A system for quantum-safe routing via dynamic crypto-switching in the WAN / SD-WAN
Patent Information
- Application Number
- DE202025102839
- Authority / Receiving Office
- DE · DE
- Patent Type
- Utility models
- Current Assignee / Owner
- Filing Date
- 2025-05-22
- Publication Date
- 2025-09-04
- Estimated Expiration
- 2035-05-31
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to the field of secure network communications, in particular to wide area networks (WANs) and software-defined wide area networks (SD-WANs). It relates to quantum-resistant data routing mechanisms that adaptively switch cryptographic protocols based on threat intelligence and network conditions. This invention ensures end-to-end data protection against both classical and quantum-based cyber threats.
[0002] In recent years, the rapid development of quantum computing has posed a significant threat to traditional cryptographic algorithms widely used in WAN and SD-WAN environments. Protocols such as RSA and ECC, which form the basis of current secure communications, are vulnerable to quantum attacks such as the Shor algorithm. This looming threat necessitates the development of quantum-resistant solutions that can protect sensitive data during transmission across geographically distributed enterprise networks.
[0003] Furthermore, modern WAN / SD-WAN infrastructures operate in highly dynamic environments where the threat landscape is rapidly evolving. Static cryptographic configurations are unable to handle security fluctuations in real time, leaving networks vulnerable to security breaches and data leaks. Current solutions lack the intelligence and flexibility to assess the threat landscape and migrate to more secure algorithms or protocols without interrupting ongoing communications or impacting performance.
[0004] To address these challenges, there is a critical need for a system that enables dynamic switching between classical and quantum-resistant cryptographic methods based on real-time threat analytics and network performance metrics. Such a solution must integrate seamlessly with existing SD-WAN frameworks and enable adaptive end-to-end encryption without manual intervention. The proposed invention closes this gap by introducing an intelligent routing mechanism that enables quantum-resistant cryptographic switching, thus future-proofing network security while maintaining high availability and low latency.
[0005] One goal of this disclosure is to enable a seamless transition between classical and post-quantum crypto algorithms.
[0006] Another goal of this disclosure is to protect WAN / SD-WAN communications from current and future quantum threats.
[0007] Another objective of this disclosure is to automate cryptographic decisions based on real-time threat intelligence.
[0008] Another goal of this disclosure is to maintain uninterrupted secure sessions during cryptographic transitions.
[0009] Another objective of this disclosure is to support policy-based encryption control for regulatory and performance requirements.
[0010] Another objective of the present disclosure is to provide adaptive, secure routing that is optimized for both speed and resiliency.
[0011] Another objective of this disclosure is to ensure interoperability between legacy and quantum security network components.
[0012] Another objective of this disclosure is to provide real-time audit trails and compliance reporting for corporate security.
[0013] The present invention relates to a system that proactively secures WAN / SD-WAN communications using quantum-resistant cryptographic algorithms. It dynamically switches between classical and post-quantum encryption depending on evolving threat conditions. This ensures future-proof security against both current and emerging quantum attacks.
[0014] Another embodiment of the present invention is the real-time threat intelligence module, which continuously analyzes cybersecurity risks, cryptographic vulnerabilities, and external threat data. This enables the system to assess when traditional encryption is insufficient. It forms the core of the decision-making process for initiating crypto transitions.
[0015] Another embodiment of the present invention is the Dynamic Crypto Switching Engine, which ensures automatic and seamless cryptographic reconfiguration. It switches active sessions without interruption and maintains secure connections while changing encryption algorithms. This supports continuous uptime and zero-trust security principles.
[0016] Another embodiment of the present invention allows administrators to define policies for cryptographic transitions based on compliance, performance, geographic, or risk thresholds. The SD-WAN orchestration module automatically enforces these policies, enabling enterprise-wide control with minimal manual oversight.
[0017] Another embodiment of the present invention is for the routing module to dynamically select network paths based on both performance metrics and security posture. It favors routes that provide the highest level of cryptographic resilience. This ensures both the efficiency and protection of real-time data streams.
[0018] Another embodiment of the present invention, the compatibility layer, enables the coexistence of legacy and modern systems by allowing protocol negotiation and fallback. It ensures encryption interoperability between nodes using different cryptographic standards.
