Packet Orchestration for IP-Layer Encryption Without Hardware Encryptors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The rapid increase in network data production, particularly from the Internet of Things, poses significant challenges for secure transport and storage, as existing technologies struggle to efficiently encrypt and decrypt high volumes of network data without specialized hardware, leading to increased costs and administrative burdens.

Innovation Solution

A software-based packet orchestration method utilizing a quantum secure pre-shared key derivation scheme and data link layer encryption, combined with CPU core affinity and NIC offloading, to provide low-cost, high-performance encryption at the IP layer, leveraging off-the-shelf components like standard CPUs and NICs, without the need for specialized hardware encryptors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized hardware encryptors are used to encrypt high volumes of network data, then encryption security is improved, but device complexity and cost increase

Engineering Contradiction:
Improveencryption securityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces specialized hardware encryption devices with software-based encryption implemented on general-purpose CPUs. The encryption function is migrated from dedicated hardware to software routines that can execute on standard processors, eliminating the need for complex hardware encryptors while maintaining security through algorithmic encryption at the data link layer.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent enables general-purpose CPUs to perform encryption functions that were previously reserved for specialized hardware devices. By implementing encryption software on standard processors, the system achieves multi-functionality where ordinary CPUs can handle both general computing tasks and security-critical encryption operations, reducing the need for dedicated hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Device complexity

If software-based encryption is used instead of specialized hardware, then device complexity is reduced, but processing speed may deteriorate

Engineering Contradiction:
Improvehardware complexityVSAvoidencryption speed
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent divides the encryption processing workload across multiple CPU cores, with each core handling encryption for specific network bridges or segments. This segmentation allows parallel processing of encryption operations, maintaining high throughput while using software-based implementation on general-purpose hardware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a packet orchestration layer that acts as an intermediary between network traffic and encryption operations. This orchestration layer manages the flow of packets through the encryption process, optimizing CPU utilization and ensuring that software-based encryption maintains wire-speed performance through efficient packet handling and processing pipelines.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If encryption is implemented at the IP layer using data link layer schemes, then ease of operation is improved, but manufacturing precision requirements increase

Engineering Contradiction:
Improveencryption implementation easeVSAvoidconfiguration precision
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent implements automated key management and configuration mechanisms where the encryption system self-configures through pre-shared key derivation schemes. The system automatically establishes secure communication channels and manages cryptographic parameters without requiring manual configuration, reducing operational complexity while maintaining precise cryptographic implementation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12452057B2Methods and systems of a packet orchestration to provide data encryption at the IP layer, utilizing a data link layer encryption scheme
Publication Date: 2025.10.21 FRANKLIN KELVIN R
  • US12452057B2 patent drawing
  • US12452057B2 patent drawing
  • US12452057B2 patent drawing

AI summary

In one aspect, a method for packet orchestration to provide data encryption at the internet protocol (IP) layer, includes the step of providing a quantum secure pre-shared key derivation scheme for a data link layer bulk encryption algorithm, meaning the ability to setup a separate communication channel, via the SSH protocol, and leverage ECDH over said channel to share pre-shared keys. The method includes the step of providing a set of software-based network bridges. The method includes the step of assigning a set of network ports to specific bridges, wherein the set of network ports implement segmentation and isolation based on an organizational policy.