IP Library › Granted Patent US 12,621,174
Granted Patent B2
US 12,621,174 · App. 18/454,416 · Granted May 5, 2026

Data security for networks combining encryption with error correction

Inventors: Scott Roy Fluhrer (North Attleboro, MA); Gilberto Loprieno (Milan, IT)
Assignee: CISCO TECHNOLOGY, INC.
H04L9/40G06F21/80H03M13/1515H04J3/1611H04L1/22H04L9/007
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,174
App. No.
18/454,416
Granted
May 5, 2026
Kind
B2
Abstract

In one example embodiment, data is received at a node of a network. The data includes encrypted data segments containing data portions and error correction information. The encrypted data segments are decrypted to produce the data portions and the error correction information. Error correction is performed on the data portions using the error correction information. Corrupt data is determined based on the error correction indicating uncorrectable data.

Claims (42)

1 . A method comprising:

receiving data of a frame at a node of a network, wherein the data includes encrypted codewords generated by encrypting codewords including encoded data segments, wherein the encoded data segments include plaintext symbols representing data portions and error correction information, wherein each plaintext symbol of the encoded data segments is associated with a different portion of unpredictable sequences of values and independently encrypted within the encrypted codewords by corresponding values from the different portion to map each plaintext symbol to a corresponding unpredictable ciphertext symbol, and wherein the unpredictable sequences of values are produced from different portions of an encrypted value;

generating the unpredictable sequences of values used to encrypt the codewords;

decrypting the encrypted codewords of the frame using the unpredictable sequences of values to produce the encoded data segments containing the data portions and the error correction information;

performing authentication and error correction simultaneously on the data portions using the error correction information; and

determining corrupt data based on the error correction indicating uncorrectable data.

2 . The method of claim 1 , wherein the network includes an optical transport network (OTN) and the frame includes an OTN frame.

3 . The method of claim 1 , wherein the data includes Ethernet traffic.

4 . The method of claim 1 , wherein the encrypted codewords include Reed-Solomon codes.

5 . The method of claim 1 , wherein the encrypted value is produced based on an advanced encryption standard (AES).

6 . The method of claim 1 , further comprising:

synchronizing the unpredictable sequences of values with a transmitting node of the network.

7 . The method of claim 6 , wherein decrypting the encrypted codewords comprises:

decrypting the encrypted codewords based on the unpredictable sequences of values synchronized with the transmitting node.

8 . An apparatus comprising:

a network computing device of a network comprising a memory for storing program instructions and one or more processors configured to execute the program instructions and perform operations including:

receiving data of a frame including encrypted codewords generated by encrypting codewords including encoded data segments, wherein the encoded data segments include plaintext symbols representing data portions and error correction information, wherein each plaintext symbol of the encoded data segments is associated with a different portion of unpredictable sequences of values and independently individually encrypted within the encrypted codewords by corresponding values from the different portion to map each plaintext symbol to a corresponding unpredictable ciphertext symbol, and wherein the unpredictable sequences of values are produced from different portions of an encrypted value;

generating the unpredictable sequences of values used to encrypt the codewords;

decrypting the encrypted codewords of the frame using the unpredictable sequences of values to produce the encoded data segments containing the data portions and the error correction information;

performing authentication and error correction simultaneously on the data portions using the error correction information; and

determining corrupt data based on the error correction indicating uncorrectable data.

9 . The apparatus of claim 8 , wherein the network includes an optical transport network (OTN) and the frame includes an OTN frame.

10 . The apparatus of claim 8 , wherein the data includes Ethernet traffic.

11 . The apparatus of claim 8 , wherein the encrypted codewords include Reed-Solomon codes.

12 . The apparatus of claim 8 , wherein the encrypted value is produced based on an advanced encryption standard (AES).

