IP Library Granted Patent US 11,012,427
Granted Patent B2
US 11,012,427 · App. 16/014,984 · Granted May 18, 2021

RSA trusted networks: RSA packet frames for advanced networking switches

Inventor: Livingston Paul Delightson (Tirunelveli, IN)
Assignee: EMC IP HOLDING COMPANY LLC
H04L63/0464H04L9/0869H04L63/0442H04L63/12H04L63/162
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,012,427
App. No.
16/014,984
Granted
May 18, 2021
Kind
B2
Abstract

Embodiments are described for enhanced security in a switched network using RSA security between hops of a transmission path of a data frame from an origination node to a destination node, via one or more intervening switches. Each switch and node in a switched network can be configured for “RSA security enabled” or “RSA security disabled.” RSA security can be enabled, or disabled, for the whole network. RSA security can be enabled for all switches (but not nodes) or selectively enabled for switches. If two adjacent devices (nodes or switches) have RSA security enabled, then an RSA secure frame is generated to transmit data on that hop of a transmission path between an originating node and destination node. RSA encryption keys can be different for each hop on the transmission path. RSA token seeds can be regenerated periodically to increase the difficulty of learning an encryption key for any hop.

Claims (44)

1. A computer-implemented method of transmitting a message over a switched network comprising a plurality of devices, the method, comprising:

for each of a plurality of hops in transmitting the message over the switched network, determining, by a sending first device, whether a receiving second device for the hop is configured for secure transmission;

in response to determining that the receiving second device is configured for secure transmission:

encrypting, by the sending first device, an unencrypted data frame using an encryption key of the receiving second device; and

transmitting the encrypted data frame to the receiving second device;

otherwise transmitting, by the sending first device, the unencrypted data frame to the receiving second device without encryption;

wherein the unencrypted data frame is encrypted for at least one hop of the plurality of hops, and the unencrypted data frame is not encrypted for at least one hop of the plurality of hops.

2. The method of claim 1 , wherein the encryption key of the receiving second device comprises a public key of the receiving second device.

3. The method of claim 1 , wherein the encryption key of the receiving second device is based at least in part on a token seed of the receiving second device, stored on the sending first device.

4. The method of claim 3 , wherein the token seed of the receiving second device is regenerated at a periodic interval.

5. The method of claim 1 , further comprising, before the encrypting:

decrypting, by the sending first device, the data frame using a decryption key of the sending first device.

6. The method of claim 5 , wherein the decryption key of the sending first device comprises a private key of the sending first device, based at least in part on a token seed of the sending first device.

7. The method of claim 1 , wherein the sending first device and the receiving second device are both network switches, and all hops in the plurality of hops that are used to transmit the message that are between network switches encrypt the data frame before transmission, and at least one hop between a node and a network switch does not encrypt the data frame before transmission.

8. A non-transitory computer-readable medium programmed with executable instructions that, when executed by a processing system having at least one hardware processor, perform operations for transmitting a message over a switched network comprising a plurality of devices, the operations comprising:

for each of a plurality of hops in transmitting the message over the switched network, determining, by a sending first device, whether a receiving second device for the hop is configured for secure transmission;

in response to determining that the receiving second device is configured for secure transmission:

encrypting, by the sending first device, an unencrypted data frame using an encryption key of the receiving second device; and

transmitting the encrypted data frame to the receiving second device;

otherwise transmitting, by the sending first device, the unencrypted data frame to the receiving second device without encryption;

wherein the unencrypted data frame is encrypted for at least one hop of the plurality of hops, and the unencrypted data frame is not encrypted for at least one hop of the plurality of hops.

9. The medium of claim 8 , wherein the encryption key of the receiving second device comprises a public key of the receiving second device.

10. The medium of claim 8 , wherein the encryption key of the receiving second device is based at least in part on a token seed of the receiving second device, stored on the sending first device.

11. The medium of claim 10 , wherein the token seed of the receiving second device is regenerated at a periodic interval.

12. The medium of claim 8 , further comprising, before the encrypting:

decrypting, by the sending first device, the data frame using a decryption key of the sending first device.

13. The medium of claim 12 , wherein the decryption key of the sending first device comprises a private key of the sending first device, based at least in part on a token seed of the sending first device.

14. The medium of claim 13 , wherein the sending first device and receiving second device are both network switches, and all hops in the plurality of hops that are between network switches encrypt the data frame before transmission, and at least one hop between a node and a network switch does not encrypt the data frame before transmission.

15. A system comprising:

a processing system having at least one hardware processor, the processing system coupled to a memory programmed with executable instructions that, when executed by the processing system, perform operations for transmitting a message over a switched network comprising a plurality devices, the operations comprising:

for each of a plurality of hops in transmitting the message over the switched network,

determining, by a sending first device, whether a receiving second device is configured for secure transmission;

in response to determining that the receiving second device is configured for secure transmission:

encrypting, by the sending first device, an unencrypted data frame using an encryption key of the receiving second device; and

transmitting the encrypted data frame to the receiving second device;

otherwise transmitting, by the sending first device, the unencrypted data frame to the receiving second device without encryption;

wherein at least one hop of the plurality of hops encrypts the unencrypted data frame and at least one hop of the plurality of hops does not encrypt the unencrypted data frame, before transmitting the data frame.

16. The system of claim 15 , wherein the encryption key of the receiving second device comprises a public key of the receiving second device.

17. The system of claim 15 , wherein the encryption key of the receiving second device is based at least in part on a token seed of the receiving second device, stored on the sending first device.

18. The system of claim 17 , wherein the token seed of the receiving second device is regenerated at a periodic interval.

19. The system of claim 15 , further comprising, before the encrypting:

decrypting, by the sending first device, the data frame using a decryption key of the sending first device.

20. The system of claim 19 , wherein the decryption key of the sending first device comprises a private key of the sending first device, based at least in part on a token seed of the sending first device.

21. The system of claim 20 , wherein the sending first device and the receiving second device are both network switches, and all hops in the plurality of hops that are between network switches encrypt the data frame and at least one hop between a node and a network switch does not encrypted the data frame.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 21, 2018
From: DELIGHTSON, LIVINGSTON PAUL
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046170/0557 →
Continuity (1)
Related Publication 20190394177A1 · Dec 26, 2019