IP Library Granted Patent US 12,726,455
Granted Patent B2
US 12,726,455 · App. 17/315,192 · Granted Sep 1, 2026

Managing access to cloud-hosted applications using domain name resolution

Inventors: Sidhesh Divekar (Milpitas, CA); Linus Aranha (Los Gato, CA); Santosh Ghanshyam Pandey (Fremont, CA)
Assignee: Palo Alto Networks, Inc.
H04L61/35H04L61/2503H04L61/4511H04L63/0869H04L67/101H04L67/60H04L2101/69
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,455
App. No.
17/315,192
Granted
Sep 1, 2026
Kind
B2
Abstract

Edge clusters execute in a plurality of regional clouds of a cloud computing platforms, which may include cloud POPs. Edge clusters may be programmed to control access to applications executing in the cloud computing platform. Edge clusters and an intelligent routing module route traffic to applications executing in the cloud computing platform. Cost and latency may be managed by the intelligent routing module by routing requests over the Internet or a cloud backbone network and using or bypassing cloud POPs. The placement of edge clusters may be selected according to measured or estimated latency. Latency may be estimated using speed test servers and the locations of speed test servers may be verified.

Claims (57)

1 . A method comprising:

instantiating a plurality of edge clusters on one or more cloud computing platforms, each edge cluster being located in a different regional cloud of a plurality of regional clouds in the one or more cloud computing platforms, the regional clouds being connected to one another by one or more cloud backbone networks, the plurality of regional clouds being further connected to a wide area network (WAN) that does not include the one or more cloud backbone networks;

instantiating an application instance in a first regional cloud of the plurality of regional clouds, a first edge cluster of the plurality of edge clusters executing in the first regional cloud and having a first internet protocol (IP) address;

programming, by an intelligent routing module, domain name resolution logic of the one or more cloud computing platforms to manage latency of requests to access the application instance from locations in multiple regional clouds of the plurality of regional clouds; and

configuring, by the intelligent routing module, one or more edge clusters of the plurality of edge clusters with alternative routing logic such that the intelligent routing module, the first edge cluster, and a second edge cluster of the plurality of edge clusters are configured to perform a method including:

resolving, by the intelligent routing module, a domain of the application instance to a second IP address of the second edge cluster;

receiving, by the second edge cluster, a request to access the application instance, the request addressed to the second IP address;

routing, by the second edge cluster, the request to the first IP address according to the alternative routing logic.

2 . The method of claim 1 , wherein programming the domain name resolution logic of the one or more cloud computing platforms comprises:

programming a geographic domain name service (GeoDNS) of the one or more cloud computing platforms to resolve a domain name associated with the application instance to an IP address according to a location of an endpoint requesting resolution of the domain name.

3 . The method of claim 2 , wherein the IP address is a static IP address.

4 . The method of claim 2 , wherein the IP address is an Anycast IP address.

5 . The method of claim 2 , further comprising:

programming, by the intelligent routing module, the GeoDNS of the one or more cloud computing platforms such that for first user endpoints accessing the application instance using a first portion of the plurality of regional clouds, a domain name of the application instances is resolved to an Anycast IP address; and

programming, by the intelligent routing module, the GeoDNS of the one or more cloud computing platforms such that for second user endpoints accessing the application instance within second first portion of the plurality of regional clouds, a domain name of the application instances is resolved to a static IP address.

6 . The method of claim 1 , further comprising configuring the second edge cluster, by the alternative routing logic, to route the request to the first IP address by providing the first IP address to a source of the request.

7 . The method of claim 1 , further comprising:

receiving, by the intelligent routing module, a first lane selection;

determining, by the intelligent routing module, that the first lane selection is selection of a fast lane; and

in response to determining that the first lane selection is selection of the fast lane, programming, by the intelligent routing module, the domain name resolution logic to associate a domain name of the application instance with an Anycast IP address such that requests addressed to the domain name are routed over the one or more cloud backbone networks.

8 . The method of claim 7 , further comprising:

receiving, by the intelligent routing module a second lane selection;

determining, by the intelligent routing module that the second lane selection is selection of a cost effective lane; and

in response to determining that the first lane selection is selection of the cost effective lane, programming, by the intelligent routing module, the domain name resolution logic to associate the domain name of the application instance with a static IP address such that requests addressed to the domain name are routed over the one or more cloud backbone networks.

