IP Library Granted Patent US 12,647,403
Granted Patent B2
US 12,647,403 · App. 18/751,956 · Granted Jun 2, 2026

Multiplexing encrypted tunnels

Inventors: Min Hao Chen (Milpitas, CA); Yash Amin (Milpitas, CA); Pradeep K. Aragonda (Fremont, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/0485H04L63/029
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,403
App. No.
18/751,956
Granted
Jun 2, 2026
Kind
B2
Abstract

Multiplexing of encrypted tunnels is facilitated by the use of a custom header. Upon receiving a packet, information about the packet is collected stored, such as a port number, destination instance identifier, and a hash key. A custom packet is generated that includes the encrypted packet and a custom header including some or all of the collected information. Middleware may retrieve information from the custom header to perform load balancing, routing, or other function. The destination instance may use information from the custom header to obtain the port number, which may be changed in the custom packet to accommodate limitations of the middleware.

Claims (24)

1 . A method comprising:

encrypting an original packet and encapsulating the encrypted packet for tunneling;

modifying the tunneling encapsulated encrypted packet, wherein the modifying comprises adding a custom header to the tunneling encapsulated encrypted packet, changing a first port number in a tunnel user datagram protocol (UDP) header to a second port number, and recording the first port number or an offset between the first and second port numbers into the custom header; and

transmitting the modified packet to a destination.

2 . The method of claim 1 further comprising determining a source identifier and a hash key derived from a L3 or L4 header of the original packet.

3 . The method of claim 2 further comprising storing the source identifier and the hash key from the original packet prior to encrypting the original packet.

4 . The method of claim 3 further comprising:

storing the source identifier and a second hash key derived from a second original packet;

encrypting the second original packet and encapsulating the encrypted second original packet for tunneling;

modifying the tunneling encapsulated, encrypted second original packet, wherein the modifying comprises adding a second custom header to the tunneling encapsulated encrypted second original packet, changing a third port number in a tunnel user datagram protocol (UDP) header to a fourth port number, and recording the third port number or an offset between the third and fourth port numbers into the custom header to obtain a second modified packet; and

transmitting the second modified packet to a second destination.

5 . The method of claim 1 , further comprising passing the original packet to a networking stack for the encrypting and encapsulating, wherein the modifying is after the networking stack encrypts and encapsulates the original packet for tunneling.

6 . The method of claim 1 , wherein the first port number is an open port of a firewall between a source of the original packet and the destination.

7 . A method comprising:

retrieving a base port number or port offset from a custom header of a tunneling encapsulated packet that comprises an encrypted packet, the custom header, a tunnel header, a tunnel user datagram protocol (UDP) header that indicates a first port number, and a tunnel Internet Protocol (IP) header;

modifying, the tunneling encapsulated packet to change the first port number in the tunnel UDP header to a second port number that is the base port number or based on applying the port offset to the first port number and removing the custom header; and

passing the modified, tunneling encapsulated packet to a networking stack for tunnel decapsulation and decrypting.

8 . A method comprising:

retrieving a custom header from a tunneling encapsulated packet which comprises an encrypted packet, the custom header, a tunnel header, a tunnel user datagram protocol (UDP) header, and a tunnel Internet Protocol (IP) header;

determining an identifier of a source of the encrypted packet from the customer header;

selecting a destination from a plurality of destinations based, at least in part, on the source identifier determined from the custom header; and

transmitting the tunneling encapsulated packet to the selected destination.

9 . The method of claim 8 , further comprising determining, from the custom header, a hash key derived from a L3 or L4 header of the encrypted packet, wherein selecting the destination is also based on the hash key.

10 . The method of claim 9 , wherein selecting the destination based on the source identifier and the hash key comprises load balancing based on the hash key.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2025
From: PROSIMO INC.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 071425/0477 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT THE NAME OF THE RECEIVING PARTY PREVIOUSLY RECORDED AT REEL: 67815 FRAME: 853. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 15, 2025
From: CHEN, MIN HAO; AMIN, YASH; ARAGONDA, PRADEEP K.
To: PROSIMO INC.
Reel/Frame 069930/0653 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 24, 2024
From: CHEN, MIN HAO; AMIN, YASH; ARAGONDA, PRADEEP K.
To: PROSIMO INC.
Reel/Frame 067815/0853 →
Continuity (1)
Related Publication 20250392578A1 · Dec 25, 2025
References Cited (6)
US 9331920B2 · Nedeltchev · 2016 [cited by examiner]
US 20060262783A1 · Nedeltchev · 2006 [cited by examiner]
US 20190020684A1 · Qian · 2019 [cited by examiner]
US 20190104438A1 · Mittal · 2019 [cited by examiner]
US 20210037057A1 · Suleman · 2021 [cited by examiner]
US 20210400029A1 · Wang · 2021 [cited by examiner]