[0019] This supports the gradual, non-disruptive introduction of quantum-safe technology.
[0020] Another embodiment of the present invention is that the system has an integrated dashboard for compliance monitoring, threat logging, and cryptographic toggles recording. It supports audits and reports compliant with standards such as NIST PQC and ISO 27001. This ensures transparency, accountability, and compliance readiness.
[0021] Another embodiment of the present invention is the system designed for enterprise-class WAN / SD-WAN environments, which is modular, scalable, and vendor-independent. It adapts autonomously to threats and network changes without human intervention, making it suitable for large-scale, mission-critical deployments.
[0022] The present invention relates to a quantum-resistant routing system for WAN / SD-WAN that dynamically switches between classical and post-quantum crypto protocols based on real-time threat data. It comprises six key modules: a Threat Intelligence and Crypto-Resilience Assessment Module for continuous risk assessment, a Dynamic Crypto Switching Module for seamless encryption transitions, and an SD-WAN Policy Integration Module for security policy enforcement. Furthermore, an Adaptive Routing Module ensures secure path selection, while a Compatibility Layer manages interoperability between legacy and quantum-safe systems. Finally, an audit and analytics dashboard provides complete visibility and compliance reporting across the entire cryptographic lifecycle. Threat Intelligence and Crypto Resilience Assessment Module:
[0023] This module continuously monitors the threat landscape using real-time threat intelligence, vulnerability databases, and predictive analytics. It assesses the cryptographic risks associated with current and emerging threats, including quantum-enabled attackers. Based on these assessments, the module dynamically evaluates each connection or data flow based on its exposure to cryptographic vulnerabilities. Thanks to this real-time analysis, the system can decide when to transition from traditional to quantum-resistant cryptographic protocols to ensure proactive network security. Dynamic crypto switching module:
[0024] At the core of the invention, this module is responsible for dynamically switching between classical (e.g., RSA, ECC) and post-quantum crypto protocols (e.g., lattice-based, hash-based encryption) without interrupting ongoing communication sessions. It interfaces with the routing and session management layers to negotiate and enforce the selected cryptographic method in real time. The engine supports key flexibility and cryptographic renegotiation to ensure secure and seamless transitions between algorithms triggered by threat data or policy thresholds. SD-WAN policy integration and orchestration module:
[0025] This module ensures that the cryptographic switching logic is fully integrated into the SD-WAN controller's orchestration policies. It enables administrators to define security, performance, and compliance policies that trigger cryptographic transitions based on criteria such as link security, geographic region, regulatory requirements, or detected threat severity. This tight integration ensures that quantum-resistant routing decisions are policy-driven, automated, and tailored to the organization's specific needs. Adaptive routing and path selection module:
[0026] This module leverages secure multipath routing and real-time path analysis to select routes that optimize both performance and security. It considers the results of the Threat Intelligence module and the Crypto Switching Engine to make routing decisions that favor quantum-resistant paths in high-risk scenarios. It also ensures that secure tunnels (e.g., IPSec, TLS) are established using the currently active cryptographic protocols and redirects traffic as needed to maintain cryptographic integrity and performance. Cryptographic compatibility and interoperability layer:
[0027] This layer ensures compatibility between different cryptographic protocols across different network devices, vendors, and endpoints. It handles protocol translation, handshake negotiations, and fallback mechanisms if a node does not support post-quantum algorithms. This module enables the gradual introduction and coexistence of classical and quantum-safe technologies across the entire enterprise WAN and minimizes disruption during the transition to a quantum-resistant infrastructure. Audit, compliance and analytics dashboard:
[0028] To ensure transparency and accountability, this module provides real-time logging, analytics, and visual dashboards that track cryptographic states, switching operations, threat assessments, and routing decisions. It supports forensic analysis and compliance audits by maintaining immutable logs of all cryptographic transitions and their justifications. Administrators can generate reports to demonstrate compliance with quantum readiness mandates and cybersecurity frameworks such as NIST Post-Quantum Standards or ISO / IEC 27001.