9 . The method of claim 8 , further comprising:

receiving, by the intelligent routing module a third lane selection;

determining, by the intelligent routing module that the second lane selection is selection of a performance lane; and

in response to determining that the first lane selection is selection of the performance lane, programming, by the intelligent routing module, the domain name resolution logic to associate the domain name of the application instance with a static IP address such that requests addressed to the domain name are routed over the one or more cloud backbone networks with ingress to the one or more cloud computing platforms in bypass of points of presence (POP) of the one or more cloud computing platforms.

10 . The method of claim 1 , wherein the WAN includes any of the Internet, a 5G Cellular Network, and a LONG TERM EVOLUTION (LTE) cellular network.

11 . A system comprising:

a cloud computing platform comprising a plurality of regional clouds connected by a cloud backbone network, each regional cloud comprising a plurality of computing devices associated with a geographic region and connected by a regional network, the plurality of regional clouds being further connected to a wide area network (WAN) that does not include the cloud backbone network;

a plurality of edge clusters on the cloud computing platform, each edge cluster being located in a different regional cloud of the plurality of regional clouds; and

an intelligent routing module coupled to the plurality of edge clusters and programmed to:

invoke instantiation of an application instance in a first regional cloud of the plurality of regional clouds having a first edge cluster of the plurality of edge clusters executing in the first regional cloud, the first edge cluster having a first internet protocol (IP) address;

configure the first edge cluster to control access to the application instance; and

program domain name resolution logic of the cloud computing platform to manage latency of requests to access the application instance from locations in multiple regional clouds of the plurality of regional clouds;

configuring, by the intelligent routing module, one or more edge clusters of the plurality of edge clusters with alternative routing logic such that the intelligent routing module, the first edge cluster, and a second edge cluster of the plurality of edge clusters are configured to perform a method including:

resolving, by the intelligent routing module, a domain of the application instance to a second IP address of the second edge cluster;

receiving, by the second edge cluster, a request to access the application instance, the request addressed to the second IP address;

routing, by the second edge cluster, the request to the first IP address according to the alternative routing logic.

12 . The system of claim 11 , wherein the intelligent routing module is further programmed to program the domain name resolution logic of the cloud computing platforms by:

programming a geographic domain name service (GeoDNS) of the cloud computing platform to resolve a domain name associated with the application instance to an IP address according to a location of an endpoint requesting resolution of the domain name.

13 . The system of claim 12 , wherein the IP address is a static IP address.

14 . The system of claim 12 , wherein the IP address is an Anycast IP address.

15 . The system of claim 12 , wherein the intelligent routing module is further programmed to program the domain name resolution logic of the cloud computing platform by:

programming the GeoDNS of the cloud computing platforms such that for first user endpoints accessing the application instance using a first portion of the plurality of regional clouds, a domain name of the application instances is resolved to an Anycast IP address; and

programming the GeoDNS of the cloud computing platforms such that for second user endpoints accessing the application instance within second first portion of the plurality of regional clouds, a domain name of the application instances is resolved to a static IP address.

16 . The system of claim 11 , wherein the intelligent routing module is further programmed to:

configure the second edge cluster to route the request to the first IP address by providing the first IP address to a source of the request.

17 . The system of claim 11 , wherein the intelligent routing module is further programmed to:

receive a lane selection;

if the lane selection is selection of a fast lane, program the domain name resolution logic to associate a domain name of the application instance with an Anycast IP address such that requests addressed to the domain name are routed over the cloud backbone networks.

18 . The system of claim 17 , wherein the intelligent routing module is further programmed to:

if the lane selection is selection of a performance lane, program the domain name resolution logic to associate the domain name of the application instance with a static IP address such that requests addressed to the domain name are routed over the cloud backbone networks.

19 . The system of claim 18 , wherein the intelligent routing module is further programmed to:

if the lane selection is selection of a performance lane, program the domain name resolution logic to associate the domain name of the application instance with a static IP address such that requests addressed to the domain name are routed over the cloud backbone networks with ingress to the cloud computing platforms in bypass of points of presence (POP) of the cloud computing platforms.

