IP Library › Granted Patent US 12,567,953
Granted Patent B2
US 12,567,953 · App. 18/745,443 · Granted Mar 3, 2026

Inline security key exchange

Inventors: Abilash Menon (Boxborough, MA); Avinash Prakash Bhat (Bedford, MA); Anna Yungelson (Lexington, MA)
Assignee: Juniper Networks, Inc.
H04L9/0825H04L9/0827H04L9/0891H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,567,953
App. No.
18/745,443
Granted
Mar 3, 2026
Kind
B2
Abstract

Techniques are disclosed for inline security key exchanges between network devices. An example network device includes one or more processors and memory coupled to the one or more processors. The memory stores instructions that, upon execution, cause one or more processors to obtain a first payload key and obtain a path key. The instructions cause the one or more processors to encrypt a first payload of a first packet using the first payload key and insert the first payload key into first metadata of the first packet. The instructions cause the one or more processors to encrypt the first metadata using the path key and send the first packet to another network device.

Claims (84)

1 . Non-transitory computer readable storage media storing instructions, which, when executed cause one or more processors of a network device to:

obtain a first payload key, the first payload key being associated with a first session;

obtain a path key, wherein the path key is associated with a path between the network device and a neighboring network device;

encrypt a first packet payload of a first packet using the first payload key;

insert the first payload key into first metadata for the first packet;

encrypt the first metadata using the path key, the first metadata including the first payload key, to generate encrypted first metadata;

send the first packet including the encrypted first metadata and the first packet payload to the neighboring network device;

determine that a second packet payload of a second packet is associated with the first session;

based on the second packet payload being associated with the first session, encrypt the second packet payload using the first payload key; and

send the second packet including second metadata to the neighboring network device, the second metadata not including the first payload key.

2 . The non-transitory computer readable storage media of claim 1 , wherein the instructions cause the one or more processors to obtain the first payload key by generating the first payload key or by receiving the first payload key.

3 . The non-transitory computer readable storage media of claim 1 , wherein the instructions further cause the one or more processors to:

determine to update the first payload key;

obtain a second payload key;

encrypt a third packet payload of a third packet using the second payload key;

insert the second payload key into third metadata of the third packet;

encrypt the third metadata using the path key; and

send the third packet to the neighboring network device.

4 . The non-transitory computer readable storage media of claim 1 , wherein the instructions further cause the one or more processors to:

obtain a second payload key associated with a second session;

encrypt a third packet payload of a third packet associated with the second session using the second payload key;

insert the second payload key into third metadata of the third packet;

encrypt the third metadata using the path key; and

send the third packet to the neighboring network device.

5 . The non-transitory computer readable storage media of claim 1 , wherein the first payload key is further associated with a first type of service and wherein the instructions further cause the one or more processors to:

obtain a second payload key associated with a second type of service;

encrypt a third packet payload of a third packet associated with the second type of service using the second payload key;

insert the second payload key into third metadata of the third packet;

encrypt the third metadata using the path key; and

send the third packet to the neighboring network device.

6 . The non-transitory computer readable storage media of claim 1 , wherein the network device comprises a session-based router.

7 . The non-transitory computer readable storage media of claim 1 , wherein the neighboring network device comprises a session-based router.

8 . Non-transitory computer readable storage media storing instructions, which, when executed cause one or more processors of a network device to:

obtain a path key;

receive a first packet from a neighboring network device;

decrypt first metadata of the first packet using the path key;

obtain a first payload key from the first metadata of the first packet, the first payload key being associated with a first session;

decrypt a first packet payload of the first packet using the first payload key;

receive a second packet including a second packet payload and second metadata from the neighboring network device, the second metadata not including the first payload key;

determine that the second packet payload is associated with the first session based on the second metadata; and

decrypt the second packet payload of the second packet using the first payload key.

9 . The non-transitory computer readable storage media of claim 8 , wherein the instructions further cause the one or more processors to:

receive a third packet from the neighboring network device;

decrypt third metadata of the third packet using the path key;

obtain a second payload key from the third metadata of the third packet; and

decrypt a third packet payload of the third packet using the second payload key.

10 . The non-transitory computer readable storage media of claim 8 , wherein the instructions further cause the one or more processors to:

receive a third packet from the neighboring network device, the third packet being associated with a second session;

decrypt third metadata of the third packet using the path key;

obtain a second payload key from the third metadata of the third packet, the second payload key being associated with the second session; and

decrypt a third packet payload of the third packet using the second payload key.

11 . The non-transitory computer readable storage media of claim 8 , wherein the first payload key is further associated with a first type of service and wherein the instructions further cause the one or more processors to:

receive a third packet from the neighboring network device, the third packet being associated with a second type of service;

decrypt third metadata of the third packet using the path key;

obtain a second payload key from the third metadata of the third packet, the second payload key being associated with the second type of service; and

decrypt a third packet payload of the third packet using the second payload key.

12 . The non-transitory computer readable storage media of claim 8 , wherein the network device comprises a session-based router.

13 . The non-transitory computer readable storage media of claim 8 , wherein the neighboring network device comprises a session-based router.

