IP Library › Granted Patent US 12,549,526
Granted Patent B2
US 12,549,526 · App. 18/542,247 · Granted Feb 10, 2026

End-to-end network encryption from customer on-premise network to customer virtual cloud network using customer-managed keys

Inventors: Nachiketh Rao Potlapally (McLean, VA); Pradeep Vincent (Bothell, WA); Jagwinder Singh Brar (Bellevue, WA)
Assignee: ORACLE INTERNATIONAL CORPORATION
H04L63/0428G06F9/45541H04L9/083H04L63/029H04L63/164H04L12/4641
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,526
App. No.
18/542,247
Granted
Feb 10, 2026
Kind
B2
Abstract

For end-to-end encryption of a virtual cloud network, a VPN tunnel from a customer device is terminated at a host network headend device using encryption keys secured in hardware and managed by the customer. The network headend device can be a card in a bare-metal server with one or more network virtualization devices. The network headend device is configured to receive a first key provisioned by a customer; receive a first data packet sent from a device of the customer; and decrypt the first data packet using the first key to obtain information. A network virtualization device is configured to receive the information from the network headend device; ascertain that the information is to be sent to a virtual machine in a virtual cloud network; ascertain that data in the virtual cloud network is configured to be encrypted; and encrypt the information with a second key to generate a second data packet before routing the second data packet to the virtual machine.

Claims (46)

1 . A system comprising:

a network headend device comprising memory and providing an endpoint for a secured transmission link located within a virtual cloud network (“VCN”), wherein the network headend device is configured-to:

receive a first key provisioned by a customer;

receive a first data packet sent from a device of the customer; and

decrypt the first data packet using the first key to obtain information; and

a network virtualization device comprising memory, wherein the network virtualization device is configured to:

receive the information from the network headend device;

ascertain that the information is to be sent to a destination in the VCN;

generate a second data packet, wherein the second data packet comprises the information encrypted using a second key; and

route the second data packet to the destination in the VCN.

2 . The system of claim 1 , wherein the system is maintained by a host, and the host does not have access to the first key or the second key.

3 . The system of claim 1 , wherein both the network headend device and the network virtualization device are comprised in a VCN gateway associated with the VCN.

4 . The system of claim 3 , wherein the VCN gateway comprises a processor.

5 . The system of claim 3 , wherein the VCN gateway comprises a first network card associated with the VCN headend and a second network card associated with the network virtualization device.

6 . The system of claim 3 , wherein the VCN gateway is dedicated to the customer.

7 . The system of claim 3 , wherein the VCN headend and the network virtualization device share at least one of: a network card; a rack; or a room.

8 . The system of claim 3 , wherein the VCN gateway is configured to terminate an Internet Protocol SECurity (IPSec) tunnel.

9 . The system of claim 1 , wherein the network headend device is configured to be a termination point of an internet protocol security (IPSec) tunnel formed between the network headend device and a customer device.

10 . The system of claim 1 , wherein the first data packet is routed through the public Internet.

11 . The system of claim 1 , wherein the first data packet is routed through a set of private links, without using links in the public Internet.

12 . The system of claim 1 , wherein the destination in the VCN comprises a virtual machine.

13 . The system of claim 12 , wherein the network virtualization device supports the virtual machine in the virtual cloud network.

14 . The system of claim 1 , wherein the network headend device is dedicated to the customer, such that no other customers of a host use the network headend device.

15 . The system of claim 1 , wherein the network headend device is a first network headend device and the system further comprises a second network headend device configured to decrypt data from the customer.

16 . The system of claim 1 , wherein:

the network virtualization device is a first network virtualization device;

the virtual cloud network is a first virtual cloud network;

the system further comprises a second network virtualization device; and

the second network virtualization device is configured to receive data from the network headend device and encrypt data received from the network headend device for a second virtual cloud network using a third key.

17 . The system of claim 16 , wherein the first network virtualization device and the second network virtualization device are part of the same network interface card.

