IP Library › Granted Patent US 12,267,421
Granted Patent B2
US 12,267,421 · App. 17/451,312 · Granted Apr 1, 2025

Post quantum secure ingress/egress network communication

Inventors: Nataraj Nagaratnam (Cary, NC); Martin Schmatz (Zurich, CH); Navaneeth Rameshan (Zurich, CH); Vaijayanthimala K. Anand (Austin, TX); Jeffrey J. Feng (Round Rock, TX)
Assignee: International Business Machines Corporation
H04L9/0855H04L9/302H04L9/3066H04L67/133H04L67/563
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,267,421
App. No.
17/451,312
Granted
Apr 1, 2025
Kind
B2
Abstract

Post quantum secure network communication is provided. The process comprises sending, by a client in a first computing cluster, an outbound message to a quantum safe cryptographic (QSC) proxy server in the first computing cluster, wherein the outbound message is addressed to a target server in a second computing cluster. The QSC proxy server initiates a QSC transport layer security (TLS) connection with an ingress controller in the second computing cluster, wherein the ingress controller comprises a QSC algorithm. The QSC proxy server transfers the message to the ingress controller via the QSC TLS connection, and the ingress controller routes the message to the target server in the second computing cluster via a non-QSC connection.

Claims (36)

1. A computer-implemented method for post quantum secure network communication, the method comprising:

using a number of processors to perform the steps of:

sending, by a client in a first computing cluster, an outbound message to a quantum safe cryptographic (QSC) proxy server in the first computing cluster, wherein the outbound message is addressed to a target server in a second computing cluster;

initiating, by the QSC proxy server, a hybrid QSC transport layer security (TLS) connection with an ingress controller in the second computing cluster, wherein the ingress controller uses a QSC key encapsulation mechanism algorithm for session key establishment in hybrid mode;

transferring, by the QSC proxy server, the message to the ingress controller via the QSC TLS connection;

routing, by the ingress controller, the message to the target server in the second computing cluster via a non-QSC connection; and

sending, by the target server, a response to the client via the QSC TLS connection.

2. The method of claim 1 , wherein the QSC proxy server acts as an application load balancer with the first cluster.

3. The method of claim 1 , wherein the QSC server comprises a Nginx or HAProxy server.

4. The method of claim 1 , wherein initiating the QSC TLS connection comprises using the key encapsulation mechanism algorithm in combination with elliptical-curve cryptography or Rivest-Shamir-Adleman cryptography.

5. The method of claim 1 , wherein the ingress controller comprises a Kyber algorithm.

6. The method of claim 1 , wherein communication between microservices within the first and second computing clusters employ remote procedure calls comprising a QSC algorithm.

7. A system for post quantum secure network communication, the system comprising:

a storage device configured to store program instructions; and

one or more processors operably connected to the storage device and configured to execute the program instructions to cause the system to:

send, by a client in a first computing cluster, an outbound message to a quantum safe cryptographic (QSC) proxy server in the first computing cluster, wherein the outbound message is addressed to a target server in a second computing cluster;

initiate, by the QSC proxy server, a hybrid QSC transport layer security (TLS) connection with an ingress controller in the second computing cluster, wherein the ingress controller uses a QSC key encapsulation mechanism algorithm for session key establishment in hybrid mode;

transfer, by the QSC proxy server, the message to the ingress controller via the QSC TLS connection;

route, by the ingress controller, the message to the target server in the second computing cluster via a non-QSC connection; and

send, by the target server, a response to the client via the QSC TLS connection.

8. The system of claim 7 , wherein the QSC proxy server acts as an application load balancer with the first cluster.

9. The system of claim 7 , wherein the QSC server comprises a Nginx or HAProxy server.

10. The system of claim 7 , wherein initiating the QSC TLS connection comprises using the key encapsulation mechanism algorithm in combination with elliptical-curve cryptography or Rivest-Shamir-Adleman cryptography.

11. The system of claim 7 , wherein communication between microservices within the first and second computing clusters employ remote procedure calls comprising a QSC algorithm.

