Application Watermarking for Secure Packet Flow Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network-based application recognition technologies are inadequate in ensuring security from malicious applications, as they rely on complex deep packet inspection and are challenged by new application layer protocols, payload encryption, and the need for higher throughput and lower latencies, making them ineffective against rogue programs that mimic legitimate protocols.
Innovation Solution
The implementation of application watermarking, which involves inserting a security tag into packets with a unique identifier that authenticates registered applications, allowing for secure packet flow management and access control based on verified identities, thereby preventing unauthorized access and ensuring the integrity of communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deep packet inspection is used for application recognition, then security against malicious applications is improved, but device complexity and processing time increase
Solution Approach 1:
The patent applies preliminary action by inserting application identifiers into packets at the source before transmission. This pre-marking approach eliminates the need for complex deep packet inspection at intermediate nodes, as the application identity is already established and embedded in the packet metadata, enabling simple lookup-based recognition downstream.
Solution Approach 2:
The patent extracts the application identification function from complex deep packet inspection by isolating it into a separate metadata field (application identifier) that is inserted into packets. This extraction allows security functions to operate on simple identifier matching rather than complex payload analysis, reducing device complexity while maintaining security.
2Reliability
If deep packet inspection is used for application recognition, then security against malicious applications is improved, but processing speed decreases
Solution Approach 1:
By performing application identification and identifier insertion at the packet source before transmission, the patent eliminates time-consuming deep packet inspection at intermediate nodes. The preliminary tagging enables fast identifier-based matching downstream, significantly improving throughput while maintaining security.
Solution Approach 2:
The patent extracts application identification from complex deep packet inspection operations, isolating it into a simple metadata field. This extraction transforms the security checking process from complex payload analysis to simple identifier matching, thereby improving processing speed and throughput.
3Adaptability or versatility
If application identifiers are inserted into packets, then access control based on application identity is improved, but packet structure complexity increases
Solution Approach 1:
The patent makes the application identifier field a universal component of packet structure that serves multiple functions: application recognition, access control, bandwidth management, and quality of service differentiation. This multi-functionality justifies the added packet structure element by providing versatile control capabilities across multiple network functions.
Data Source
AI summary
A method or system for managing packet flow is disclosed. The packets each include an inserted application identifier identifying a registered application. The method includes receiving packets destined for one or more resources, determining, by a packet processor, the inserted application identifier for each of the respective packets received and managing the packet flow of each received packet sent from a security node based at least in part on the inserted application identifier of the received packet.


