod's telescope so that the second through-hole is connected or spaced apart from the second through-hole is provided with an opening that opens or closes as the telescoping rod is telescoped, so that the second through-hole is connected or spaced apart from the first through-hole.
    Type: Application
    Filed: September 20, 2024
    Publication date: February 19, 2026
    Inventor: Shu Lin
  • Patent number: 12549352
    Abstract: While organizations can employ IPsec based VPNs to securely connect different sites (e.g., branch sites, data centers, and/or virtual private clouds), the security can disrupt network performance by obfuscating information used for load balancing. Disclosed is technology that employs minimal decryption in a secure manner to load balance multiple network traffic flows within a secure connection (“tunnel”) across security appliances that effectively operate as alternative endpoints for the tunnel. The security appliances within a load balancing pool are configured/programmed to share tunnel keys with each other after tunnel establishment and with the load balancer. The load balancer uses the tunnel keys to minimally decrypt in a lookaside memory encrypted packets to ascertain N-tuples. The load balancer then uses the N-tuples to load balance the flows within a tunnel across the security appliances.
    Type: Grant
    Filed: July 27, 2023
    Date of Patent: February 10, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Fang Lu, Peng Chen, Shu Lin
  • Patent number: 12537797
    Abstract: An orchestrator that manages security appliances for an organization determines a sink configured for traffic mirroring and correspondingly configures components for the correlation and secure conveyance. The orchestrator also configures the security appliances. The orchestrator configures the security appliances to copy cryptographic keys (hereinafter “tunnel keys”) and identifiers associated with the keys of secure VPN tunnels established by the security appliances to a repository of the cloud-service provider. The orchestrator configures a virtual machine associated with the mirroring sink with correlation logic. The virtual machine correlates sets of packets aggregated across different mirroring streams and tunnel keys with the associated identifiers. Correlating the sets of packets and the tunnel keys allows an organization to efficiently access the content of the encrypted packets or facilitates secure conveyance.
    Type: Grant
    Filed: July 31, 2023
    Date of Patent: January 27, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Tushar Vyankatesh Nargunde, Zhanglin He, Tripti Agarwal, Shu Lin, Jose Carlos Sagrero Dominguez
  • Patent number: 12526256
    Abstract: Traffic log data generated by cloud firewalls executing in a cloud environment during a time period that indicate classes and corresponding amounts of network traffic detected across sessions as well as usage cost data recorded for the cloud firewalls during the time period are obtained. The traffic log data are preprocessed to generate training data comprising feature vectors indicating the aggregate amount of network traffic detected for each traffic class during a corresponding time interval within the time period and are labeled with the associated usage cost. A machine learning model is trained on the labeled traffic log data to learn the impact each traffic class has on the accumulated usage costs. The trained model generates predicted usage costs based on distributions of detected network traffic across traffic classes that are analyzed to correlate traffic patterns with usage costs to determine the optimal size(s) of cloud firewalls to deploy.
    Type: Grant
    Filed: December 21, 2021
    Date of Patent: January 13, 2026
    Assignee: Palo Alto Networks, Inc.
    Inventors: Shangde Zhou, Sheng Meng, Shu Lin
  • Publication number: 20250358214
    Abstract: Techniques for deploying symmetric routing are disclosed. A system, process, and/or computer program product for deploying symmetric routing includes routing network traffic from a client over a security access network provider virtual private network (VPN) access to a customer network, and enforcing symmetric routing crossing an autonomous system (AS) based on one or more prepended AS routing numbers in a first routing table for inbound traffic and/or based on one or more weights and one or more local preferences in a second routing table for outbound traffic.
