IP Library Granted Patent US 12,640,909
Granted Patent B2
US 12,640,909 · App. 18/188,909 · Granted May 26, 2026

Key distribution over IP/UDP

Inventor: Hooman Bidgoli (Ottawa, CA)
Assignee: Nokia Solutions and Networks Oy
H04L9/0822H04L9/0825H04L9/3242
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,640,909
App. No.
18/188,909
Granted
May 26, 2026
Kind
B2
Abstract

Technique for distributing encryption keys for Layer 2.5/3 transport using MKA (MACsec (Media Access Control Security) Key Agreement). A transmitting (TX) node generates an MKA packet having a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing the encryption key for encrypting a packet flow transmitted from the TX node to a receiving (RX) node. The IEEE 802.1x header includes a Security Channel Identification (SCI) that uniquely identifies the packet flow and the encrypting TX node. The TX node transmits the MKA packet to the RX node via a Layer 3 transport. The RX node receives the MKA packet and obtains the encryption key from the MKA packet. The TX node uses the encryption key to encrypt Layer 2.5/3 transport to the RX node, which uses the encryption key to decrypt the encrypted Layer 2.5/3 transport received from the TX node.

Claims (47)

1 . A transmitting (TX) node, comprising:

at least one processor; and

at least one memory including computer program code;

wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the TX node to at least:

generate an MKA (MACsec (Media Access Control Security) Key Agreement) packet comprising a Layer 2 header, an Internet Protocol (IP) header, a User Datagram Protocol (UDP) header, an IEEE 802.1x header, and an MKA payload containing an encryption key for encrypting a packet flow transmitted from the TX node to a receiving (RX) node; and

transmit the MKA packet to the RX node via a Layer 3 transport, wherein:

the IEEE 802.1x header comprises a Security Channel Identification (SCI) that uniquely identifies the packet flow and the encrypting TX node; and

the SCI comprises an encryption segment identifier (SID) to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.

2 . The TX node of claim 1 , wherein the encryption key is a Secure Association Key (SAK).

3 . The TX node of claim 1 , wherein the TX node is configured to receive the SAK from a key server using Advanced Encryption Standard (AES) Key Wrap.

4 . The TX node of claim 1 , wherein the TX node is configured to encrypt the encryption key in the MKA packet using AES Key Wrap.

5 . The TX node of claim 1 , wherein the TX node is configured to:

generate the unique identifier locally; and

transmit the SCI to the RX node using MKA over IP/UDP header.

6 . The TX node of claim 1 , wherein the TX node is configured to:

use the encryption key to encrypt packets of the packet flow; and

transmit the encrypted packets to the RX node via Layer 2.5/3 transport.

7 . The TX node of claim 6 , wherein the Layer 2.5/3 transport is a Layer 2.5 Multiprotocol Label Switching (MPLS) transport.

8 . The TX node of claim 6 , wherein the Layer 2.5/3 transport is a Layer 3 Internet Protocol (IP) transport.

9 . The TX node of claim 1 , wherein the Layer 3 transport is IP transport.

10 . A receiving (RX) node, comprising:

at least one processor; and

at least one memory including computer program code;

wherein the at least one memory and the computer program code are configured to, with the at least one processor, cause the RX node to at least:

receive, from a transmitting (TX) node via a Layer 3 transport, an MKA packet comprising a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing an encryption key for decrypting a packet flow transmitted from the TX node to the RX node; and

process the MKA packet to obtain the encryption key, wherein:

the IEEE 802.1x header comprises an SCI that uniquely identifies the packet flow and the encrypting TX node; and

the SCI comprises an encryption SID to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.

11 . The RX node of claim 10 , wherein the encryption key is a SAK.

12 . The RX node of claim 10 , wherein the encryption key is encrypted in the MKA packet using AES Key wrap.

13 . The RX node of claim 10 , wherein the RX node is configured to receive the SCI from the TX node using MKA over IP/UDP header.

14 . The RX node of claim 10 , wherein the RX node is configured to:

receive encrypted packets of the packet flow from the TX node via the Layer 2.5/3 transport; and

use the encryption key to decrypt the encrypted packets.

15 . The RX node of claim 14 , wherein the Layer 2.5/3 transport is a Layer 2.5 MPLS transport.

16 . The RX node of claim 14 , wherein the Layer 2.5/3 transport is a Layer 3 IP transport.

