IP Library › Granted Patent US 12,659,269
Granted Patent B2
US 12,659,269 · App. 18/108,937 · Granted Jun 16, 2026

Multipath network traffic distribution methods for reduced detectability

Inventors: Prithwish Basu (Westford, MA); George Stephen Zabele (North Reading, MA); Gregory S. Lauer (Falmouth, MA); Christophe Jean-Claude Merlin (Wakefield, MA)
Assignee: RTX BBN TECHNOLOGIES, INC.
H04L45/38H04L47/125H04L47/2441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,659,269
App. No.
18/108,937
Granted
Jun 16, 2026
Kind
B2
Abstract

A method of sending a flow of a plurality of data packets across a data network from a source node to a destination node is provided, the data network including a plurality of links between nodes. The method includes: (a) determining a set of weights, the weights corresponding to respective links of the plurality of links, such that obeying the set of weights during data transmission tends to minimize side channel leakage for the flow; and (b) routing packets of the flow along the plurality of links of the data network according to their respective weights. A corresponding apparatus, system, and computer program product are also provided.

Claims (33)

1 . A method of sending a flow of a plurality of data packets across a data network from a source node to a destination node, the data network including a plurality of links between nodes, the method comprising:

determining a set of weights associated with minimizing side channel leakage for the flow of the plurality of data packets across the data network from the source node to the destination node, the weights corresponding to respective links of the plurality of links, such that obeying the set of weights during data transmission minimizes the side channel leakage for the flow; and

routing packets of the flow along the plurality of links of the data network according to their respective weights.

2 . The method of claim 1 wherein determining the set of weights such that obeying the set of weights during data transmission tends to minimize side channel leakage includes utilizing a spreading scheme that spreads traffic across a plurality of diverse paths.

3 . The method of claim 2 wherein utilizing the spreading scheme includes minimizing a maximum load per intermediate node of the data network between the source node and the destination node.

4 . The method of claim 2 wherein utilizing the spreading scheme includes applying a quadratic spreading strategy to achieve maximal spreading across all outgoing links at each node.

5 . The method of claim 1 wherein determining the set of weights includes imposing a Quality of Service (QoS) constraint, including ensuring that a sum of products of a respective cost of traversing each link with the weight for that link over all links of the data network does not exceed the QoS constraint.

6 . The method of claim 5 wherein determining the set of weights further includes ensuring that each weight of the set of weights does not exceed a maximum capacity of the corresponding link.

7 . The method of claim 6 wherein the method further comprises sending another flow of another plurality of data packets across the data network from another source node to another destination node by:

determining another set of weights, the other weights of the other set of weights corresponding to respective links of the plurality of links, such that obeying the other set of weights during data transmission tends to minimize side channel leakage for the other flow, including ensuring that, for each link of the plurality of links, a sum of the corresponding weight and corresponding other weight does not exceed the maximum capacity of that link; and

routing packets of the other flow along the plurality of links of the data network according to their respective other weights.

8 . The method of claim 5 wherein determining the set of weights further includes:

for all untrusted links, setting their respective costs to a maximum value; and

for all links that input into or output from any untrusted node, setting their respective costs to a maximum value.

9 . The method of claim 8 wherein determining the set of weights further includes, in response to determining that ensuring that the sum of products of the respective cost of traversing each link with the weight for that link over all links of the data network does not exceed the QoS constraint is impossible, reducing the costs of one or more links having respective costs set to the maximum value.

10 . The method of claim 1 wherein routing packets of the flow along the plurality of links according to their respective weights includes, at each node of the data network except the destination node, stochastically routing packets of the flow to respective links emanating from that node in proportion to the respective weights of each link emanating from that node.

11 . The method of claim 1 wherein each of the plurality of data packets of the flow is encrypted.

12 . A computer program product comprising a non-transitory computer-readable storage medium storing a set of instructions, which, when executed by processing circuitry of a computing device, causes the computing device to:

send a flow of a plurality of data packets across a data network from a source node to a destination node, the data network including a plurality of links between nodes, by:

determining a set of weights associated with minimizing side channel leakage for the flow of the plurality of data packets across the data network from the source node to the destination node, the weights corresponding to respective links of the plurality of links, such that obeying the set of weights during data transmission minimizes the side channel leakage for the flow; and

routing packets of the flow along the plurality of links of the data network according to their respective weights.

13 . The computer program product of claim 12 wherein determining the set of weights such that obeying the set of weights during data transmission tends to minimize side channel leakage includes utilizing a spreading scheme that spreads traffic across a plurality of diverse paths.