    Type: Application
    Filed: July 31, 2025
    Publication date: November 20, 2025
    Inventors: Jia Chen, Saurabh Dixit, Anil Saini, Shu Lin, Hao Long
  • Publication number: 20250348386
    Abstract: Support for distributed database backtracking, in which the database is reverted or iteratively reverted to a previous state, is provided. Log sequence number ranges and storage offset ranges for use in reconstructing the previous state are determined and used in the reconstruction. Clock sampling records can be generated indicating a feasible backtracking window with time points indicating allowable times to which backtracking can be performed. Appropriate log records, snapshots and checkpoints for database states are identified and organized with backtracking information record and timeline. A minimal and necessary set of log records, snapshots and checkpoints enabling database reconstruction within a time window is maintained. Measures are taken to maintain the necessary data to support backtracking even after prior backtrackings have occurred in the backtracking time window.
    Type: Application
    Filed: May 9, 2024
    Publication date: November 13, 2025
    Applicant: HUAWEI CLOUD COMPUTING TECHNOLOGIES CO., LTD.
    Inventors: Guanzhu XIONG, Alexandre DEPOUTOVITCH, Lengdong WU, Chong CHEN, Cheng ZHAO, Jack Hon Wai NG, Shu LIN
  • Patent number: 12463902
    Abstract: Techniques for deploying IPv6 routing are disclosed. A system, process, and/or computer program product for deploying IPv6 routing includes advertising in Border Gateway Protocol (BGP) a new address-family capability in combination with an existing address-family in a network that supports a plurality of address families, and undoing BGP filters to allow BGP routes to be exchanged at a time that a network administrator enables the new address-family capability in the network.
    Type: Grant
    Filed: October 6, 2022
    Date of Patent: November 4, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jia Chen, Shu Lin, Jining Tian, Enke Chen
  • Publication number: 20250330441
    Abstract: Described herein are systems, methods, and software to enhance failover operations in a cloud computing environment. In one implementation, a method of operating a first service instance in a cloud computing environment includes obtaining a communication from a computing asset, wherein the communication comprises a first destination address. The method further provides replacing the first destination address with a second destination address in the communication, wherein the second destination address comprises a shared address for failover from a second service instance. After replacing the address, the method determines whether the communication is permitted based on the second destination address, and if permitted, processes the communication in accordance with a service executing on the service instance.
    Type: Application
    Filed: June 30, 2025
    Publication date: October 23, 2025
    Inventors: Shu Lin, Patrick Xu, Eswar Rao Sadaram, Hao Long
  • Patent number: 12411847
    Abstract: There is provided a method and apparatus for optimizing a database query. Embodiments expand the scope of query optimization to two or more query optimizers. Therefore, a larger class of plan trees can be explored, and a more optimal (for example faster) physical plan may be chosen for execution. The query will continue to be executed by the “original”, “home” or “first” query execution engine, and therefore, a translation or conversion mechanism is be put into place that is able to convert the chosen physical plan into a format that is acceptable to the original optimizer.
    Type: Grant
    Filed: December 29, 2022
    Date of Patent: September 9, 2025
    Assignee: HUAWEI CLOUD COMPUTING TECHNOLOGIES CO., LTD.
    Inventors: Arunprasad P. Marathe, Shu Lin
  • Publication number: 20250279961
    Abstract: Techniques for supporting overlapping network addresses universally are disclosed. A system, process, and/or computer program product for supporting overlapping network addresses universally includes generating at least two virtual routers for a cloud security service, the at least two virtual routers including a first virtual router and a second virtual router, routing cloud security service packets using the first virtual router, and routing enterprise subscriber packets using the second virtual router.
    Type: Application
    Filed: May 15, 2025
    Publication date: September 4, 2025
    Inventors: Jia Chen, Hao Long, Shu Lin
  • Patent number: 12401585
    Abstract: Techniques for deploying symmetric routing are disclosed. A system, process, and/or computer program product for deploying symmetric routing includes routing network traffic from a client over a security access network provider virtual private network (VPN) access to a customer network, and enforcing symmetric routing crossing an autonomous system (AS) based on one or more prepended AS routing numbers in a first routing table for inbound traffic and/or based on one or more weights and one or more local preferences in a second routing table for outbound traffic.