12. A computer program product for post quantum secure network communication, the computer program product comprising:

a computer-readable storage medium having program instructions embodied therewith, the program instructions executable by a computer to cause the computer to perform the steps of:

sending, by a client in a first computing cluster, an outbound message to a quantum safe cryptographic (QSC) proxy server in the first computing cluster, wherein the outbound message is addressed to a target server in a second computing cluster;

initiating, by the QSC proxy server, a hybrid QSC transport layer security (TLS) connection with an ingress controller in the second computing cluster, wherein the ingress controller uses a QSC key encapsulation mechanism algorithm for session key establishment in hybrid mode;

transferring, by the QSC proxy server, the message to the ingress controller via the QSC TLS connection;

routing, by the ingress controller, the message to the target server in the second computing cluster via a non-QSC connection; and

sending, by the target server, a response to the client via the QSC TLS connection.

13. The computer program product of claim 12 , wherein the QSC proxy server acts as an application load balancer with the first cluster.

14. The computer program product of claim 12 , wherein the QSC server comprises a Nginx or HAProxy server.

15. The computer program product of claim 12 , wherein initiating the QSC TLS connection comprises using the key encapsulation mechanism algorithm in combination with elliptical-curve cryptography or Rivest-Shamir-Adleman cryptography.

16. The computer program product of claim 12 , wherein the ingress controller comprises a Kyber algorithm.

17. The computer program product of claim 12 , wherein communication between microservices within the first and second computing clusters employ remote procedure calls comprising a QSC algorithm.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: NAGARATNAM, NATARAJ; SCHMATZ, MARTIN; RAMESHAN, NAVANEETH; ANAND, VAIJAYANTHIMALA K.; FENG, JEFFREY J.
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 057825/0289 →
Continuity (1)
Related Publication 20230119304A1 · Apr 20, 2023
References Cited (41)
US 5764765A · Phoenix · 1998 [cited by examiner]
US 6748083B2 · Hughes · 2004 [cited by examiner]
US 7178277B2 · Takeuchi · 2007 [cited by examiner]
US 7437081B2 · Mitchell · 2008 [cited by examiner]
US 8855316B2 · Wiseman · 2014 [cited by examiner]
US 9960465B2 · Dudley · 2018 [cited by examiner]
US 10057058B2 · Murakami · 2018 [cited by examiner]
US 10581604B2 · Mustafa · 2020 [cited by examiner]
US 11121878B2 · McCarty · 2021 [cited by examiner]
US 11892746B1 · Mazed · 2024 [cited by examiner]
US 20050138352A1 · Gauvreau · 2005 [cited by examiner]
US 20070065154A1 · Luo · 2007 [cited by examiner]
US 20070076884A1 · Wellbrock · 2007 [cited by examiner]
US 20070195774A1 · Sherman · 2007 [cited by examiner]
US 20110206204A1 · Sychev · 2011 [cited by examiner]
US 20110213979A1 · Wiseman · 2011 [cited by examiner]
US 20140010234A1 · Patel · 2014 [cited by examiner]
US 20140068765A1 · Choi · 2014 [cited by examiner]
US 20140133652A1 · Oshida · 2014 [cited by examiner]
US 20160241396A1 · Fu · 2016 [cited by examiner]
US 20160359626A1 · Fu · 2016 [cited by examiner]
US 20160366094A1 · Mason · 2016 [cited by examiner]
US 20170214525A1 · Zhao · 2017 [cited by examiner]
US 20170230173A1 · Choi · 2017 [cited by examiner]
US 20180115523A1 · Subbarayan · 2018 [cited by examiner]
US 20180176091A1 · Yoon · 2018 [cited by examiner]
US 20190036821A1 · Levy · 2019 [cited by examiner]
US 20190319796A1 · Ghosh · 2019 [cited by examiner]
US 20190319804A1 · Mathew · 2019 [cited by examiner]
US 20190349392A1 · Wetterwald · 2019 [cited by examiner]
US 20200084222A1 · William · 2020 [cited by examiner]
US 20210374585A1 · Ramanathan · 2021 [cited by examiner]
US 20210374761A1 · Ramanathan · 2021 [cited by examiner]
US 20210374862A1 · Ramanathan · 2021 [cited by examiner]
US 20230023529A1 · Jenkins · 2023 [cited by examiner]
CN 103338187A · 2013 [cited by applicant]
CN 108111301A · 2018 [cited by applicant]
CN 112039670A · 2020 [cited by applicant]
CN 112118098A · 2020 [cited by applicant]
EP 3562115A1 · 2019 [cited by applicant]
Mell et al., “The NIST Definition of Cloud Computing”, Computer Security Division, National Institute of Standards and Technology, Jan. 2011, 7 pages. [cited by applicant]