IP Library Granted Patent US 12,401,501
Granted Patent B2
US 12,401,501 · App. 18/195,699 · Granted Aug 26, 2025

Methods and apparatus for quantum-resistant network communication

Inventors: Thomas A. Gilbert (Fairfax, VA); Kenneth A. Hardwick (Newburg, OR); Srinivas R. Mirmira (Bethesda, MD)
Assignee: Blue Ridge Networks, Inc.
H04L9/0844H04L9/0827H04L9/14H04L9/302H04L9/3215H04L63/045
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,501
App. No.
18/195,699
Granted
Aug 26, 2025
Kind
B2
Abstract

A method includes sending, to a compute device and via a private channel, a public key for asymmetric encryption. The method also includes concurrently authenticating the compute device and generating a traffic key for symmetric encryption, based at least in part on the public key. The method further includes sending a message to the compute device, the message being encrypted using the traffic key via the symmetric encryption.

Claims (48)

1. A method, comprising:

sending a request to a compute device, the request being encrypted at least by a private key of an asymmetric key pair that includes a public key, the request including a first set of Diffie-Hellman key exchange parameters and a nonce, the first set of Diffie-Hellman key exchange parameters further encrypted by a temporary key;

receiving a reply from the compute device, the reply being encrypted at least by the public key and including a second set of Diffie-Hellman key exchange parameters so as to generate a traffic key, the reply further including the nonce;

encrypting a message using the traffic key; and

sending the message to the compute device after the temporary key has been discarded.

2. The method of claim 1 , further comprising:

sending, to the compute device and via a private channel, the public key for asymmetric encryption.

3. The method of claim 1 , further comprising:

sending, to the compute device, via a private channel, and via a management system, the public key for asymmetric encryption, the sending the request and the receiving the reply done without using the management system.

4. The method of claim 1 , further comprising:

sending the public key to a management system; and

sending the public key to the compute device via a local cable between the management system and the compute device.

5. The method of claim 1 , wherein the message is sent to the compute device after the encrypting the message using the traffic key.

6. An apparatus, comprising:

a memory; and

a processor operatively coupled to the memory and configured to:

generate a request including a first set of Diffie-Hellman key exchange parameters and a nonce;

encrypt the first set of Diffie-Hellman key exchange parameters using a temporary key via a random symmetric encryption;

encrypt the request using at least a private key of an asymmetric key pair that includes a public key to generate an encrypted request;

send the encrypted request to a compute device;

receive a reply from the compute device, the reply being encrypted by the public key and including a second set of Diffie-Hellman key exchange parameters and the nonce;

generate a traffic key using the first set and the second set of Diffie-Hellman key exchange parameters;

authenticate the compute device based on the nonce; and

discard the temporary key after authenticating the compute device.

7. The apparatus of claim 6 , wherein the processor is further configured to:

send a message to the compute device, the message being encrypted using the traffic key via symmetric encryption.

8. The apparatus of claim 6 , wherein the processor is further configured to:

send the public key via a management system,

the processor configured to generate the request, encrypt the request, send the encrypted request, receive the reply, and generate the traffic key without using the management system.

9. The apparatus of claim 6 , wherein the processor is further configured to:

send the public key for asymmetric encryption via a private channel.

10. The apparatus of claim 6 , wherein the processor is further configured to:

send the public key for asymmetric encryption to a management system via a private channel and via a local cable between the apparatus and the management system.

11. The apparatus of claim 6 , wherein the processor is further configured to:

send the public key via a private channel for asymmetric RSA encryption.

12. The apparatus of claim 6 , wherein the processor is configured to perform the generating the request, the encrypting the request, the sending the encrypted request, the receiving the reply, and the generating the traffic key via a public channel.

13. An apparatus, comprising:

a memory; and

a processor operatively coupled to the memory and configured to:

decrypt a request using a first public key, the request including a first set of Diffie-Hellman key exchange parameters and a first nonce, the request being encrypted using a first private key of a first asymmetric key pair that includes the first public key, the first set of Diffie-Hellman key exchange parameters encrypted by a temporary key;

generate a reply including the first nonce, a second set of Diffie-Hellman key exchange parameters, and a second nonce;

encrypt the reply using a second private key in a second asymmetric key pair that further includes a second public key and

receive a message from a compute device after the temporary key has been discarded.

14. The apparatus of claim 13 , wherein the request is further encrypted using the second public key and the processor is further configured to:

encrypt the reply using the first public key.