17 . The RX node of claim 10 , wherein the Layer 3 transport is IP transport.

18 . A method comprising:

a TX node generating an MKA packet comprising a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing an encryption key for encrypting a packet flow transmitted from the TX node to an RX node; and

the TX node transmitting the MKA packet to the RX node via a Layer 3 transport, wherein:

the IEEE 802.1x header comprises an SCI that uniquely identifies the packet flow and the encrypting TX node; and

the SCI comprises an encryption SID to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.

19 . A method comprising:

an RX node receiving, from a TX node via a Layer 3 transport, an MKA packet comprising a Layer 2 header, an IP header, a UDP header, an IEEE 802.1x header, and an MKA payload containing an encryption key for decrypting a packet flow transmitted from the TX node to the RX node; and

the RX node processing the MKA packet to obtain the encryption key, wherein:

the IEEE 802.1x header comprises an SCI that uniquely identifies the packet flow and the encrypting TX node; and

the SCI comprises an encryption SID to identify the encrypting TX node and a unique identifier of a tunnel on the encrypting TX node.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2023
From: BIDGOLI, HOOMAN
To: NOKIA CANADA INC.
Reel/Frame 063722/0270 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 23, 2023
From: NOKIA CANADA INC.
To: NOKIA SOLUTIONS AND NETWORKS OY
Reel/Frame 063722/0273 →
Continuity (1)
Related Publication 20240322999A1 · Sep 26, 2024
References Cited (24)
US 8707020B1 · Lengyel · 2014 [cited by examiner]
US 10212138B1 · Diamant et al. · 2019 [cited by applicant]
US 10491659B1 · Powell, III · 2019 [cited by applicant]
US 10826876B1 · Sinn et al. · 2020 [cited by applicant]
US 20080126559A1 · Elzur et al. · 2008 [cited by applicant]
US 20140330982A1 · Jalan et al. · 2014 [cited by applicant]
US 20170104851A1 · Arangasamy et al. · 2017 [cited by applicant]
US 20180302269A1 · Sankaran · 2018 [cited by examiner]
US 20190173860A1 · Sankaran et al. · 2019 [cited by applicant]
US 20200106702A1 · Acharya et al. · 2020 [cited by applicant]
US 20210075829A1 · Wei · 2021 [cited by applicant]
US 20230133729A1 · Bidgoli et al. · 2023 [cited by applicant]
US 20230370369A1 · Saad · 2023 [cited by examiner]
JP 2013102352A · 2013 [cited by applicant]
Office Action in corresponding Japanese Application No. 2024-042970; dated Apr. 1, 2025 (6 pages) Machine Translation. [cited by applicant]
Extended European Search Report for corresponding European application No. 24156066.3; dated Jul. 2, 2024 (11 pages). [cited by applicant]
IEEE Standards Association, “IEEE Standard 802.1X-2020, Local and Metropolitan Area Networks—Port-Based Network Access Control.” Feb. 28, 2020, 289 pages. [cited by applicant]
IEEE Standards Association, “IEEE Standard 802.1AE-2018, Local and metropolitan area networks—Media Access Control (MAC) Security,” Sep. 27, 2018, 239 pages. [cited by applicant]
IEEE Standards Association, “IEEE Standard 802.1X-2010, Local and metropolitan area networks—Port-Based Network Access Control,” Feb. 2, 2010, 222 pages. [cited by applicant]
Dubroca, Sabrina. “MACsec: a different solution to encrypt traffic”, Red Hat Developer, Oct. 2016 (available at https://developers.redhat.com/blog/2016/10/14/macsec-a-different-solution-to-encrypt-network-traffic#) (Yea… [cited by applicant]
Techopedia, “What Does Layer 3 Mean?”, Apr. 2014 (available at https://www.techopedia.com/definition/14825/layer-3) (Year: 2014). [cited by applicant]
ForcePoint, “What is Multiprotocol Label Switching (MPLS)?”, (available at https://www.forcepoint.com/cyber-edu/mpls-multiprotocol-label-switching#) (Year: 2022). [cited by applicant]
Wikipedia, “IP header”, (available at https://en.wikipedia.org/wiki/IP_header) (Year: 2021). [cited by applicant]
Wikipedia, “List of network protocols (OSI model)”, (available at https://en.wikipedia.org/wiki/List_of_network_protocols_(OSI_model)) (Year: 2022). [cited by applicant]