IP Library › Granted Patent US 12,494,911
Granted Patent B2
US 12,494,911 · App. 18/680,143 · Granted Dec 9, 2025

Internet packet provenance to verify packet validity and control packet usage

Inventor: George Sidman (Penn Valley, CA)
Assignee: ANON-X, INC.
H04L9/32H04L63/0245H04L63/0428H04L63/0464H04L63/0876H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,494,911
App. No.
18/680,143
Granted
Dec 9, 2025
Kind
B2
Abstract

This disclosure provides systems, devices, apparatus, and methods, including computer programs encoded on storage media, to verify packet validity and control packet usage based on centrally stored and locally cached device profiles and usage policies. A processing device may receive, at an encryption tunnel, an unencrypted packet or a previously encrypted packet. The packet is encrypted with a one or more layers of encryption (e.g., C2 and/or C1). The processing device generates a Passport to accompany the packet, where the Passport is a data file including information to validate the packet and control packet usage. The processing device encrypts the Passport and the packet with an additional layer of encryption (C3) that provides a multi-tiered encryption stack for the packet and outputs, from the encryption tunnel, the Passport and the packet encrypted with the additional layer of encryption.

Claims (54)

1 . A method comprising:

receiving, at a tunnel, a packet including an indication of a source from which the packet originated, the packet being encrypted with a first layer of encryption;

encrypting provenance data and the packet with a second layer of encryption that provides a multi-tiered encryption stack for the packet, the provenance data to accompany the packet encrypted with the first layer of encryption and including embedded provenance information to validate the source from which the packet originated and embedded usage policy information to control usage of the packet, the provenance data not being a header of the packet or trailer of the packet; and

outputting, from the tunnel, the provenance data and the packet encrypted with the second layer of encryption.

2 . The method of claim 1 , further comprising:

decrypting the second layer of encryption of the multi-tiered encryption stack to reveal the packet encrypted with the first layer of encryption and the provenance data, the provenance data being appended to the packet encrypted with the first layer of encryption.

3 . The method of claim 2 , further comprising:

validating, based on the information included in the provenance data, the packet encrypted with the first layer of encryption.

4 . The method of claim 3 , wherein the packet is validated at a hop point or an endpoint with or without reference to an external database.

5 . The method of claim 3 , further comprising:

decrypting, at a destination of the packet, the first layer of encryption based on the packet being validated using the information included in the provenance data.

6 . The method of claim 1 , wherein the header of the packet and the trailer of the packet correspond to a protocol structure and a use indicated by Internet Engineering Task Force (IETF) request for comments (RFC).

7 . The method of claim 1 , wherein a format of the provenance data includes JavaScript Object Notation (JSON), extensible markup language (XML) or other formatted data.

8 . The method of claim 1 , further comprising:

rejecting the packet when the packet is not accompanied by the provenance data within the tunnel.

9 . The method of claim 1 , wherein the provenance data includes at least one of: an internet protocol (IP) address, a device profile, an encryption key, or a device fingerprint, or one or more other unique identifiers.

10 . The method of claim 1 , wherein the provenance data includes a device fingerprint for any computing device, an internet-of-things (IoT) device, or other network connected equipment.

11 . The method of claim 1 , wherein the packet includes an initial layer of encryption prior to the first layer of encryption, and

wherein the initial layer of encryption corresponds to a cryptography 1 (C1) inner encryption layer, the first layer of encryption corresponds to a cryptography 2 (C2) middle encryption layer, and the second layer of encryption corresponds to a cryptography 3 (C3) outer encryption layer.

12 . The method of claim 1 , wherein the packet is at least one of: encrypted within the tunnel or encrypted prior to receiving the packet at the tunnel.

13 . The method of claim 1 , wherein the indication of the source from which the packet originated corresponds to an internet protocol (IP) address.

14 . The method of claim 1 , wherein the embedded usage policy information controls the usage of the packet at a granularity of at least one of: an individual computing device, an internet of things (IoT) device, a machine sensor, a protocol, a file type, and internet protocol (IP) geofencing level, an operational date, or an operation time.

