IP Library Granted Patent US 12,732,489
Granted Patent B1
US 12,732,489 · App. 18/797,911 · Granted Sep 8, 2026

Protocol free encrypting device

Inventors: Joshua E. Cline (Edgewater, MD); Dan A. DeVries (Brooklyn, MD); William J. Layton (Sykesville, MD); Zachary Smith (Severn, MD); Brendan S. Surrusco (Highland, MD); Andrew H. White (Catonsville, MD); David F. Wiecek (Ft. George G. Meade, MD); Mitchell E. Buchman (Hanover, MD)
Assignee: The Government of the United States as represented by the Director, National Security Agency
H04L63/0471G06F21/602H04L45/74H04L63/0272H04W28/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,489
App. No.
18/797,911
Granted
Sep 8, 2026
Kind
B1
Abstract

The present invention provides an encrypting device including an encryption unit and a communications unit. Paired encrypting devices allow for communication of trusted data between trusted devices over an untrusted network. Data received by the encryption unit is encrypted and provided with a connectionless header for delivery to the communications unit. Data received by the communications units is provided with a complex header for delivery to the paired encrypting device. The encrypting devices may be implemented in hardware or may be virtualized on a server or a plurality of severs. Arrangement of the encrypting devices in a hub-and-spoke topology allows for communication amongst a plurality of trusted devices. The encrypting devices can be used to covert commercially available equipment suitable for high assurance environments.

Claims (42)

1 . A cryptographic system comprising:

a first cryptographic device including a first communications unit with a first addressable interface paired to a second communications unit of a second cryptographic device and a first cryptographic engine coupled to the first communications unit via a first connectionless interconnect and a first trusted element; and

the second cryptographic device including the second communications unit with a second addressable interface paired to the first communications unit of the first cryptographic device and a second cryptographic engine coupled to the second communications unit via a second connectionless interconnect and a second trusted element, wherein the first and second cryptographic engines use a shared key, and wherein the pairing between the first communications unit of the first cryptographic device and the second communications unit of the second cryptographic device provides an encrypted tunnel across an untrusted network for the first and second trusted elements,

wherein communications within the first and second cryptographic devices are connectionless, and wherein communications between the first and second cryptographic devices across the untrusted network are connection-oriented.

2 . The cryptographic system of claim 1 , wherein the first cryptographic engine of the first cryptographic device and the second cryptographic engine of the second cryptographic are configured to transmit encrypted inter-cryptographic device control messages to change the shared key, manage a cryptographic algorithm associated with the shared key, manage sessions, and manage status of the first and second cryptographic engines.

3 . The cryptographic system of claim 1 , wherein the first cryptographic engine is coupled to the first trusted element via a first trusted interconnect, and wherein the second cryptographic engine is coupled to the second trusted element via a second trusted interconnect.

4 . The cryptographic system of claim 1 , wherein the first and second cryptographic devices correspond to hardware devices.

5 . The cryptographic system of claim 1 , wherein one of the first and second cryptographic devices corresponds to a virtualized device hosted on one or more severs.

6 . The cryptographic system of claim 1 , wherein the first cryptographic device corresponds to a first virtualized device hosted by a first set of one or more severs, and wherein the second cryptographic device corresponds to a second virtualized device hosted by a second set of one or more severs.

7 . The cryptographic system of claim 1 , wherein the first trusted element includes a first plurality trusted elements, wherein the first cryptographic device further includes a first trusted mapping server for mapping native packets from the first plurality of trusted elements to the first cryptographic engine and for mapping native packets from the first cryptographic engine to the first plurality of trusted elements, and wherein the first passive interface of the cryptographic engine is coupled to the first trusted mapping server via a connectionless interconnect.

8 . A first cryptographic device for enabling communication of trusted data between trusted elements over an untrusted network, the first cryptographic device comprising:

a first cryptographic engine, including a first passive interface for communicating with a first trusted element among the trusted elements and a second passive interface for communicating with a first communications unit, wherein the first cryptographic engine is configured to at least one of encrypt or decrypt native packets from the trusted elements with a shared key; and

the first communications unit, including a first passive interface for connectionless communication with the first cryptographic engine and a second addressable interface for connection-oriented communication with a second communications unit of a second cryptographic device that is paired to the first cryptographic device, wherein the first communications unit further includes at least one of an untrusted device interface for communicating with an untrusted device and a storage interface for communicating with a storage device.

9 . The first cryptographic device of claim 8 , further comprising:

a second cryptographic engine, including a first passive interface coupled to the second passive interface of the first cryptographic engine and a second passive interface coupled to the first passive interface of the first communications unit, wherein the second cryptographic engine is configured to at least one of encrypt or decrypt native packets from the trusted elements with a second shared key different from the shared key.