[0029] The invention is explained again below with reference to the figure. It shows: Fig. a system (100) for quantum-resilient routing via dynamic crypto-switching in the WAN / SD-WAN.
[0030] Fig.illustrates a system (100) for quantum-resilient routing via dynamic crypto-switching in the WAN / SD-WAN. The system for quantum-resilient routing via dynamic crypto-switching in the WAN / SD-WAN begins with the Threat Intelligence and Crypto-Resilience Assessment Module, which continuously ingests and analyzes real-time threat data to assess the security posture of network paths and the cryptographic algorithms used. Based on this analysis, it triggers the Dynamic Crypto Switching Module, which seamlessly switches communication channels between classic and post-quantum crypto protocols without interrupting active sessions. This engine works closely with the SD-WAN Policy Integration and Orchestration Module, which enforces predefined corporate policies, such as regulatory compliance or minimum security thresholds, to determine when and how cryptographic transitions occur.At the same time, the adaptive routing and path selection module evaluates available network paths and reroutes traffic over routes that provide optimal security and performance, ensuring that encrypted tunnels are reestablished using the most robust cryptographic standards available. To ensure interoperability between heterogeneous network devices, the cryptographic compatibility and interoperability layer manages protocol negotiations and fallback procedures, allowing classical and quantum-resistant systems to coexist in the same environment. Finally, all actions and transitions are logged and visualized via the Audit, Compliance, and Analytics dashboard, which provides administrators with real-time insights, historical data, and audit logs required for compliance reporting and proactive cybersecurity management.This coordinated operation across all modules enables the system to provide intelligent, adaptable, and future-proof security in modern WAN / SD-WAN implementations.
Claims
[1] A system (100) for quantum-resistant routing via dynamic cryptographic switching in a WAN or SD-WAN environment, the system comprising: (a) a threat intelligence and crypto resilience assessment module configured to monitor cyber threats in real time and assess the security level of active cryptographic protocols; (b) a Dynamic Crypto Switching Module operatively connected to the assessment module and configured to automatically switch between classical cryptographic algorithms and post-quantum cryptographic algorithms based on the assessed threat levels; c) an SD-WAN policy integration and orchestration module configured to enforce organizational policies related to security, compliance, and performance to control cryptographic transitions; (d) an adaptive routing and path selection module configured to select network paths based on real-time security assessments and cryptographic strength; (e) a cryptographic compatibility and interoperability layer configured to manage encryption protocol handshakes and fallback mechanisms and to support communication between classical and post-quantum-enabled endpoints; f) and an audit, compliance and analytics dashboard configured to log cryptographic transitions, generate compliance reports and provide real-time visibility into system operations; g) whereby the system dynamically adapts encryption protocols and routing paths in response to evolving quantum and classical cybersecurity threats, thereby ensuring secure, continuous and compliant data transmission over WAN or SD-WAN networks. [2] The system (100) of claim 1, wherein the threat intelligence and crypto resilience assessment module uses artificial intelligence or machine learning to predict potential cryptographic vulnerabilities based on historical attack patterns and anomaly detection. [3] The system (100) of claim 1, wherein the Dynamic Crypto Switching Engine supports key agility and session recovery without requiring end-user intervention or session termination. [4] The system (100) of claim 1, wherein the SD-WAN policy integration and orchestration module enables custom policy templates to trigger crypto switching based on geographic regions, regulatory requirements, or network performance metrics. [5] The system (100) of claim 1, wherein the adaptive routing and path selection module employs multipath routing algorithms to ensure continuous connectivity even during cryptographic reconfiguration events. [6] The system (100) of claim 1, wherein the cryptographic compatibility and interoperability layer supports protocol bridging between hybrid infrastructures with legacy devices and quantum-safe devices. [7] The system (100) of claim 1, wherein the audit, compliance, and analytics dashboard provides role-based access control to ensure that only authorized users can view or modify compliance and cryptographic reports. [8] The system (100) of claim 1, wherein the cryptographic transition logic includes a risk threshold comparator that initiates an algorithm switch only when the assessed risk exceeds a dynamically adjustable threat tolerance level.
Citation Information
Cited By
Communication method based on anti-quantum key encapsulation algorithm
CN121727721A