IP Library › Granted Patent US 12,647,266
Granted Patent B2
US 12,647,266 · App. 18/905,930 · Granted Jun 2, 2026

Efficient and secure hop-by-hop routing in hierarchical multi-region-fabric networks

Inventors: Arul Murugan Manickam (Mountain House, CA); Basavaraju Halappa (San Jose, CA)
Assignee: Cisco Technology, Inc.
H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,266
App. No.
18/905,930
Granted
Jun 2, 2026
Kind
B2
Abstract

In one embodiment, an illustrative method herein may comprise: receiving, at a device in a computer network, a packet having an unencrypted header and an encrypted segment list, wherein the device is an authorized segment hop device and wherein a destination address within the unencrypted header matches an address of the device; decrypting, by the device and in response to the destination address within the unencrypted header matching the address of the device, the encrypted segment list to expose at least a next segment hop address in the encrypted segment list; replacing, by the device, the destination address within the unencrypted header with the next segment hop address; and forwarding, from the device, the packet toward the next segment hop address along with the encrypted segment list.

Claims (39)

1 . A method, comprising:

receiving, at a device in a computer network, a packet having an unencrypted header and an encrypted segment list, wherein the device is an authorized segment hop device and wherein a destination address within the unencrypted header matches an address of the device, wherein the encrypted segment list is encrypted using a private key;

decrypting, by the device and in response to the destination address within the unencrypted header matching the address of the device, the encrypted segment list to expose at least a next segment hop address in the encrypted segment list, wherein decrypting comprises decrypting the encrypted segment list using a public key received from a controller;

replacing, by the device, the destination address within the unencrypted header with the next segment hop address; and

forwarding, from the device, the packet toward the next segment hop address along with the encrypted segment list.

2 . The method of claim 1 , wherein the encrypted segment list, when decrypted, is view-only to the device.

3 . The method of claim 1 , wherein the packet is formatted as a Segment Routing for Internet Protocol version 6 packet.

4 . The method of claim 1 , wherein the packet comprises an encrypted Software-Defined Wide Area Network Internet Protocol Security tunneled packet that remains un-decrypted while forwarding.

5 . The method of claim 4 , wherein a last segment hop for the packet decrypts the packet before forwarding toward a final destination device.

6 . The method of claim 1 , wherein the computer network comprises a hierarchical multi-region fabric.

7 . The method of claim 1 , further comprising:

rekeying keys used for decrypting the encrypted segment list with a controller.

8 . The method of claim 1 , further comprising:

reducing a segment left field by one segment prior to forwarding the packet.

9 . A method, comprising:

determining, by a device, a segment list corresponding to a segment route from a source device to a destination device via one or more authorized segment hop devices across a computer network;

encrypting, by the device, the segment list into an encrypted segment list using a private key, wherein a public key corresponding to the private key is distributed only to authorized devices of the computer network; and

causing, by the device, the encrypted segment list to be carried within packets forwarded from the source device to the destination device, wherein the packets are forwarded through the computer network with the encrypted segment list and an unencrypted header indicating a subsequent segment hop, and wherein only the one or more authorized segment hop devices are configured to decrypt the encrypted segment list using the public key to expose at least a next segment hop address and then forward the packets with the encrypted segment list and with the next segment hop address replacing the subsequent segment hop in the unencrypted header.

10 . The method of claim 9 , wherein the device is a controller within the computer network.

11 . The method of claim 10 , wherein causing comprises:

sending the encrypted segment list to an edge device to add the encrypted segment list to the packets when received from the source device.

12 . The method of claim 11 , wherein the edge device does not have the private key.

13 . The method of claim 9 , wherein the device is one of either the source device or an edge device associated with the source device.

14 . The method of claim 13 , wherein causing comprises:

encapsulating the packets within an encapsulation containing the encrypted segment list.

15 . The method of claim 13 , wherein determining comprises:

obtaining the segment list from a controller.

16 . The method of claim 9 , wherein the packets are formatted as a Segment Routing for Internet Protocol version 6 packets.

17 . The method of claim 9 , wherein the packets comprise encrypted Software-Defined Wide Area Network Internet Protocol Security tunneled packets that remain un-decrypted while forwarded across the computer network.

18 . The method of claim 9 , further comprising:

rekeying the private key and the public key.

19 . An apparatus, comprising:

one or more network interfaces to communicate with a network;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a non-transitory memory configured to store a process that is executable by the processor, the process comprising:

receiving, as a device, a packet having an unencrypted header and an encrypted segment list, wherein the device is an authorized segment hop device, wherein a destination address within the unencrypted header matches an address of the device, wherein the encrypted segment list is encrypted using a private key;

decrypting, in response to the destination address within the unencrypted header matching the address of the device, the encrypted segment list to expose at least a next segment hop address in the encrypted segment list, wherein decrypting comprises decrypting the encrypted segment list using a public key received from a controller;

replacing the destination address within the unencrypted header with the next segment hop address; and

forwarding the packet toward the next segment hop address along with the encrypted segment list.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2024
From: HALAPPA, BASAVARAJU; MANICKAM, ARUL MURUGAN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 068786/0780 →
Continuity (1)
Related Publication 20260100831A1 · Apr 9, 2026
References Cited (31)
US 11245617B1 · Bonica · 2022 [cited by examiner]
US 11394636B1 · Walker · 2022 [cited by examiner]
US 11936613B2 · Wing · 2024 [cited by examiner]
US 12199958B1 · Layton · 2025 [cited by examiner]
US 20040205332A1 · Bouchard · 2004 [cited by examiner]
US 20080065890A1 · Lundsgaard · 2008 [cited by applicant]
US 20170289114A1 · Wood · 2017 [cited by examiner]
US 20170324654A1 · Previdi et al. · 2017 [cited by applicant]
US 20180219783A1 · Pfister · 2018 [cited by examiner]
US 20190104064A1 · Cidon · 2019 [cited by examiner]
US 20190158605A1 · Markuze · 2019 [cited by examiner]
US 20200106702A1 · Acharya · 2020 [cited by examiner]
US 20200358698A1 · Song et al. · 2020 [cited by applicant]
US 20210034790A1 · Charles · 2021 [cited by examiner]
US 20210092054A1 · Kondapavuluru · 2021 [cited by examiner]
US 20210399983A1 · Blatt · 2021 [cited by examiner]
US 20210409323A1 · Menon · 2021 [cited by examiner]
US 20220103535A1 · Chifor · 2022 [cited by examiner]
US 20220166713A1 · Markuze · 2022 [cited by examiner]
US 20220417254A1 · Michaelis · 2022 [cited by examiner]
US 20230131877A1 · Menon · 2023 [cited by examiner]
US 20230327983A1 · Song · 2023 [cited by examiner]
US 20230388233A1 · Thoria · 2023 [cited by examiner]
US 20240039702A1 · Crawshaw · 2024 [cited by examiner]
US 20240106740A1 · Chang · 2024 [cited by examiner]
US 20240113902A1 · Michaelis · 2024 [cited by examiner]
US 20240205205A1 · Hou · 2024 [cited by examiner]
US 20250343677A1 · Inamdar · 2025 [cited by examiner]
WO 2019105462A1 · 2019 [cited by applicant]
WO 2023114351A1 · 2023 [cited by applicant]
WO WO2024124260A2 · 2024 [cited by examiner]