Patent pending · Priority: May 2026

Cross-Layer Stitch

Zero‑overhead synchronization. A cross-level parameter that is never transmitted.
See CLS in action

CLS (Cross-Layer Stitch) technology allows two network nodes to obtain the same cross-layer parameter value on two network nodes that have established a transport connection — without transmission over the network and without prior agreement.

This parameter is tightly bound to the transport session, is cryptographically secure, and is unique to each connection. The technology used to obtain it does not introduce detectable anomalies into network traffic. This allows this parameter to be used as control information for synchronizing the behavior of nodes establishing a connection, as well as converting its value into derived values for use in various network connection subsystems.

Технология CLS (Cross-Layer Stitch) позволяет двум узлам сети получить одинаковое значение кросс-уровневого параметра на двух узлах сети, установивших транспортное соединение — без передачи по сети и без предварительного согласования .

Why CLS changes the game

Cross‑layer binding
Derived from L4 + L5+, tied to exact connection.
Never transmitted
Exists only on endpoints — DPI/ML never see it.
Session‑unique & PFS
Each session creates distinct CLS, compromising one does not affect others.

Applications of CLS and its derived values

VPN / Obfuscated tunnels

Encryption keys, obfuscation parameters (H1/S1/Jc) derived from CLS. No sync over wire, invisible to DPI/ML.

IIoT & URLLC

Device auth keys, replay counters, QoS parameters derived from CLS. Synchronisation without signalling.

6G / Zero‑Trust

Implicit authentication, session keys, priority tags derived from CLS. Zero‑overhead for massive MIMO.

API security / anti‑fraud

HMAC keys for requests, dynamic tokens derived from CLS. Keys never transmitted.

Passwordless auth

Time‑based tokens derived from CLS. No password transfer, replay protection.

Distributed systems / DRM

RNG seeds, stream keys derived from CLS. Replica synchronisation without extra round trips.

Multiplexed streams (QUIC/MPTCP)

Per‑stream derived keys from single CLS + Stream ID. Isolation, no per‑stream handshake.

Cryptocurrencies / Blockchain

Per‑transaction signature keys derived from CLS, wallet authentication without private key exchange, protection against transaction replay across forks.

UAV swarms / telemetry

Command authentication, rolling counters derived from CLS. Resilient to MITM/replay.

Cryptographic properties

No secret transmission

CLS never leaves the endpoints; cannot be intercepted in transit.

PFS & session binding

Unique per session, compromise of one session does not affect others.

KDF scalability

Infinite isolated derived keys (HKDF) without extra transmissions.

Post‑quantum ready

The employed one-way mathematical functions remain secure against quantum attacks. For full post‑quantum protection it is enough to replace this functions with a quantum‑safe functions — the core CLS method stays unchanged.

Who will benefit

Telecom & network equipment vendors

Integrate CLS into 6G, URLLC, IIoT stacks.

VPN / cybersecurity companies

Build unblockable, DPI‑resistant tunnels with zero‑overhead sync.

Blockchain / crypto exchanges

Prevent transaction replay, strengthen wallet authentication.

IIoT & industrial automation

Zero‑overhead security for sensors, actuators, real‑time control.

UAV / robotics developers

Lightweight command authentication, replay protection.

Patent pools & licensors

Acquire or sublicense the pending CLS patent family.

Banks, financial services

Strengthen API security, prevent replay attacks, implicit session binding.

Defense & government, state services

Hidden synchronisation, zero‑overhead authentication for classified / tactical networks.

Enterprises of critical infrastructure

Implicit authentication, resistance to MITM / DPI for sensitive data flows.

PROOF OF CONCEPT

CLS‑powered VPN demo

Full tunnel: obfuscation parameters (H1,S1,Jc) derived from CLS, CLS itself never transmitted.

Client and server establish TLS connection. CLS is obtained independently on both sides — visible values match (first 8 bytes). Obfuscation parameters (H1, S1, Jc) and RNG seeds are derived from CLS. After closing TCP, both switch to UDP, client sends obfuscated ping, server replies pong. All synchronisation happens without transmitting CLS or derivative parameters over the network.

Note: When no NAT exists (direct connections), the short initialisation handshake (trigger + confirmation) is not required at all — CLS can be derived immediately using standard transport parameters.
Russian patent application
Application № 2026113066 dated 21.04.2026

We are looking for a strategic partnership

We are seeking interested parties and partners to create a joint commercial product based on CLS (e.g., a VPN with implicit synchronization of tunnel behavior parameters, a secure messenger, etc.), to obtain a patent, license it, or acquire it. Priority date established, formal examination passed — ready for commercial engagement.

📧 eldicom@yandex.ru   |   Telegram: @CLS_tech