14 . A method comprising:

obtaining, by one or more processors of an egress network device, a path key;

receiving, by the one or more processors of the egress network device, a first packet from a neighboring network device;

decrypting, by the one or more processors of the egress network device, first metadata of the first packet using the path key;

obtaining, by the one or more processors of the egress network device, a first payload key from the first metadata of the first packet, the first payload key being associated with a first session;

decrypting, by the one or more processors of the egress network device, a first packet payload of the first packet using the first payload key;

receiving, by the one or more processors of the egress network device, a second packet including a second packet payload and second metadata from the neighboring network device, the second metadata not including the first payload key;

determining, by the one or more processors of the egress network device, that the second packet payload is associated with the first session based on the second metadata; and

decrypting, by the one or more processors of the egress network device, the second packet payload of the second packet using the first payload key.

15 . The method of claim 14 , further comprising:

receiving, by the one or more processors of the egress network device, a third packet from the neighboring network device;

decrypting, by the one or more processors of the egress network device, third metadata of the third packet using the path key;

obtaining, by the one or more processors of the egress network device, a second payload key from the third metadata of the third packet; and

decrypting, by the one or more processors of the egress network device, a third packet payload of the third packet using the second payload key.

16 . The method of claim 14 , further comprising:

receiving, by the one or more processors of the egress network device, a third packet from the neighboring network device, the third packet being associated with a second session;

decrypting, by the one or more processors of the egress network device, third metadata of the third packet using the path key;

obtaining, by the one or more processors of the egress network device, a second payload key from the third metadata of the third packet, the second payload key being associated with the second session; and

decrypting, by the one or more processors of the egress network device, a third packet payload of the third packet using the second payload key.

17 . The method of claim 14 , wherein the first payload key is further associated with a first type of service and wherein the method further comprises:

receiving, by the one or more processors of the egress network device, a third packet from the neighboring network device, the third packet being associated with a second type of service;

decrypting, by the one or more processors of the egress network device, third metadata of the third packet using the path key;

obtaining, by the one or more processors of the egress network device, a second payload key from the third metadata of the third packet, the second payload key being associated with the second type of service; and

decrypting, by the one or more processors of the egress network device, a third packet payload of the third packet using the second payload key.

18 . The method of claim 14 , wherein the egress network device comprises a session-based router.

19 . The method of claim 14 , wherein the neighboring network device comprises a session-based router.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 2025
From: MENON, ABILASH; BHAT, AVINASH PRAKASH; YUNGELSON, ANNA
To: JUNIPER NETWORKS, INC.
Reel/Frame 071911/0484 →
Continuity (3)
Continuation 17651599 · Feb 18, 2022
Provisional Application 63263066 · Oct 26, 2021
Related Publication 20240340163A1 · Oct 10, 2024
References Cited (22)
US 9729439B2 · MeLampy et al. · 2017 [cited by applicant]
US 10826876B1 · Sinn et al. · 2020 [cited by applicant]
US 20030031320A1 · Fan et al. · 2003 [cited by applicant]
US 20030200176A1 · Foster et al. · 2003 [cited by applicant]
US 20140044262A1 · Loprieno et al. · 2014 [cited by applicant]
US 20150058629A1 · Yarvis et al. · 2015 [cited by applicant]
US 20160205133A1 · Mackey et al. · 2016 [cited by applicant]
US 20160315762A1 · Moon et al. · 2016 [cited by applicant]
US 20170033924A1 · Jain et al. · 2017 [cited by applicant]
US 20180278419A1 · Higgins · 2018 [cited by examiner]
US 20190140826A1 · Carrel et al. · 2019 [cited by applicant]
US 20200304477A1 · Venkataraman · 2020 [cited by applicant]
US 20230078461A1 · Tanaka et al. · 2023 [cited by applicant]
US 20230131877A1 · Menon et al. · 2023 [cited by applicant]
WO 2017083980A1 · 2017 [cited by applicant]
WO 2021032304A1 · 2021 [cited by applicant]
“Transmission Control Protocol,” DARPA Internet Program, RFC 793, Sep. 1981, 91 pp. [cited by applicant]
Extended Search Report from counterpart European Application No. 22172852.0 dated Oct. 27, 2022, 9 pp. [cited by applicant]
Menezes et al., “Chapter 13: Key Management Techniques”, Handbook of Applied Cryptography, Oct. 1996, pp. 543-590., Retrieved from the Internet on Oct. 12, 2022 from URL: http://www.cacr.math.uwaterloo.ca/hac/. [cited by applicant]
Notice of Intent to Grant and Text Intended to Grant from counterpart European Application No. 22172852.0 dated May 10, 2024, 46 pp. [cited by applicant]
Prosecution History from U.S. Appl. No. 17/651,599, dated Dec. 28, 2023 through Mar. 15, 2024, 30 pp. [cited by applicant]
Response to Extended Search Report dated Oct. 27, 2022, from counterpart European Application No. 22172852.0 filed Nov. 1, 2023, 27 pp. [cited by applicant]