20 . The system of claim 11 , wherein the WAN includes any of the Internet, a 5G Cellular Network, and a LONG TERM EVOLUTION (LTE) cellular network.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2025
From: PROSIMO INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 071425/0477 →
RELEASE OF SECURITY INTEREST Recorded Jan 24, 2025
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: PROSIMO INC.
Reel/Frame 069996/0300 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE RECEIVING PARTY PREVIOUSLY RECORDED ON REEL 56176 FRAME 979. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 15, 2025
From: DIVEKAR, SIDHESH; ARANHA, LINUS; PANDEY, SANTOSH GHANSHYAM
To: PROSIMO INC.
Reel/Frame 069932/0990 →
SECURITY INTEREST Recorded Sep 27, 2024
From: PROSIMO INC.
To: FIRST-CITIZENS BANK & TRUST COMPANY
Reel/Frame 068719/0171 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2021
From: DIVEKAR, SIDHESH; ARANHA, LINUS; PANDEY, SANTOSH GHANSHYAM
To: PROSIMO INC
Reel/Frame 056176/0979 →
Continuity (2)
Continuation In Part 17127876 · Dec 18, 2020
Related Publication 20220200954A1 · Jun 23, 2022
References Cited (41)
US 7904541B2 · Swildens et al. · 2011 [cited by applicant]
US 8949459B1 · Scholl · 2015 [cited by applicant]
US 9391856B2 · Kazerani · 2016 [cited by examiner]
US 10218781B2 · Byers et al. · 2019 [cited by applicant]
US 10887276B1 · Parulkar et al. · 2021 [cited by applicant]
US 11070453B2 · Thiagarajan et al. · 2021 [cited by applicant]
US 11095534B1 · Dunsmore et al. · 2021 [cited by applicant]
US 11128597B1 · Johnson · 2021 [cited by examiner]
US 11201915B1 · Mesard · 2021 [cited by examiner]
US 11252126B1 · Thunga · 2022 [cited by examiner]
US 11394636B1 · Walker · 2022 [cited by examiner]
US 20120124194A1 · Shouraboura · 2012 [cited by applicant]
US 20150188823A1 · Williams et al. · 2015 [cited by applicant]
US 20160119279A1 · Maslak · 2016 [cited by examiner]
US 20160191600A1 · Scharber · 2016 [cited by examiner]
US 20170310709A1 · Foxhoven · 2017 [cited by examiner]
US 20170317954A1 · Masurekar et al. · 2017 [cited by applicant]
US 20200076685A1 · Vaidya et al. · 2020 [cited by applicant]
US 20200099659A1 · Cometto · 2020 [cited by examiner]
US 20200162386A1 · Radlein et al. · 2020 [cited by applicant]
US 20210075729A1 · Fedorov et al. · 2021 [cited by applicant]
US 20210314291A1 · Chandrashekhar et al. · 2021 [cited by applicant]
US 20210328893A1 · Cherkas et al. · 2021 [cited by applicant]
US 20220060431A1 · Vadayadiyil Raveendran et al. · 2022 [cited by applicant]
US 20220200957A1 · Prabagaran et al. · 2022 [cited by applicant]
US 20220353168A1 · Hegde et al. · 2022 [cited by applicant]
US 20220377131A1 · Szilagyi et al. · 2022 [cited by applicant]
US 20220394088A1 · Salkintzis · 2022 [cited by examiner]
US 20230037031A1 · Wang · 2023 [cited by examiner]
US 20240380654A1 · Zaicenko et al. · 2024 [cited by applicant]
U.S. Appl. No. 17/127,876, Notice of Allowance mailed Oct. 15, 2025, 6 pages. [cited by applicant]
U.S. Appl. No. 17/315,167, Notice of Allowance mailed Oct. 15, 2025, 9 pages. [cited by applicant]
U.S. Appl. No. 17/127,876, Non-Final Office Action mailed Nov. 28, 2025, 15 pages. [cited by applicant]
U.S. Appl. No. 17/127,876, Non-Final Office Action mailed Nov. 3, 2022, 16 pages. [cited by applicant]
U.S. Appl. No. 17/315,167, Notice of Allowance mailed Dec. 5, 2025, 10 pages. [cited by applicant]
U.S. Appl. No. 17/315,175, Non-Final Office Action mailed Dec. 22, 2022, 25 pages. [cited by applicant]
U.S. Appl. No. 18/530,458, Final Office Action mailed Jan. 27, 2026, 11 pages. [cited by applicant]
U.S. Appl. No. 18/530,458, Non-Final Office Action mailed Jul. 15, 2025, 10 Pages. [cited by applicant]
U.S. Appl. No. 17/315,167, Non-Final Office Action mailed Dec. 21, 2022, 13 pages. [cited by applicant]
Li, et al., “Internet Anycast: Performance, Problems, & Potential”, Aug. 25, 2018, SIGCOMM '18, Aug. 20-25, 2018, Budapest, Hungary ACM ISBN 978-1-4503-5567-Apr. 18, 08, https://doi.org/10.1145/3230543.3230547, 15 pages. [cited by applicant]
Yu, et al., “A Survey on the Edge Computing for the Internet of Things”, Nov. 29, 2017, Digital Object Identifier 10.1109/ ACCESS.2017.2778504, vol. 6, 2018, pp. 6900-6919. (Year: 2017). [cited by applicant]