18 . A method comprising:

receiving, using a network headend device, a first key provisioned by a customer, the network headend device providing an endpoint for a secure transmission link within a virtual cloud network (“VCN”);

receiving a first data packet at the network headend device sent from a device of the customer;

decrypting the first data packet, using the first key, to obtain information;

receiving, using a network virtualization device, the information from the network headend device;

ascertaining that the information is to be sent to a destination in the VCN;

generate a second data packet, wherein the second data packet comprises the information encrypted using a second key; and

routing the second data packet to the destination in the VCN.

19 . A non-transitory computer-readable memory storing a plurality of instructions executable by one or more processors, the plurality of instructions comprising instructions that when executed by the one or more processors cause the one or more processors to perform processing comprising:

receiving, using a network headend device, a first key provisioned by a customer, the network headend device providing an endpoint for a secure transmission link within a virtual cloud network (“VCN”);

receiving a first data packet at the network headend device sent from a device of the customer;

decrypting the first data packet, using the first key, to obtain information;

receiving, using a network virtualization device, the information from the network headend device;

ascertaining that the information is to be sent to a destination in the VCN;

generate a second data packet, wherein the second data packet comprises the information encrypted using a second key; and

routing the second data packet to the destination in the VCN.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2023
From: POTLAPALLY, NACHIKETH RAO; VINCENT, PRADEEP; BRAR, JAGWINDER SINGH
To: ORACLE INTERNATIONAL CORPORATION
Reel/Frame 065889/0046 →
Continuity (2)
Continuation 17133523 · Dec 23, 2020
Related Publication 20240129280A1 · Apr 18, 2024
References Cited (58)
US 10250522B1 · Anderson · 2019 [cited by examiner]
US 10326744B1 · Nossik et al. · 2019 [cited by applicant]
US 11848918B2 · Potlapally et al. · 2023 [cited by applicant]
US 11856097B2 · Potlapally et al. · 2023 [cited by applicant]
US 12231558B2 · Potlapally et al. · 2025 [cited by applicant]
US 20050013317A1 · Lindsay et al. · 2005 [cited by applicant]
US 20070055891A1 · Plotkin et al. · 2007 [cited by applicant]
US 20100115174A1 · Akyol et al. · 2010 [cited by applicant]
US 20110314469A1 · Qian et al. · 2011 [cited by applicant]
US 20130042086A1 · Cardona et al. · 2013 [cited by applicant]
US 20140019745A1 · Dodgson et al. · 2014 [cited by applicant]
US 20140269705A1 · Decusatis et al. · 2014 [cited by applicant]
US 20140283010A1 · Rutkowski et al. · 2014 [cited by applicant]
US 20150301844A1 · Droux et al. · 2015 [cited by applicant]
US 20160182458A1 · Shatzkamer et al. · 2016 [cited by applicant]
US 20160285910A1 · Galinski · 2016 [cited by examiner]
US 20160337329A1 · Sood et al. · 2016 [cited by applicant]
US 20180041398A1 · Cohn et al. · 2018 [cited by applicant]
US 20190007378A1 · Jowett et al. · 2019 [cited by applicant]
US 20190044927A1 · Sood et al. · 2019 [cited by applicant]
US 20190081891A1 · Mundkur · 2019 [cited by examiner]
US 20190087575A1 · Sahita et al. · 2019 [cited by applicant]
US 20190102323A1 · Durham et al. · 2019 [cited by applicant]
US 20190103972A1 · Pope et al. · 2019 [cited by applicant]
US 20200127981A1 · Yang · 2020 [cited by examiner]