15 . An apparatus comprising:

a memory; and

at least one processor coupled to the memory and configured to:

receive, at a tunnel, a packet including an indication of a source from which the packet originated, the packet being encrypted with a first layer of encryption;

encrypt provenance data and the packet with a second layer of encryption that provides a multi-tiered encryption stack for the packet, the provenance data to accompany the packet encrypted with the first layer of encryption, the provenance data including embedded provenance information to validate the source from which the packet originated and an embedded usage policy information to control a usage of the packet, the provenance data not being a header of the packet or a trailer of the packet; and

output, from the tunnel, the provenance data and the packet encrypted with the second layer of encryption.

16 . The apparatus of claim 15 , wherein the at least one processor is further configured to:

decrypt the second layer of encryption of the multi-tiered encryption stack to reveal the packet encrypted with the first layer of encryption and the provenance data in the clear, the provenance data being appended to the packet encrypted with the first layer of encryption.

17 . The apparatus of claim 16 , wherein the at least one processor is further configured to:

validate, based on the information included in the provenance data, the packet encrypted with the first layer of encryption.

18 . The apparatus of claim 17 , wherein the packet is validated at a hop point or an endpoint without reference to an external database.

19 . The apparatus of claim 17 , wherein the at least one processor is further configured to:

decrypt, at a destination of the packet, the first layer of encryption based on the packet being validated using the information included in the provenance data.

20 . The apparatus of claim 15 , wherein the header of the packet and the trailer of the packet corresponding to a protocol structure and a use indicated by Internet Engineering Task Force (IETF) request for comments (RFC).

21 . A method comprising:

receiving, a destination, an encrypted packet that has been encrypted with a multi-tiered encryption stack having first and second layers of encryption;

decrypting the second layer of encryption packet to reveal provenance data and the packet encrypted with the first layer of encryption, the provenance data accompanying the packet encrypted with the first layer of encryption and including embedded provenance information to validate the source from which the packet originated and embedded usage policy information to control usage of the packet, the provenance data not being a header of the packet or trailer of the packet;

decrypting the packet that is encrypted with a first layer of encryption based on the packet being validated using the information included in the provenance data; and

outputting the decrypted packet upon being decrypted based on the packet being validated using the information included in the provenance data, the decrypted packet including an indication of the source form which the packet originated.

22 . The method of claim 21 , further comprising:

validating, based on the information included in the provenance data, the packet encrypted with the first layer of encryption.

23 . The method of claim 22 , wherein the packet is validated at a hop point or an endpoint without reference to an external database.

24 . The method of claim 21 , wherein the header of the packet and the trailer of the packet correspond to a protocol structure and a use indicated by Internet Engineering Task Force (IETF) request for comments (RFC).

25 . The method of claim 21 , wherein a format of the provenance data includes JavaScript Object Notation (JSON) or extensible markup language (XML).

26 . The method of claim 21 , further comprising:

rejecting the packet when the packet is not accompanied by the provenance data within an encryption tunnel.

27 . The method of claim 21 , wherein the provenance data includes at least one of: an internet protocol (IP) address, a device profile, an encryption key, or a device fingerprint.

28 . The method of claim 21 , wherein the provenance data includes a device fingerprint for an internet-of-things (IoT) device.

29 . The method of claim 21 , wherein the packet includes an initial layer of encryption prior to the first layer of encryption, and

wherein the initial layer of encryption corresponds to a cryptography 1 (C1) inner encryption layer, the first layer of encryption corresponds to a cryptography 2 (C2) middle encryption layer, and the second layer of encryption corresponds to a cryptography 3 (C3) outer encryption layer.

30 . The method of claim 21 , wherein an indication of the source from which the packet originated corresponds to an internet protocol (IP) address.

31 . The method of claim 21 , wherein the embedded usage policy information controls the usage of the packet at a granularity of at least one of: an individual computing device, an internet of things (IoT) device, a machine sensor, a protocol, a file type, and internet protocol (IP) geofencing level, an operational date, or an operation time.

