IP Library Granted Patent US 9,106,618
Granted Patent B2
US 9,106,618 · App. 13/748,244 · Granted Aug 11, 2015

Control plane encryption in IP/MPLS networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,106,618
App. No.
13/748,244
Granted
Aug 11, 2015
Kind
B2
Abstract

A method for providing control plane encryption in layer 3 networks is disclosed. The method for providing control plane encryption in layer 3 networks includes for a network having a subset of network elements forming a secured domain; the steps of at a network element which is in the secured domain, encrypting all unencrypted Layer 3 packets as they egress an encryption enable egress interface; unencrypting all encrypted Layer 3 packets as they egress an egress interface is not enabled for encryption; and leaving encrypted all encrypted Layer 3 packets as they egress an encryption enable egress interface. A system and machine readable storage media are also disclosed.

Claims (17)

1. A method of encrypting data for a network having a plurality of network elements, each of said plurality of network elements having a connection between a respective ingress interface to a respective egress interface of another network element of said plurality of network elements, and a subset of said plurality of network elements comprising a secured domain, the method comprising:

at a first network element, which is a member of said subset of network elements and inside the secured domain, encrypting all unencrypted Layer 3 packets as they egress the respective egress interface, wherein said egress interface is enabled for encryption;

at said first network element, unencrypting all encrypted Layer 3 packets as they egress the respective egress interface, wherein said egress interface is not enabled for encryption and is outside the secured domain; and

at said first network element, leaving encrypted all encrypted Layer 3 packets as they egress the respective egress interface, wherein said egress interface is enabled for encryption.

2. The method as claimed in claim 1 , wherein said encrypting is associated with an encryption protocol that is one of a group of DES, 3DES, Blowfish, Twofish, Serpent, SNOW 3G, Kasumi-F8, AES-128, AES-192, and AES-256.

3. A system for providing a secured domain, comprising:

a plurality of network elements, each of said plurality of network elements having a connection between a respective ingress interface to a respective egress interface of another network element of said plurality of network elements;

a subset of said plurality of network elements comprising said secured domain;

a first network element which is a member of said subset of network elements and inside the secured domain, which encrypts all unencrypted Layer 3 packets as they egress the respective egress interface, wherein said egress interface is enabled for encryption;

said first network element further unencrypting all encrypted Layer 3 packets as they egress the respective egress interface, wherein said egress interface is not enabled for encryption and is outside the secured domain; and

said first network element leaving encrypted all encrypted Layer 3 packets as they egress the respective egress interface, wherein said egress interface is enabled for encryption.

4. The system as claimed in claim 3 , wherein said encrypting is associated with an encryption protocol that is one of a group of DES, 3DES, Blowfish, Twofish, Serpent, SNOW 3G, Kasumi-F8, AES-128, AES-192, and AES-256.

5. A non-transitory machine readable storage medium encoded with instructions for execution by a processor at a first network element for a network having a plurality of network elements, each of said plurality of network elements having a connection between a respective ingress interface to a respective egress interface of another network element of said plurality of network elements, and a subset of said plurality of network elements comprising a secured domain, and said first network element a member of said subset and inside the secured domain, the medium comprising:

instructions for encrypting all unencrypted Layer 3 packets as they egress the respective egress interface of said first network element when said egress interface is enabled for encryption;

instructions for unencrypting all encrypted Layer 3 packets as they egress the respective egress interface of said first network element when said egress interface is not enabled for encryption and is outside the secured domain; and

instructions for leaving encrypted all encrypted Layer 3 packets as they egress the respective egress interface of said first network element when said egress interface is enabled for encryption.

6. The non-transitory machine readable storage medium as claimed in claim 3 , wherein said encrypting is associated with an encryption protocol that is one of a group of DES, 3DES, Blowfish, Twofish, Serpent, SNOW 3G, Kasumi-F8, AES-128, AES-192, and AES-256.

Assignments (13)
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
TERMINATION AND RELEASE OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Apr 2, 2020
From: DEUTSCHE BANK TRUST COMPANY AMERICAS
To: SPRINT COMMUNICATIONS COMPANY L.P.
Reel/Frame 052969/0475 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
GRANT OF FIRST PRIORITY AND JUNIOR PRIORITY SECURITY INTEREST IN PATENT RIGHTS Recorded Mar 6, 2017
From: SPRINT COMMUNICATIONS COMPANY L.P.
To: DEUTSCHE BANK TRUST COMPANY AMERICAS
Reel/Frame 041895/0210 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2014
From: ALCATEL-LUCENT CANADA INC.
To: ALCATEL LUCENT
Reel/Frame 032351/0949 →
CORRECTIVE ASSIGNMENT TO CORRECT THE TO CORRECT ASSIGNEE ADDRESS PREVIOUSLY RECORDED ON REEL 029680 FRAME 0774. ASSIGNOR(S) HEREBY CONFIRMS THE CORRECTED ASSIGNMENT DOCUMENT. Recorded Feb 6, 2013
From: RAJSIC, CARL; CHAN, HANSEN
To: ALCATEL-LUCENT CANADA INC.
Reel/Frame 029762/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2013
From: RAJSIC, CARL; CHAN, HANSEN
To: ALCATEL-LUCENT CANADA INC.
Reel/Frame 029680/0774 →