10 . The first cryptographic device of claim 9 , wherein the first cryptographic engine is configured to transmit intra-cryptographic device control messages to the second cryptographic engine to manage the second shared key, start the second cryptographic engine, stop the second cryptographic engine, restart the second cryptographic engine, and install new software on the second cryptographic engine.

11 . The first cryptographic device of claim 8 , wherein the first cryptographic engine includes a one-way interface for communicating instructions to the first communications unit, and wherein the first communications unit includes a one-way interface for receiving instructions from the first cryptographic engine.

12 . The first cryptographic device of claim 8 , wherein the first cryptographic device corresponds to a hardware device.

13 . The first cryptographic device of claim 8 , wherein the first cryptographic device corresponds to a virtualized device hosted on one or more severs.

14 . A method comprising:

at a first encrypting device including an encryption unit with first and second passive interfaces, a first communications unit with a first passive interface and a second addressable interface, and a connectionless interconnect that couples the second passive interface of the encryption unit to the first passive interface of the first communications unit:

obtaining a native packet from a trusted element at the first passive network interface of the encryption unit;

encrypting, via the encryption unit, the native packet using a shared encryption key;

adding, via the encryption unit, a connectionless header to the encrypted native packet to form an outgoing connectionless datagram;

sending, via the second passive interface of the encryption unit, the outgoing connectionless datagram to the first communications unit;

obtaining the outgoing connectionless datagram at the first passive interface of the first communications unit;

adding, via the first communications unit, a complex header to form a packet for delivery to a second communications unit of a second encrypting device, wherein the first communications unit of the first encrypting device is paired with the second communications unit of the second encrypting device; and

sending, via the second addressable interface of the first communications unit, the packet to the second communications unit of the second encrypting device.

15 . The method of claim 14 , further comprising:

obtaining an incoming packet including an encrypted native packet and a complex header from the second communications unit of the second encrypting device at the second addressable interface of the first communications unit;

removing, via the first communications unit, the complex header from the incoming packet;

adding, via the first communications unit, the connectionless header to form an incoming connectionless datagram including the encrypted native packet;

sending, via the first passive interface of the first communications unit, the incoming connectionless datagram including the encrypted native packet to the encryption device;

obtaining the incoming connectionless datagram including the encrypted native packet at the second passive network interface of the encryption unit; and

decrypting, via the encryption unit, the encrypted native packet using the shared encryption key.

16 . The method of claim 15 , further comprising:

sending, via the first passive interface of the encryption unit, the decrypted native packet to the trusted element.

17 . The method of claim 15 , further comprising:

dropping the encrypted native packet in response to failing to decrypt the encrypted native packet by the encryption unit.

18 . The method of claim 14 , wherein the first encrypting device further includes a trusted interconnect that couples the first passive interface of the encryption unit to the trusted element.

19 . The method of claim 14 , wherein the first and second passive interfaces of the encryption unit and the first passive interface of the first communications unit are promiscuous interfaces that are not associated with an address.

20 . The method of claim 14 , wherein the packet is sent to the second communications unit of the second encrypting device across an untrusted network, and wherein the pairing between the first communications unit of the first encrypting device and the second communications unit of the second encrypting device provides a tunnel across the untrusted network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2026
From: CLINE, JOSHUA E.; DEVRIES, DAN A.; LAYTON, WILLIAM J.; SMITH, ZACHARY; SURRUSCO, BRENDAN S.; WHITE, ANDREW H.; WIECEK, DAVID F.; BUCHMAN, MITCHELL E.
To: THE GOVERNMENT OF THE UNITED STATES AS REPRESENTED BY THE DIRECTOR, NATIONAL SECURITY AGENCY
Reel/Frame 075208/0220 →
Continuity (3)
Continuation 18100312 · Jan 23, 2023
Continuation 17200468 · Mar 12, 2021
Provisional Application 62988484 · Mar 12, 2020
References Cited (11)
US 6253321B1 · Nikander et al. · 2001 [cited by applicant]
US 6922774B2 · Meushaw et al. · 2005 [cited by applicant]
US 7712143B2 · Comlekoglu · 2010 [cited by applicant]
US 7809955B2 · Comlekoglu · 2010 [cited by applicant]
US 10630467B1 · Gilbert et al. · 2020 [cited by applicant]
US 11095610B2 · Gilbert et al. · 2021 [cited by applicant]
US 11689359B2 · Gilbert et al. · 2023 [cited by applicant]
US 20120201383A1 · Matsuo · 2012 [cited by examiner]
US 20170006034A1 · Link, II · 2017 [cited by examiner]
US 20190227827A1 · Zmudzinski · 2019 [cited by examiner]
US 20210243020A1 · Mukherjee · 2021 [cited by examiner]