US 20200279060A1 · McGraw · 2020 [cited by examiner]
US 20210117360A1 · Kutch et al. · 2021 [cited by applicant]
US 20220021678A1 · Kreger-Stickles et al. · 2022 [cited by applicant]
US 20220150055A1 · Cui et al. · 2022 [cited by applicant]
US 20220164451A1 · Bagwell · 2022 [cited by applicant]
US 20220276886A1 · Diaz-Cuellar et al. · 2022 [cited by applicant]
JP 2005503047A · 2005 [cited by applicant]
JP 2015138336A · 2015 [cited by applicant]
JP 2016511610A · 2016 [cited by applicant]
JP 2019205030A · 2019 [cited by applicant]
WO 2008146639A1 · 2008 [cited by applicant]
WO 2012042637A1 · 2012 [cited by applicant]
“An In-Depth Look at SR-IOV NIC Passthrough”, Vswitchzero, Online Available At: https://vswitchzero.com/2019/06/19/an-in-depth-look-at-sr-iov-nic-passthrough/, Jun. 19, 2019, pp. 1-13. [cited by applicant]
“IPSEC—Internet Protocol Security”, Firewall.cx, Available Online at: http://www.firewall.cx/networking-topics/protocols/127-ip-security-protocol.html, Accessed from Internet on Jan. 27, 2021, 4 pages. [cited by applicant]
“Understanding VPN Ipsec Tunnel Mode and Ipsec Transport Mode—What's the Difference?”, Firewall.cx, Available Online at: http://www.firewall.cx/networking-topics/protocols/870-ipsec modes.html#:˜:text=IPSec%20tunnel%20m… [cited by applicant]
U.S. Appl. No. 17/133,523 , “Corrected Notice of Allowability”, Nov. 6, 2023, 3 pages. [cited by applicant]
U.S. Appl. No. 17/133,523 , “Non-Final Office Action”, Feb. 15, 2023, 27 pages. [cited by applicant]
U.S. Appl. No. 17/133,523 , “Notice of Allowance”, Aug. 8, 2023, 11 pages. [cited by applicant]
U.S. Appl. No. 17/133,526 , “Corrected Notice of Allowability”, Nov. 24, 2023, 2 pages. [cited by applicant]
U.S. Appl. No. 17/133,526 , “Non-Final Office Action”, Feb. 10, 2023, 21 pages. [cited by applicant]
U.S. Appl. No. 17/133,526 , “Notice of Allowance”, Aug. 1, 2023, 13 pages. [cited by applicant]
U.S. Appl. No. 17/133,526 , “Supplemental Notice of Allowability”, Aug. 9, 2023, 2 pages. [cited by applicant]
Deierling , “What Is a SmartNIC”, Mellanox Technologies, Available Online at: https://blog.mellanox.com/2018/08/defining-smartnic/, Accessed from Internet on Jan. 27, 2021, 3 pages. [cited by applicant]
International Application No. PCT/US2021/063714 , “International Preliminary Report on Patentability”, Jul. 6, 2023, 9 pages. [cited by applicant]
International Application No. PCT/US2021/063714 , “International Search Report and Written Opinion”, Apr. 11, 2022, 12 pages. [cited by applicant]
International Application No. PCT/US2021/063715 , “International Preliminary Report on Patentability”, Jul. 6, 2023, 9 pages. [cited by applicant]
International Application No. PCT/US2021/063715 , “International Search Report and Written Opinion”, Apr. 5, 2022, 12 pages. [cited by applicant]
U.S. Appl. No. 18/390,744, Notice of Allowance, mailed on Oct. 8, 2024, 11 pages. [cited by applicant]
Application No. EP21844123.6, Office Action, mailed on Jan. 22, 2025, 6 pages. [cited by applicant]
Application No. EP21844467.7, Office Action, mailed on Jan. 22, 2025, 7 pages. [cited by applicant]
Natarajan et al., “Security Issues in Network Virtualization for the Future Internet”, 2012 International Conference on Computing, Networking and Communications (ICNC), Institute of Electrical and Electronics Engineers,… [cited by applicant]
Application No. JP2023-538778 , Office Action, Mailed on Sep. 16, 2025, 5 pages. [cited by applicant]
Application No. JP2023-538798 , Notice of Decision to Grant, Mailed on Oct. 7, 2025, 3 pages. [cited by applicant]