US2023133729A1PendingUtilityA1

Security for communication protocols

Assignee: NOKIA SOLUTIONS & NETWORKS OYPriority: Oct 29, 2021Filed: Oct 29, 2021Published: May 4, 2023
Est. expiryOct 29, 2041(~15.2 yrs left)· nominal 20-yr term from priority
H04L 45/50H04L 45/66H04L 63/0428H04W 12/03H04W 12/06H04L 63/08H04L 45/42H04L 2101/622H04L 63/166H04L 61/6022
55
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Various example embodiments for supporting security for communications may be configured to support security for communications of communication protocols at various communication layers. For example, various example embodiments for supporting security for communications may be configured to support security for communications of communication protocols operating above Layer 2 using a Layer 2 network security protocol. For example, various example embodiments for supporting security for communications may be configured to support security for communications of communication protocols operating at Layer 2.5 (e.g., Multiprotocol Label Switching (MPLS) protocols or other Layer 2.5 protocols) using a Layer 2 network security protocol. For example, various example embodiments for supporting security for communications may be configured to support security for communications of communication protocols operating at Layer 3 (e.g., Internet Protocol (IP), such as IP version 4 (IPv4) or IP version 6 (IPv6), or other Layer 3 protocols) using a Layer 2 network security protocol.

Claims

exact text as granted — not AI-modified
1 - 35 . (canceled) 
     
     
         36 . An apparatus, comprising:
 at least one processor; and   at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least:
 support communication of a packet, wherein the packet includes a payload, a header of a first communication protocol at a first communication layer, and a header of a second communication protocol at a second communication layer above the first communication layer, wherein the second communication protocol is a Layer 3 protocol, wherein the packet includes a header of a third communication protocol at a third communication layer, wherein the packet includes a header of a fourth communication protocol at the first communication layer; 
 wherein a first portion of the packet, including the payload, is encrypted based on the first communication protocol; 
 wherein a second portion of the packet, including the payload and the header of the first communication protocol, is authenticated based on the first communication protocol; 
 wherein a third portion of the packet, including the header of the second communication protocol, remains unencrypted based on the first communication protocol and unauthenticated based on the first communication protocol. 
   
     
     
         37 . The apparatus of  claim 36 , wherein the first communication layer is at Layer 2. 
     
     
         38 . The apparatus of  claim 36 , wherein the first communication protocol is a network security protocol configured to support encryption functions and authentication functions. 
     
     
         39 . The apparatus of  claim 38 , wherein the network security protocol supports features of an IEEE 802.1AE protocol. 
     
     
         40 - 50 . (canceled) 
     
     
         51 . The apparatus of  claim 36 , wherein the second communication protocol supports features of Internet Protocol (IP). 
     
     
         52 - 56 . (canceled) 
     
     
         57 . The apparatus of  claim 36 , wherein the third communication layer is at Layer 2.5 and the third communication protocol is a Layer 2.5 protocol. 
     
     
         58 . The apparatus of  claim 57 , wherein the third communication protocol supports features of Multiprotocol Label Switching (MPLS). 
     
     
         59 . The apparatus of  claim 36 , wherein the header of the third communication protocol is included in the third portion of the packet. 
     
     
         60 . (canceled) 
     
     
         61 . The apparatus of  claim 36 , wherein the header of the fourth communication protocol is included in the third portion of the packet. 
     
     
         62 . The apparatus of  claim 36 , wherein the fourth communication protocol supports features of Ethernet. 
     
     
         63 . The apparatus of  claim 62 , wherein the header of the fourth communication protocol includes at least one of source and destination Media Access Control (MAC) addresses or at least one Ethernet related tag. 
     
     
         64 . The apparatus of  claim 36 , wherein the first portion of the packet, the second portion of the packet, and the third portion of the packet are identified based on an encryption offset associated with the packet and an authentication offset associated with the packet. 
     
     
         65 . The apparatus of  claim 36 , wherein, to support communication of the packet, the instructions, when executed by the at least one processor, cause the apparatus to at least:
 perform, by an encrypting node, encryption of the first portion of the packet and authentication over the second portion of the packet; and   send, by the encrypting node toward a destination node, the packet.   
     
     
         66 . The apparatus of  claim 36 , wherein, to support communication of the packet, the instructions, when executed by the at least one processor, cause the apparatus to at least:
 receive, by a node, the packet; and   determine, by the node based on the third portion of the packet, handling of the packet at the node.   
     
     
         67 . The apparatus of  claim 66 , wherein, to support communication of the packet, the instructions, when executed by the at least one processor, cause the apparatus to at least:
 modify, by the node, at least one aspect of the third portion of the packet to form a modified packet; and   send, by the node, toward a destination node, the modified packet.   
     
     
         68 . The apparatus of  claim 36 , wherein, to support communication of the packet, the instructions, when executed by the at least one processor, cause the apparatus to at least:
 receive, by a decrypting node, the packet; and   perform, by the decrypting node, authentication over the second portion of the packet and decryption of the first portion of the packet.   
     
     
         69 . A non-transitory computer-readable medium comprising program instructions that, when executed by an apparatus, cause the apparatus at least to:
 support communication of a packet, wherein the packet includes a payload, a header of a first communication protocol at a first communication layer, and a header of a second communication protocol at a second communication layer above the first communication layer, wherein the second communication protocol is a Layer 3 protocol, wherein the packet includes a header of a third communication protocol at a third communication layer, wherein the packet includes a header of a fourth communication protocol at the first communication layer;   wherein a first portion of the packet, including the payload, is encrypted based on the first communication protocol;   wherein a second portion of the packet, including the payload and the header of the first communication protocol, is authenticated based on the first communication protocol;   wherein a third portion of the packet, including the header of the second communication protocol, remains unencrypted based on the first communication protocol and unauthenticated based on the first communication protocol.   
     
     
         70 . A method, comprising:
 supporting communication of a packet, wherein the packet includes a payload, a header of a first communication protocol at a first communication layer, and a header of a second communication protocol at a second communication layer above the first communication layer, wherein the second communication protocol is a Layer 3 protocol, wherein the packet includes a header of a third communication protocol at a third communication layer, wherein the packet includes a header of a fourth communication protocol at the first communication layer;   wherein a first portion of the packet, including the payload, is encrypted based on the first communication protocol;   wherein a second portion of the packet, including the payload and the header of the first communication protocol, is authenticated based on the first communication protocol;   wherein a third portion of the packet, including the header of the second communication protocol, remains unencrypted based on the first communication protocol and unauthenticated based on the first communication protocol.

Join the waitlist — get patent alerts

Track US2023133729A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.