    Type: Grant
    Filed: January 31, 2023
    Date of Patent: August 26, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jia Chen, Saurabh Dixit, Anil Saini, Shu Lin, Hao Long
  • Patent number: 12385810
    Abstract: A device for in-situ measurement of substance migration and transformation on a sediment-water interface includes a floating platform. Three take-up and pay-off components are fixedly connected to the edge of a top surface of the floating platform. Each take-up and pay-off component comprises an L-shaped base, a cable take-up and pay-off assembly, vertical rods, a guide sheave wheel, an adjustment assembly and a first cable. Two DGT samplers are fixedly connected to bottom ends of two three take-up and pay-off components. Water quality monitoring sensors are fixedly connected to the two first cables fixedly connected to the two DGT samplers, respectively. A sediment collector is fixedly connected to a bottom end of the other take-up and pay-off component. Sampling can be performed in-situ directly through DGT flat plates to avoid the impact of environmental changes.
    Type: Grant
    Filed: March 9, 2023
    Date of Patent: August 12, 2025
    Assignee: SOUTH CHINA INSTITUTE OF ENVIRONMENTAL SCIENCE, MEE (ECOLOGICAL AND ENVIRONMENTAL EMERGENCY RESEARCH INSTITUTE, MEE)
    Inventors: Weijie Li, Shu Lin, Jiale Chen, Runmian Yang, Huaiyang Fang, Xiaobao Li
  • Patent number: 12363062
    Abstract: Described herein are systems, methods, and software to enhance failover operations in a cloud computing environment. In one implementation, a method of operating a first service instance in a cloud computing environment includes obtaining a communication from a computing asset, wherein the communication comprises a first destination address. The method further provides replacing the first destination address with a second destination address in the communication, wherein the second destination address comprises a shared address for failover from a second service instance. After replacing the address, the method determines whether the communication is permitted based on the second destination address, and if permitted, processes the communication in accordance with a service executing on the service instance.
    Type: Grant
    Filed: September 12, 2023
    Date of Patent: July 15, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Shu Lin, Patrick Xu, Eswar Rao Sadaram, Hao Long
  • Patent number: 12328256
    Abstract: Techniques for supporting overlapping network addresses universally are disclosed. A system, process, and/or computer program product for supporting overlapping network addresses universally includes generating at least two virtual routers for a cloud security service, the at least two virtual routers including a first virtual router and a second virtual router, routing cloud security service packets using the first virtual router, and routing enterprise subscriber packets using the second virtual router.
    Type: Grant
    Filed: August 10, 2022
    Date of Patent: June 10, 2025
    Assignee: Palo Alto Networks, Inc.
    Inventors: Jia Chen, Hao Long, Shu Lin
  • Patent number: 12313500
    Abstract: A leakage quick-detection device for drainage pipes comprises an operating rod assembly, a development module and a probe assembly. The development module comprises a receiving shell. A development board is fixedly connected into the receiving shell. A receiving and transmitting antenna is fixedly connected to the receiving shell and is electrically connected to the development board. The probe assembly comprises a composite platform. Four threaded through-holes are vertically and regularly formed in the composite platform. The change of water flow and water quality can be quickly reflected by ultrasonic data, conductivity data and flow data; compared with a traditional visual detection method, the detection dimensions are richer, the working time of personnel is shortened, more water flow information can be obtained, the labor intensity is reduced, and the troubleshooting accuracy is improved.
    Type: Grant
    Filed: March 9, 2023
    Date of Patent: May 27, 2025
    Assignee: SOUTH CHINA INSTITUTE OF ENVIRONMENTAL SCIENCE, MEE (ECOLOGICAL AND ENVIRONMENTAL EMERGENCY
    Inventors: Huaiyang Fang, Weijie Li, Jiale Chen, Zhiwei Huang, Shu Lin, Fantang Zeng