IP Library › Patent Application 16983176
Patent Application
App. No. 16/983,176

METHODS AND SYSTEMS OF A PACKET ORCHESTRATION TO PROVIDE DATA ENCRYPTION AT THE IP LAYER, UTILIZING A DATA LINK LAYER ENCRYPTION SCHEME

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/983,176
Abstract

In one aspect, A method for packet orchestration to provide data encryption at the Internet protocol (IP) layer, includes the step of providing a quantum secure pre-shared key derivation scheme for a data link layer bulk encryption algorithm, meaning the ability to setup a separate communication channel, via the SSH protocol, and leverage ECDH over said channel to share pre-shared keys. The method includes the step of providing a set of software-based network bridges. The method includes the step of assigning a set of network ports to specific bridges, wherein the set of network ports implement segmentation and isolation based on an organizational policy.

Claims (16)

1 . A method for packet orchestration to provide data encryption at the internet protocol (IP) layer, comprising the steps of:

providing a quantum secure pre-shared key derivation scheme for a data link layer bulk encryption algorithm, wherein the ability to setup a separate communication channel, via the SSH protocol, and leverage ECDH over said channel to share pre-shared keys;

providing a set of software-based network bridges;

assigning a set of network ports to specific bridges, wherein the set of network ports implement segmentation and isolation based on an organizational policy;

provisioning and configuring of a set of CPU cores to handle wire-speed data encryption and decryption on a per bridge segmentation standpoint, wherein each network bridge segment, has it own CPU core affinity, and recommended buffer allocation.

provisioning per bridge, an IP overlay encapsulation of a set of encrypted packets; and

provisioning a Network interface card (NIC) offloading and packet steering functionality, wherein the NIC offloading and packet steering functionality provides network packet handling for network communications.

2 . The method of claim 1 , wherein the set of network ports are assigned to set of software-based network bridges based on a set of communication and isolation requirements.

3 . The method of claim 1 , wherein the mechanism for provisioning per bridge is provided using segment isolation.

4 . The method of claim 1 , wherein the provisioning per bridge of the IP overlay encapsulation of the set of encrypted packets is implemented with a specified encapsulation/decapsulation functionality of an operating-system software and a network vendors ethernet controller.

5 . The method of claim 1 , wherein the IP overlay encapsulation is implemented with a tunneling protocol.

6 . The method of claim 1 , wherein the network packet handling of the NIC offloading and packet steering functionality comprises an encapsulation operation.

7 . The method of claim 1 , wherein the network packet handling of the NIC offloading and packet steering functionality comprises a checksum operation.

8 . The method of claim 1 , wherein the network packet handling of the NIC offloading and packet steering functionality comprises a buffer allocation operation.

9 . The method of claim 1 , wherein the provisioning per bridge and the IP overlay encapsulation of encrypted packets with post quantum encryption is implemented per the specifications of a specified Ethernet Controller manufacturer.

10 . The method of claim 9 , wherein an Ethernet Controller enables and configures the encapsulation/decapsulation offloading functionality.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2021
From: FRANKLIN, KELVIN R; FLACK, JONATHAN
To: BROADBRIDGE NETWORKS, INC.
Reel/Frame 054832/0483 →