15. The apparatus of claim 13 , wherein the processor is further configured to:

receive the first public key from the compute device and via a private channel; and

send the reply to the compute device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 5, 2023
From: GILBERT, THOMAS A.; HARDWICK, KENNETH A.; MIRMIRA, SRINIVAS R.
To: BLUE RIDGE NETWORKS, INC.
Reel/Frame 065768/0979 →
Continuity (3)
Continuation 16852935 · Apr 20, 2020
Continuation 16240445 · Jan 4, 2019
Related Publication 20230283457A1 · Sep 7, 2023
References Cited (48)
US 5241599A · Bellovin · 1993 [cited by examiner]
US 6922774B2 · Meushaw et al. · 2005 [cited by applicant]
US 7421578B1 · Huang et al. · 2008 [cited by applicant]
US 7712143B2 · Comlekoglu · 2010 [cited by applicant]
US 7809955B2 · Comlekoglu · 2010 [cited by applicant]
US 8549300B1 · Kumar et al. · 2013 [cited by applicant]
US 10630467B1 · Gilbert et al. · 2020 [cited by applicant]
US 11689359B2 · Gilbert et al. · 2023 [cited by applicant]
US 20030072059A1 · Thomas et al. · 2003 [cited by applicant]
US 20040090943A1 · Da Costa et al. · 2004 [cited by applicant]
US 20040167465A1 · Mihai et al. · 2004 [cited by applicant]
US 20040228492A1 · Park · 2004 [cited by applicant]
US 20090217043A1 · Metke et al. · 2009 [cited by applicant]
US 20090323954A1 · Sprunk et al. · 2009 [cited by applicant]
US 20120042170A1 · Curtin et al. · 2012 [cited by applicant]
US 20120288092A1 · Cakulev et al. · 2012 [cited by applicant]
US 20130083926A1 · Hughes et al. · 2013 [cited by applicant]
US 20130173913A1 · Kocsis et al. · 2013 [cited by applicant]
US 20150039890A1 · Khosravi et al. · 2015 [cited by applicant]
US 20150067338A1 · Gero et al. · 2015 [cited by applicant]
US 20150120569A1 · Belshe et al. · 2015 [cited by applicant]
US 20150222619A1 · Hughes et al. · 2015 [cited by applicant]
US 20150244525A1 · McCusker et al. · 2015 [cited by applicant]
US 20150288514A1 · Pahl et al. · 2015 [cited by applicant]
US 20160055485A1 · Benoit et al. · 2016 [cited by applicant]
US 20160057118A1 · Lee et al. · 2016 [cited by applicant]
US 20160373418A1 · Stahl · 2016 [cited by applicant]
US 20170006004A1 · Li et al. · 2017 [cited by applicant]
US 20170323116A1 · Mumford et al. · 2017 [cited by applicant]
US 20180041507A1 · Sivarajan et al. · 2018 [cited by applicant]
US 20180131551A1 · Murakami et al. · 2018 [cited by applicant]
US 20200382292A1 · Gilbert et al. · 2020 [cited by applicant]
EP 2173055A1 · 2010 [cited by applicant]
WO WO2017091267A1 · 2017 [cited by applicant]
Bellovin, Steven Michael, and Michael Merritt. “Encrypted key exchange: Password-based protocols secure against dictionary attacks.” (1992): 72-84. (Year: 1992). [cited by examiner]
Blue Ridge Session Authentication, 5 pages, Published before Jan. 4, 2018. (Year: 2018). [cited by examiner]
Mandal, Sayonnha et al. “Implementing Diffie-Hellman key exchange using quantum EPR pairs”, 2015. (Year: 2015). [cited by examiner]
Blake-Wilson, Simon, and Menezes, Alfred, “Authenticated Diffie-Hellman Key Agreement Protocols.” International Workshop on Selected Areas in Cryptography. Springer, Berlin, Heidelberg, 1998, 339-361. [cited by applicant]
Blue Ridge Session Authentication, 5 pages, Published before Jan. 4, 2018. [cited by applicant]
BorderGuard 5000, 2008 Blue Ridge Networks, Inc., 2 pages. [cited by applicant]
Cremers, Cas, and Horvat, Marko, “Improving the ISO/IEC 11770 standard for key management techniques.” International Journal of Information Security, 2016, 15(6):659-673. [cited by applicant]
Extended European Search Report mailed on Feb. 21, 2020, for European Application No. 20150277.0, 7 pages. [cited by applicant]
Hardwick, “Blue Ridge Networks BorderGuard 5000 Vendor information for FIPS 140-2 Derived Test Requirements,” Blue Ridge Proprietary Material, Mar. 13, 2006, 46 pages. [cited by applicant]
Hugo, K., “SIGMA: The ‘SIGn-and-MAc’ Approach to Authenticated Diffie-Hellman and its use in the IKE Protocols.” Annual International Cryptology Conference. Springer, Berlin, Heidelberg, 2003, 32 pages. [cited by applicant]
Orman, “The Oakley Key Determination Protocol,” Department of Computer Science University of Arizona, Nov. 1998, 56 pages. [cited by applicant]
Sehgal, Parth, et al. “Modification of Diffie-Hellman Algorithm to Provide More Secure Key Exchange.” International Journal of Engineering & Technology, 2013, 2498-2501. [cited by applicant]
VPN Manager Quick Start Guide, Copyright Blue Ridge Networks 2005, 12 pages. [cited by applicant]
Yang et al., “On the post-quantum security of encrypted key exchange protocols,” May 24, 2013, Retrieved from the Internet: https://arxiv.org/pdf/1305.5640.pdf, 14 pages. [cited by applicant]