IP Library Granted Patent US 12,694,138
Granted Patent B2
US 12,694,138 · App. 18/179,860 · Granted Jul 28, 2026

Data packet sharding for secure network transmission

Inventors: Michael Y. Frankel (Hallandale Beach, FL); James Carnes (Baltimore, MD); Vladimir Pelekhaty (Baltimore, MD)
Assignee: CIENA CORPORATION
G06F21/6209H04L9/0822H04L45/02H04L45/24
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,694,138
App. No.
18/179,860
Granted
Jul 28, 2026
Kind
B2
Abstract

Aspects of the subject disclosure may include, for example, receiving one or more blocks of data for transmission to a destination, splitting the one or more blocks of data into a plurality of data shards, and communicating the plurality of data shards to the destination, wherein the communicating comprises providing a respective data shard of the plurality of data shards to a respective physical path of a plurality of physical paths to increase data security during the communicating. Other embodiments are disclosed.

Claims (69)

1 . A device, comprising:

a processing system including a processor; and

a memory that stores executable instructions that, when executed by the processing system, facilitate performance of operations, the operations comprising:

receiving, at a first network endpoint, one or more units of data for transmission to a destination at a second network endpoint, the destination being one destination of a plurality of network destinations;

accumulating the one or more units of data into a block of data for transmission to the destination at the second network endpoint, the accumulating being according to the destination as a common destination for the one or more units of data among the plurality of network destinations;

splitting the one or more units of data into a plurality of data shards, wherein the splitting is according to a key to define partitioning of the one or more units of data into the plurality of data shards;

selecting a plurality of diverse physical paths for communication of information between the first network endpoint and the destination at the second network endpoint for data security during the communication of information;

adding to each data shard of the plurality of data shards a header including information defining the respective physical path of the plurality of diverse physical paths for each data shard; and

communicating the plurality of data shards from the first network endpoint to the destination at the second network endpoint, wherein the communicating comprises providing a respective data shard of the plurality of data shards to a respective physical path of the plurality of diverse physical paths according to the information defining the respective physical path, forming a terminated security service between the first network endpoint and the second network endpoint to increase data security during the communicating.

2 . The device of claim 1 , wherein the operations further comprise:

encrypting at least some data shards of the plurality of data shards, forming encrypted data shards; and

communicating the encrypted data shards over at least one physical path of the plurality of diverse physical paths.

3 . The device of claim 2 , wherein the encrypting at least some data shards comprises:

selecting a subset of data shards of the plurality of data shards, forming shard data for encryption; and

applying a multi-path digital encryption algorithm to the shard data for encryption.

4 . The device of claim 2 , wherein the operations further comprise:

selecting a single data shard of the plurality of data shards for encryption, forming an encrypted data shard; and

communicating the encrypted data shard and other data shards of the plurality of data shards over respective physical paths of the plurality of diverse physical paths.

5 . The device of claim 1 , wherein the operations further comprise:

applying an error correction algorithm to respective data shards of the plurality of data shards, forming error corrected data shards; and

communicating the error corrected data shards to the destination on respective physical paths of the plurality of diverse physical paths.

6 . The device of claim 1 , wherein the operations further comprise:

applying a respective unique label to each respective data shard of the plurality of data shards, wherein each respective unique label corresponds to a unique respective physical path of the plurality of diverse physical paths; and

providing each respective data shard to each physical data path according to each respective unique label.

7 . The device of claim 1 , wherein the operations further comprise:

selecting a unique optical fiber of an optical network; and

assigning the unique optical fiber as a respective physical path of the plurality of diverse physical paths.

8 . The device of claim 1 , wherein the operations further comprise:

selecting a unique wavelength of a wavelength-division multiplexing communication system; and

assigning the unique wavelength as a respective physical path of the plurality of diverse physical paths.

9 . The device of claim 1 , wherein the operations further comprise:

selecting a unique radio resource of a radio communication system; and

assigning the unique radio resource as a respective physical path of the plurality of diverse physical paths.

10 . The device of claim 9 , wherein the selecting a unique radio resource comprises:

selecting a unique radio frequency of the radio communication system as the unique radio resource.

