IP Library Granted Patent US 12,432,146
Granted Patent B2
US 12,432,146 · App. 18/479,465 · Granted Sep 30, 2025

Methods and apparatuses for handling end-to-end encryption

Inventors: Ana Lucia Pinheiro (Allen, TX); Robert Jaksa (Irving, TX); Stephie Lim (The Colony, TX)
Assignee: Comcast Cable Communications, LLC
H04L47/122H04L45/24H04L45/566H04L47/2483H04L63/0414H04L63/0435
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,146
App. No.
18/479,465
Granted
Sep 30, 2025
Kind
B2
Abstract

Methods, apparatuses, and systems for handling end-to-end encryption are described. A user device may send encrypted data to a server via a proxy using an encryption key shared with multiple network nodes across multiple layers. The proxy device may create an encrypted tunnel with an application server and send the encrypted data over the encrypted tunnel to the application server. The application server may receive the encrypted data over the encrypted tunnel from the proxy device. The application server may decrypt the encrypted data.

Claims (33)

1. A method comprising:

generating a frame that comprises a data packet encrypted based on an encryption key shared with a plurality of network nodes across a plurality of layers;

determining, based on Quality of Server (QOS) information associated with the data packet, a multipath connection with a proxy server;

sending, to the proxy server, a request to create an encrypted tunnel with an application server; and

sending, to the proxy server, the frame using a path of the multipath connection, wherein the frame is to be forwarded to the application server over the encrypted tunnel based on the encryption key shared with the plurality of network nodes across the plurality of layers.

2. The method of claim 1 , wherein the plurality of network nodes comprises the proxy server and the application server.

3. The method of claim 1 , wherein the plurality of layers comprises a Quick User Datagram Protocol (UDP) Internet Connections (QUIC) protocol layer, an Internet Protocol (IP) layer, and a UDP layer.

4. The method of claim 1 , wherein the frame comprises an Internet Protocol (IP) header, a User Datagram Protocol (UDP) header, a Quick UDP Internet Connections (QUIC) header, and the data packet encapsulated within a QUIC datagram.

5. The method of claim 1 , wherein the request further comprises a method field being set to CONNECT and a protocol field being set to CONNECT-UDP or CONNECT-IP.

6. The method of claim 1 , further comprising:

receiving, from the proxy server, configuration information to establish the multipath connection with the proxy server, wherein the configuration information comprises an Internet Protocol (IP) address of the proxy server, a port number for the proxy server, and a proxy type.

7. The method of claim 1 , wherein the proxy server is a network node performing one or more User Plane Functions (UPFs).

8. A method comprising:

determining, based on Quality of Server (QOS) information associated with a data packet, a multipath connection with a user device;

receiving, from the user device, a request to create an encrypted tunnel with an application server;

receiving, from the user device, using a path of the multipath connection, a frame comprising the data packet, wherein the data packet is encrypted based on an encryption key shared with a plurality of network nodes across a plurality of layers; and

sending, to the application server, the frame over the encrypted tunnel based on the encryption key shared with the plurality of network nodes across the plurality of layers.

9. The method of claim 8 , wherein the plurality of network nodes comprises the user device and the application server.

10. The method of claim 8 , wherein the plurality of layers comprises a Quick User Datagram Protocol (UDP) Internet Connections (QUIC) protocol layer, an Internet Protocol (IP) layer, and a UDP layer.

11. The method of claim 8 , wherein the frame comprises an Internet Protocol (IP) header, a User Datagram Protocol (UDP) header, a Quick UDP Internet Connections (QUIC) header, and the data packet encapsulated within a QUIC datagram.

12. The method of claim 8 , wherein the request further comprises a method field being set to CONNECT and a protocol field being set to CONNECT-UDP or CONNECT-IP.

13. The method of claim 8 , further comprising:

sending, to the user device, configuration information for the multipath connection with the user device, wherein the configuration information comprises an Internet Protocol (IP) address of a proxy server, a port number for the proxy server, and a proxy type.

14. The method of claim 13 , wherein the proxy server is a network node performing one or more User Plane Functions (UPFs).

15. A method comprising:

receiving, from a proxy server, a request to create an encrypted tunnel with a user device via the proxy server, wherein the encrypted tunnel is based on an encryption key shared with a plurality of network nodes across a plurality of layers;

receiving, from the proxy server, a frame over the encrypted tunnel, wherein the frame comprises a data packet encrypted based on the encryption key shared with the plurality of network nodes across the plurality of layers; and

decoding, based on the encryption key, the data packet.

16. The method of claim 15 , wherein the plurality of network nodes comprises the user device and the proxy server.

17. The method of claim 15 , wherein the plurality of layers comprises a Quick User Datagram Protocol (UDP) Internet Connections (QUIC) protocol layer, an Internet Protocol (IP) layer, and a UDP layer.

18. The method of claim 15 , wherein the frame comprises an Internet Protocol (IP) header, a User Datagram Protocol (UDP) header, a Quick UDP Internet Connections (QUIC) header, and the data packet encapsulated within a QUIC datagram.

19. The method of claim 15 , wherein the request further comprises a method field being set to CONNECT and a protocol field being set to CONNECT-UDP or CONNECT-IP.

20. The method of claim 15 , wherein the proxy server is a network node performing one or more User Plane Functions (UPFs).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: JAKSA, ROBERT; LIM, STEPHIE
To: COMCAST CABLE COMMUNICATIONS, LLC
Reel/Frame 071695/0902 →
Continuity (2)
Provisional Application 63411998 · Sep 30, 2022
Related Publication 20240114014A1 · Apr 4, 2024
References Cited (21)
US 10382401B1 · Lee · 2019 [cited by examiner]
US 10778588B1 · Singh · 2020 [cited by applicant]
US 11929925B2 · Dutta · 2024 [cited by examiner]
US 20050174937A1 · Scoggins · 2005 [cited by examiner]
US 20060212933A1 · Scoggins · 2006 [cited by examiner]
US 20130275534A1 · Larson · 2013 [cited by examiner]
US 20140071977A1 · Morrill et al. · 2014 [cited by applicant]
US 20170034129A1 · Sawant · 2017 [cited by examiner]
US 20180359811A1 · Verzun · 2018 [cited by examiner]
US 20190097881A1 · Lee · 2019 [cited by examiner]
US 20200304477A1 · Venkataraman · 2020 [cited by examiner]
US 20210204200A1 · Krishan · 2021 [cited by examiner]
US 20220021612A1 · Zhou et al. · 2022 [cited by applicant]
US 20220150059A1 · Tanaka · 2022 [cited by examiner]
US 20220191139A1 · Dutta · 2022 [cited by examiner]
US 20220360566A1 · Sawant · 2022 [cited by examiner]
US 20220393981A1 · Solanki · 2022 [cited by examiner]
US 20230118718A1 · Solanki · 2023 [cited by examiner]
US 20230198964A1 · Viswambharan · 2023 [cited by examiner]
International Search Report and Written Opinion issued in related application No. PCT/US23/34316 mailed Jan. 24, 2024. [cited by applicant]
International Search Report and Written Opinion issued in related application No. PCT/US23/34317 dated Apr. 22, 2024. [cited by applicant]