14 . The computer program product of claim 13 wherein utilizing the spreading scheme includes minimizing a maximum load per intermediate node of the data network between the source node and the destination node.

15 . The computer program product of claim 13 wherein utilizing the spreading scheme includes applying a quadratic spreading strategy.

16 . The computer program product of claim 12 wherein determining the set of weights includes imposing a Quality of Service (QoS) constraint, including ensuring that a sum of products of a respective cost of traversing each link with the weight for that link over all links of the data network does not exceed the QoS constraint.

17 . A system comprising:

a plurality of computing nodes, including a source node, a destination node, and a plurality of intermediate nodes; and

a network configured to connect the source node to the destination node via links between the plurality of computing nodes;

wherein the source node is configured to determine a set of weights associated with minimizing side channel leakage for a flow of a plurality of data packets across the network to the destination node, the weights corresponding to respective links of the plurality of links, such that obeying the set of weights during data transmission minimizes the side channel leakage for the flow; and

wherein the source node and the plurality of intermediate nodes are configured to route packets of the flow along the plurality of links of the network according to their respective weights.

18 . The system of claim 17 wherein determining the set of weights such that obeying the set of weights during data transmission tends to minimize side channel leakage includes utilizing a spreading scheme that spreads traffic across a plurality of diverse paths.

19 . The system of claim 17 wherein determining the set of weights includes imposing a Quality of Service (QoS) constraint, including ensuring that a sum of products of a respective cost of traversing each link with the weight for that link over all links of the data network does not exceed the QoS constraint.

20 . The system of claim 17 wherein routing packets of the flow along the plurality of links according to their respective weights by a node includes stochastically routing packets of the flow to respective links emanating from that node in proportion to the respective weights of each link emanating from that node.