Continuity (3)
Continuation 18348985 · Jul 7, 2023
Provisional Application 63359597 · Jul 8, 2022
Related Publication 20250030544A1 · Jan 23, 2025
References Cited (36)
US 6092191A · Shimbo et al. · 2000 [cited by applicant]
US 10250390B1 · Gray et al. · 2019 [cited by applicant]
US 10826876B1 · Sinn et al. · 2020 [cited by applicant]
US 10979402B1 · Hartley et al. · 2021 [cited by applicant]
US 11048686B2 · Rapanen et al. · 2021 [cited by applicant]
US 12432184B2 · Solanki · 2025 [cited by examiner]
US 20030185368A1 · Bradfield et al. · 2003 [cited by applicant]
US 20080259919A1 · Monga · 2008 [cited by applicant]
US 20090034557A1 · Fluhrer · 2009 [cited by examiner]
US 20120159159A1 · Messerges · 2012 [cited by examiner]
US 20130239169A1 · Nakhjiri · 2013 [cited by applicant]
US 20170161270A1 · Mason et al. · 2017 [cited by applicant]
US 20170171364A1 · Hu et al. · 2017 [cited by applicant]
US 20180115529A1 · Munger et al. · 2018 [cited by applicant]
US 20190109714A1 · Clark et al. · 2019 [cited by applicant]
US 20190116159A9 · Munger · 2019 [cited by examiner]
US 20190349426A1 · Smith et al. · 2019 [cited by applicant]
US 20200084222A1 · William et al. · 2020 [cited by applicant]
US 20200162431A1 · Goldschlag · 2020 [cited by examiner]
US 20210092094A1 · Kim · 2021 [cited by examiner]
US 20210352109A1 · Hughes et al. · 2021 [cited by applicant]
US 20220345459A1 · Tseng et al. · 2022 [cited by applicant]
US 20220377823A1 · Elazzouni et al. · 2022 [cited by applicant]
US 20230126851A1 · Bansal et al. · 2023 [cited by applicant]
US 20230179635A1 · Schiel et al. · 2023 [cited by applicant]
US 20230188513A1 · Ren · 2023 [cited by examiner]
US 20230188534A1 · Hill et al. · 2023 [cited by applicant]
US 20230247006A1 · Pemmaraju et al. · 2023 [cited by applicant]
Austin. “Internet Protocol Security (IPSec)”, 2015. Retrieved from <https://www.anardil.net/2015/internet-protocol-security-ipsec.html>. (Year: 2015). [cited by examiner]
Netgear. “1Introduction to VPN | VPN Concepts, Tips, and Techniques”, Jul. 2003. Retrieved from <https://www.downloads.netgear.com/files/vpn_intro.pdf>. (Year: 2003). [cited by examiner]
J. Wu, G. Ren and X. Li, “Source Address Validation: Architecture and Protocol Design,” 2007 IEEE International Conference on Network Protocols, Beijing, China, 2007, pp. 276-283, doi: 10.1109/ICNP.2007.4375858. (Year: … [cited by examiner]
Liu et al., “Passport: Secure and Adoptable Source Authentication”, NSDI, vol. 8, USENIX Symposium on Networked Systems Design and Implementation, 2008, pp. 365-378. [cited by applicant]
Naous et al., “Verifying and enforcing network paths with ICING”, Proceedings of the Seventh Conference on Emerging Networking Experiments and Technologies, 2011, 12 pages. [cited by applicant]
Notice of Allowance received for U.S. Appl. No. 18/348,985, mailed on Apr. 18, 2024, 9 pages. [cited by applicant]
Wang et al., “Inter-domain routing validator based spoofing defence system”, 2010 IEEE International Conference on Intelligence and Security Informatics. IEEE, 2010, pp. 153-155. [cited by applicant]
Wolf et al., “High-Performance Capabilities for 1-Hop Containment of Network Attacks”, IEEE/ACM Transactions on Networking, vol. 21, No. 6, Dec. 2013, pp. 1931-1946. [cited by applicant]