13 . The apparatus of claim 8 , wherein the one or more processors are configured to perform further operations including:

synchronizing the unpredictable sequences of values with a transmitting node of the network, and

wherein decrypting the encrypted codewords comprises decrypting the encrypted codewords based on the unpredictable sequences of values synchronized with the transmitting node.

14 . One or more non-transitory computer readable storage media encoded with processing instructions that, when executed by one or more processors, cause the one or more processors to perform operations including:

receiving data of a frame at a node of a network, wherein the data includes encrypted codewords generated by encrypting codewords including encoded data segments, wherein the encoded data segments include plaintext symbols representing data portions and error correction information, wherein each plaintext symbol of the encoded data segments is associated with a different portion of unpredictable sequences of values and independently encrypted within the encrypted codewords by corresponding values from the different portion to map each plaintext symbol to a corresponding unpredictable ciphertext symbol, and wherein the unpredictable sequences of values are produced from different portions of an encrypted value;

generating the unpredictable sequences of values used to encrypt the codewords;

decrypting the encrypted codewords of the frame using the unpredictable sequences of values to produce the encoded data segments containing the data portions and the error correction information;

performing authentication and error correction simultaneously on the data portions using the error correction information; and

determining corrupt data based on the error correction indicating uncorrectable data.

15 . The one or more non-transitory computer readable storage media of claim 14 , wherein the network includes an optical transport network (OTN) and the frame includes an OTN frame.

16 . The one or more non-transitory computer readable storage media of claim 14 , wherein the data includes Ethernet traffic.

17 . The one or more non-transitory computer readable storage media of claim 14 , wherein the encrypted codewords include Reed-Solomon codes.

18 . The one or more non-transitory computer readable storage media of claim 14 , wherein the encrypted value is produced based on an advanced encryption standard (AES).

19 . The one or more non-transitory computer readable storage media of claim 14 , wherein the processing instructions cause the one or more processors to perform further operations including:

synchronizing the unpredictable sequences of values with a transmitting node of the network.

20 . The one or more non-transitory computer readable storage media of claim 19 , wherein decrypting the encrypted codewords comprises:

decrypting the encrypted codewords based on the unpredictable sequences of values synchronized with the transmitting node.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 23, 2023
From: FLUHRER, SCOTT ROY; LOPRIENO, GILBERTO
To: CISCO TECHNOLOGY, INC.
Reel/Frame 064683/0103 →
Continuity (1)
Related Publication 20250070989A1 · Feb 27, 2025
References Cited (12)
US 7099584B1 · Narvaez · 2006 [cited by examiner]
US 20050068995A1 · Lahav et al. · 2005 [cited by applicant]
US 20080065906A1 · Itagaki · 2008 [cited by examiner]
US 20080211624A1 · Micali · 2008 [cited by examiner]
US 20120137196A1 · Linkewitsch · 2012 [cited by applicant]
US 20140133653A1 · Loprieno et al. · 2014 [cited by applicant]
US 20160301669A1 · Muma et al. · 2016 [cited by applicant]
US 20200067887A1 · Sarwar · 2020 [cited by applicant]
WO WO0161909A1 · 2001 [cited by examiner]
International Telecommunication Union: “Flexible OTN short-reach interfaces Amendment 3,” ITU Publications, Recommendation ITU-T G.709.1/Y.1331.1 (2018) Amd. Nov. 3, 2022, Published in Switzerland, Geneva, 2023, 66 Page… [cited by applicant]
Reed-Solomon Codes, “An Introduction to Reed-Solomon Codes: Principles, Architecture and Implementation,” retrieved from https://www.cs.cmu.edu/˜guyb/realworld/reedsolomon/reed_solomon_codes.html, on Aug. 9, 2023, 6 pag… [cited by applicant]
Yu, C., et al., “Two-Mode Reed-Solomon Decoder using Simplified Step-by-Step Algorithm,” IEEE Transactions on Circuits and System-II: Express Briefs, vol. 62, No. 11, Jul. 14, 2015, 5 pages. [cited by applicant]