IP Library › Granted Patent US 12,452,057
Granted Patent B2
US 12,452,057 · App. 18/130,425 · Granted Oct 21, 2025

Methods and systems of a packet orchestration to provide data encryption at the IP layer, utilizing a data link layer encryption scheme

Inventors: Kelvin R. Franklin (Fremont, CA); Jonathan Flack (Seattle, WA)
H04L9/3066H04L9/0852
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,452,057
App. No.
18/130,425
Granted
Oct 21, 2025
Kind
B2
Abstract

In one aspect, a method for packet orchestration to provide data encryption at the internet protocol (IP) layer, includes the step of providing a quantum secure pre-shared key derivation scheme for a data link layer bulk encryption algorithm, meaning the ability to setup a separate communication channel, via the SSH protocol, and leverage ECDH over said channel to share pre-shared keys. The method includes the step of providing a set of software-based network bridges. The method includes the step of assigning a set of network ports to specific bridges, wherein the set of network ports implement segmentation and isolation based on an organizational policy.

Claims (25)

1. A method for packet orchestration to provide data encryption at an internet protocol (IP) layer, comprising the steps of:

providing a quantum secure pre-shared key derivation scheme for a data link layer bulk encryption algorithm;

setting up a separate communication channel using a Secure Shell Protocol (SSH) protocol;

leveraging Elliptic-curve Diffie-Hellman (ECDH) protocol over said separate communication channel to share a set of pre-shared keys;

providing a set of software-based network bridges;

assigning a set of network ports to the set of software-based specific bridges, wherein the set of network ports implement segmentation and isolation based on an organizational policy;

provisioning and configuring of a set of computer processing unit (CPU) cores to handle wire-speed data encryption and decryption on a per bridge segmentation standpoint, wherein each network bridge segment has a CPU core affinity, and recommended buffer allocation;

provisioning per bridge, an IP overlay encapsulation of a set of encrypted packets; and

provisioning a Network interface card (NIC) offloading and packet steering functionality, wherein the NIC offloading and packet steering functionality provides network packet handling for network communications by orchestrating, using a selected NIC protocol, a hashing method that controls interrupt request queue affinity to allow for maximum distribution of network data across the set of CPU cores;

implementing load balancing across the set of CPU cores during implementation of the data link layer bulk encryption algorithm,

wherein a NIC Driver specification of the NIC provides a method for interaction with one or more interrupts (IRQs) that provide access to a CPU queue of the CPU,

wherein each CPU core of the set of CPU cores has an ability to encrypt or decrypt traffic,

wherein when leveraging the CPU queue access to the CPU queue is controlled by a hash method on a set of four tuples of the TCP/IP Packet flow outbound and inbound to the NIC,

wherein the set of four tuples of the TCP/IP Packet flow comprises a Destination IP/Source, an IP/Destination TCP, an UDP Port/Source TCP and a UDP Port, and

wherein the hash method comprises a mathematical hash of the packet flow and controls to which CPU core the traffic is routed such that there is a fine grain use of each CPU core, as packet flow information is different for each flow using the set of four tuples.

2. The method of claim 1 , wherein the set of network ports are assigned to set of software-based network bridges based on a set of communication and isolation requirements.

3. The method of claim 1 , wherein the mechanism for provisioning per bridge is provided using segment isolation.

4. The method of claim 1 , wherein the provisioning per bridge of the IP overlay encapsulation of the set of encrypted packets is implemented with a specified encapsulation/decapsulation functionality of an operating-system software and a network vendors ethernet controller.

5. The method of claim 1 , wherein the IP overlay encapsulation is implemented with a tunneling protocol.

6. The method of claim 1 , wherein the network packet handling of the NIC offloading and packet steering functionality comprises an encapsulation operation.

7. The method of claim 1 , wherein the network packet handling of the NIC offloading and packet steering functionality comprises a checksum operation.

8. The method of claim 1 , wherein the network packet handling of the NIC offloading and packet steering functionality comprises a buffer allocation operation.

9. The method of claim 1 , wherein the provisioning per bridge and the IP overlay encapsulation of encrypted packets with post quantum encryption is implemented per the specifications of a specified Ethernet Controller manufacturer.

10. The method of claim 9 , wherein an Ethernet Controller enables and configures the encapsulation/decapsulation offloading functionality.

11. The method of claim 10 , wherein each CPU core has an ability to encrypt or decrypt traffic, based on the capabilities specified by a manufacturer.

Continuity (2)
Continuation In Part 16983176 · Aug 3, 2020
Related Publication 20240106647A1 · Mar 28, 2024
References Cited (15)
US 7120791B2 · Volpano · 2006 [cited by examiner]
US 8832776B1 · Natarajan · 2014 [cited by examiner]
US 11012507B2 · Tumuluru · 2021 [cited by examiner]
US 20140056307A1 · Hutchison · 2014 [cited by examiner]
US 20150058682A1 · Nagumo · 2015 [cited by examiner]
US 20150124828A1 · Cj · 2015 [cited by examiner]
US 20150301975A1 · Garg · 2015 [cited by examiner]
US 20150334008A1 · Kim · 2015 [cited by examiner]
US 20160065407A1 · Saltsidis · 2016 [cited by examiner]
US 20160378545A1 · Ho · 2016 [cited by examiner]
US 20190042310A1 · Browne · 2019 [cited by examiner]
US 20190173850A1 · Jain · 2019 [cited by examiner]
US 20190372948A1 · Varghese · 2019 [cited by examiner]
US 20210185025A1 · Wang · 2021 [cited by examiner]
Green et al., “https:/Avww.ric-editor.org/ric/rfc5656.txt”, Dec. 2009, Network Working Group, pp. 1-18 (Year: 2009). [cited by examiner]