Assignments (2)
CHANGE OF NAME Recorded Aug 22, 2024
From: RAYTHEON BBN TECHNOLOGIES CORP.
To: RTX BBN TECHNOLOGIES, INC.
Reel/Frame 068748/0419 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2023
From: BASU, PRITHWISH; ZABELE, GEORGE STEPHEN; LAUER, GREGORY S.; MERLIN, CHRISTOPHE JEAN-CLAUDE
To: RAYTHEON BBN TECHNOLOGIES CORP.
Reel/Frame 062720/0807 →
Continuity (2)
Provisional Application 63309329 · Feb 11, 2022
Related Publication 20230261983A1 · Aug 17, 2023
References Cited (39)
US 6775258B1 · van Valkenburg · 2004 [cited by examiner]
US 8160056B2 · Van Der Merwe · 2012 [cited by examiner]
US 20040190447A1 · Dacosta · 2004 [cited by examiner]
US 20040264372A1 · Huang · 2004 [cited by examiner]
US 20120057456A1 · Bogatin · 2012 [cited by examiner]
US 20180262327A1 · Jain · 2018 [cited by examiner]
US 20200100117A1 · Hassan Hussein · 2020 [cited by examiner]
US 20200359159A1 · Krzych · 2020 [cited by examiner]
US 20230224942A1 · Abotabl · 2023 [cited by examiner]
International Preliminary Report on Patentability; International Application No. PCT/US2023/012813; mailed Aug. 22, 2024; 7 pages. [cited by applicant]
International Search Report and Written Opinion; International Application No. PCT/US2023/012813; International Filing Date Feb. 10, 2023; 7 Pages, Mailing Date May 2, 2023. [cited by applicant]
Draper-Gil, et al., “Characterization of Encrypted and VPN Traffic using Time-related Features”, International Conference on Information Systems Security and Privacy (ICISSP 2016), pp. 407-414. [cited by applicant]
Fortz, et al., “Internet traffic engineering by optimizing OSPF weights”, Proceedings IEEE Infocom, pp. 519-528, Tel Aviv, Israel, 2000. [cited by applicant]
Gallager, “A Minimum Delay Routing Algorithm Using Distributed Computation”, IEEE Transactions on Communications, vol. 25, No. 1, pp. 73-85, Jan. 1977. [cited by applicant]
GEneric COnstraint Development Environment. https://www.gecode.org/. [cited by applicant]
Han, et al., “Multi-path TCP: a joint congestion control and routing scheme to exploit path diversity in the internet”, EEE/ACM Transactions on Networking (TON), vol. 14 , Issue 6, pp. 1260-1271, Dec. 2006. [cited by applicant]
Hopps, “Analysis of an Equal-Cost Multi-Path Algorithm”, RFC 2992 (Informational), Nov. 2000, URL: https://tools.ietf.org/html/ rfc2992. [cited by applicant]
Javed, et al., “Multipath protocol for delay-sensitive traffic”, IEEE COMSNETS, 2009. [cited by applicant]
“Layer 3 VPN Load Balancing Overview,” Juniper Networks, 2017. URL: https://www.juniper.net/documentation/en_US/release-independent/nce/topics/concept/layer-3-vpn-load-balancing-with-ip-header-filtering-overview.html. [cited by applicant]
Kadloor, et al., “Scheduling with privacy constraints,” 2012 IEEE Information Theory Workshop, 2012, pp. 40-44. [cited by applicant]
Kleinberg, “Approximation Algorithms for Disjoint Paths Problems”, PhD thesis, Massachusetts Institute of Technology, 1996. [cited by applicant]
Kozlov, et al., “The Polynomial Solvability of Convex Quadratic Programming”, U.S.S.R. Comput. Maths. Math. Physics, 1981, pp. 223-228, vol. 20, No. 5, Pergamon Press Ltd., Great Britain. [cited by applicant]
C. Liu, et al., “Cologne: a declarative distributed constraint optimization platform”, Proc. VLDB Endowment, Apr. 2012, pp. 752-763, vol. 5, No. 8. [cited by applicant]
Q. Liu, et al., “On the min-max-delay problem: NP-completeness, algorithm, and integrality gap”, IEEE Information Theory Workshop (ITW), Kaohsiung, 2017. [cited by applicant]
Merlin, et al., “Latency-Aware Forwarding for IRON: Latency Support for Back-Pressure Forwarding”, IEEE Milcom 2018, pp. 474-479, Los Angeles, CA. [cited by applicant]
Mirhakkak, et al., “Modeling and Simulation of Haipe”, MILCOM 2006—2006 IEEE Military Communications conference, 2006. [cited by applicant]
Neely, et al., “Optimal Backpressure Routing in Wireless Networks with Multi-Receiver Diversity”, Ad Hoc Networks, 2009, pp. 862-881, vol. 7, No. 5, Elsevier. [cited by applicant]
“Network Functions Virtualization—Introductory White Paper”, ETSI., Oct. 2012, accessed from <https://portal.etsi.org/NFV/NFV_White_Paper.pdf>. [cited by applicant]
Oliveira, et al., “Coding for Trusted Storage in Untrusted Networks”, IEEE Transactions on Information Forensics and Security, Dec. 2012, pp. 1890-1899, vol. 7, No. 6. [cited by applicant]
Stellato, et al., “OSQP: An Operator Splitting Solver for Quadratic Programs.”. [cited by applicant]
Perlman, “Routing with Byzantine Robustness”, Sun Microsystems Technical Report, Sep. 2005, Menlo Park, CA. [cited by applicant]
Ristenpart, et al., “Hey, you, get off of my cloud: exploring information leakage in third-party compute clouds”, ACM CCS, 2009. [cited by applicant]
Rosner, et al., “Profit: Detecting and Quantifying Side Channels in Networked Applications”, Network and Distributed System Security (NDSS) Symposium, 2019. [cited by applicant]
Torrieri, Principles of Spread-Spectrum Communication Systems, 4th ed._abstract. [cited by applicant]
Yan, et al., “Low Probability of Detection Communication: Opportunities and Challenges,” in IEEE Wireless Communications, Oct. 2019, pp. 19-25, vol. 26, No. 5. [cited by applicant]
Zhang, et al., “Cross-Tenant Side-Channel Attacks in PaaS Clouds”, ACM CCS, 2014, pp. 990-1003. [cited by applicant]
Ye et al. “Side Channel Leakage Analysis—Detection, Exploitation and Quantification” PhD Dissertation, Worcester Polytechnic Institute, Dec. 2014. [cited by applicant]
Lou et al., “Spread: Improving Network Security By Multipath Routing,” IEEE Military Communications Conference, 2003. MILCOM 2003, pp. 808-813 vol. 2, Boston, MA. [cited by applicant]
Yang et al., “Improving Network Security by Multipath Traffic Dispersion”, 2001 MILCOM Proceedings Communications for Network-Centric Operations: Creating the Information Force, pp. 34-38, vol. 1, IEEE, McLean, VA. [cited by applicant]