11 . A non-transitory machine-readable medium, comprising executable instructions that, when executed by a processing system including a processor, facilitate performance of operations, the operations comprising:

receiving source frames of data at a network device, the network device forming a first network endpoint;

identifying destinations of the source frames of data;

accumulating source frames of data having a common destination at a destination network device, forming common frames of data, the destination network device forming a second network endpoint;

splitting the common frames of data into a plurality of shards based on a key, the key used to specify a number of data bits contained in shards of the plurality of shards;

selecting a plurality of diverse network paths for communication of information between the network device and the destination network device; and

communicating the plurality of shards from the network device over the plurality of diverse network paths for reception of the plurality of shards at the destination network device and for reassembly at the destination network device into received frames of data, wherein the received frames of data match the source frames of data, thus forming a terminated point to point security service between the first network endpoint and the second network endpoint to increase data security during the communicating.

12 . The non-transitory machine-readable medium of claim 11 , wherein the splitting the common frames of data into the plurality of shards comprises:

splitting the common frames of data into the plurality of shards using a key-based splitting algorithm.

13 . The non-transitory machine-readable medium of claim 11 , wherein the communicating the plurality of shards over the plurality of diverse network paths comprises:

applying an error correction coding algorithm to the plurality of shards to facilitate recovery of the plurality of shards at the destination network device.

14 . The non-transitory machine-readable medium of claim 11 , wherein the communicating the plurality of shards over the plurality of diverse network paths comprises:

adding to each shard of the plurality of shards a header, the header including information defining a unique path for the each shard of the plurality of diverse network paths.

15 . The non-transitory machine-readable medium of claim 11 , wherein the communicating the plurality of shards over the plurality of diverse network paths comprises:

selecting a subset of the plurality of diverse network paths for encryption, forming selected paths;

assigning selected shards of the plurality of shards to the selected paths; and

encrypting the selected shards for transmission over the selected paths.

16 . A method, comprising:

receiving, by a processing system including a processor, at a destination network device including the processing system, data shards from a diverse plurality of physical links, the diverse plurality of physical links selected for data security during communication of the data shards, the data shards received over the diverse plurality of physical links from a source network device, the source network device forming a first network endpoint and the destination network device forming a second network endpoint, the first network endpoint and the second network endpoint forming a terminated, point to point security service between network endpoints to increase the data security during the communication of the data shards;

identifying, based on header information of the data shards, a destination of a source frame of data corresponding to the data shards,

accumulating, based on the destination, the data shards corresponding to the destination to form a source block of data, wherein the accumulating is based on the header information of the data shards;

reassembling, by the processing system, the data shards into a block of data, the block of data matching the source block of data at the source network device, wherein the reassembling comprises ordering bits of the data shards using a key, the key matching a data splitting key used to partition the source block of data at the source network device;

determining, based on the key, a number of data bits contained in the data shards used to partition the source block of data at the source network device; and

communicating, by the processing system, the block of data from the destination network device to a data destination, the data destination in data communication with the destination network device.

17 . The method of claim 16 , comprising:

decrypting, by the processing system, at least some data shards prior to the reassembling the data shards into the block of data.

18 . The method of claim 16 , wherein the reassembling the data shards into the block of data comprises:

identifying, by the processing system, a plurality of frames, the plurality of frames corresponding to frames of the source block of data at the source network device; and

organizing, by the processing system, data of the block of data into frames of the plurality of frames.

19 . The method of claim 16 , wherein the receiving the data shards from a diverse plurality of physical links comprises:

demodulating, by the processing system, a plurality of wavelengths of an optical network, wherein the optical network provides data communication between the source network device and the destination network device.

20 . The method of claim 19 , wherein the demodulating the plurality of wavelengths comprises:

receiving, by the processing system, optical signals on a plurality of optical fibers of the optical network, the optical signals conveying the data shards from the source network device; and

demodulating, by the processing system, one or more wavelengths of the plurality of wavelengths on each optical fiber of a plurality of optical fibers of the optical network.