IP Library › Granted Patent US 12,063,207
Granted Patent B2
US 12,063,207 · App. 17/487,344 · Granted Aug 13, 2024

Non-interfering access layer end-to-end encryption for IOT devices over a data communication network

Inventor: Kaashif Hassan Nawaz (England, GB)
Assignee: Fortinet, Inc.
H04L63/0485H04L63/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,063,207
App. No.
17/487,344
Granted
Aug 13, 2024
Kind
B2
Abstract

Once a new session of data packets is detected, whether to proxy encrypt the data packets, on behalf of a specific headless endpoint device from the plurality of headless endpoint devices for a session, is determined based on analysis of payload data of a data packet from a session. Responsive to a determination to proxy encrypt data packets, encryption attributes are set up between a local data port on the network device and a remote data port on a remote network device as parsed from a header of the data packet. Outbound and inbound data packets of the session secure OSI layers 4 to 7 of the outbound data packets of the session are encrypted, according to the encryption attributes, without interference to OSI layers 1 to 3.

Claims (33)

1. A network switch device communicatively coupled to a plurality of headless endpoint devices for providing proxy encryption services for end-to-end encrypted communications for the plurality of headless endpoint devices with destinations over a data communication network, the network switch device comprising:

a processor;

a network interface communicatively coupled to the processor and to the data communication network to receive inbound data packets for a plurality of headless endpoint devices and to receive outbound data packets from a plurality of headless endpoint devices; and

a memory, communicatively coupled to the processor and storing:

an endpoint connection manager to register MAC addresses for the plurality of headless endpoint devices;

a DPI module to determine whether to proxy encrypt the data packets, on behalf of a specific headless endpoint device from the plurality of headless endpoint devices for a session, based on analysis of payload data of a data packet from a session;

a port configuration module to, responsive to a determination to proxy encrypt data packets, set up encryption attributes between a local data port on the network switch device and a remote data port on a remote network device as parsed from a header of the data packet;

an encryption module to parse outbound data packets of the session and encrypt OSI layers 5 to 7 of the outbound data packets of the session according to the encryption attributes, and generate encrypted outbound data packets; and

a decryption module to parse inbound data packets of the session and decrypt layers 5 to 7 of the inbound data packets according to the encryption attributes, and generate decrypted inbound data packets,

wherein the network interface transmits the encrypted outbound data packets from the specific headless endpoint device, and transmits the decrypted inbound data packets to the specific headless endpoint device.

2. The network switch device of claim 1 , wherein the DPI module determines to proxy encrypt the data packets responsive to the analysis of the data packet payload detecting HTTP only mod bus only, or bacnet.

3. The network switch device of claim 1 , wherein the DPI module determines not to proxy encrypt the data packets responsive to the analysis of the data packet payload.

4. The network switch device of claim 1 , wherein a first OT device is authenticated with the access point and a second OT device is authenticated with a second access point, wherein a Wi-Fi controller manages both the access point and the second access point.

5. The network switch device of claim 1 , wherein the endpoint device sending the data packets of the session is incapable of encryption.

6. The network switch device of claim 1 , wherein the encryption module encrypts HTTP data packets with HTTPS.

7. The network switch device of claim 1 , wherein the endpoint device sending the data packets of the session is a headless device.

8. The network switch device of claim 1 , wherein the encryption module does not interfere with OSI layers 1 to 3 of the data packet.

9. The network switch device of claim 1 , wherein the specific headless endpoint device connects wirelessly to the network interface of the network device.

10. The network switch device of claim 1 , wherein the network device is also communicatively coupled to the Internet.

11. A method in a network switch device, implemented at least partially in hardware and communicatively coupled to a plurality of headless endpoint devices, for providing proxy encryption services for end-to-end encrypted communications for the plurality of headless endpoint devices with destinations over a data communication network, the method comprising the steps of:

registering MAC addresses for the plurality of headless endpoint devices;

determining whether to proxy encrypt the data packets, on behalf of a specific headless endpoint device from the plurality of headless endpoint devices for a session, based on analysis of payload data of a data packet from a session;

responsive to a determination to proxy encrypt data packets, setting-up encryption attributes between a local data port on the network switch device and a remote data port on a remote network device as parsed from a header of the data packet;

parsing outbound data packets of the session and encrypt OSI layers 5 to 7 of the outbound data packets of the session according to the encryption attributes, and generate encrypted outbound data packets; and

parsing inbound data packets of the session and decrypt layers 5 to 7 of the inbound data packets according to the encryption attributes, and generate decrypted inbound data packets,

wherein the network interface transmits the encrypted outbound data packets from the specific headless endpoint device, and transmits the decrypted inbound data packets to the specific headless endpoint device.

12. A non-transitory computer-readable media in a network switch device, implemented at least partially in hardware and communicatively coupled to a plurality of headless endpoint devices for, when executed by a processor, for providing proxy encryption services for end-to-end encrypted communications for the plurality of headless endpoint devices with destinations over a data communication network, the method comprising the steps of:

registering MAC addresses for the plurality of headless endpoint devices;

determining whether to proxy encrypt the data packets, on behalf of a specific headless endpoint device from the plurality of headless endpoint devices for a session, based on analysis of payload data of a data packet from a session;

responsive to a determination to proxy encrypt data packets, setting-up encryption attributes between a local data port on the network switch device and a remote data port on a remote network device as parsed from a header of the data packet;

parsing outbound data packets of the session and encrypt OSI layers 5 to 7 of the outbound data packets of the session according to the encryption attributes, and generate encrypted outbound data packets; and

parsing inbound data packets of the session and decrypt layers 5 to 7 of the inbound data packets according to the encryption attributes, and generate decrypted inbound data packets,

wherein the network interface transmits the encrypted outbound data packets from the specific headless endpoint device, and transmits the decrypted inbound data packets to the specific headless endpoint device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 28, 2021
From: NAWAZ, KAASHIF HASSAN
To: FORTINET, INC.
Reel/Frame 057632/0762 →
Continuity (1)
Related Publication 20230095149A1 · Mar 30, 2023
Cited By (2)
US 12,355,740 US 12,732,360