Application Watermarking for Secure Packet Flow Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network-based application recognition technologies are inadequate in ensuring security from malicious applications, as they rely on complex deep packet inspection and are challenged by new application layer protocols, payload encryption, and the need for higher throughput and lower latencies, making them ineffective against rogue programs that mimic legitimate protocols.

Innovation Solution

The implementation of application watermarking, which involves inserting a security tag into packets with a unique identifier that authenticates registered applications, allowing for secure packet flow management and access control based on verified identities, thereby preventing unauthorized access and ensuring the integrity of communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet inspection is used for application recognition, then security against malicious applications is improved, but device complexity and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by inserting application identifiers into packets at the source before transmission. This pre-marking approach eliminates the need for complex deep packet inspection at intermediate nodes, as the application identity is already established and embedded in the packet metadata, enabling simple lookup-based recognition downstream.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the application identification function from complex deep packet inspection by isolating it into a separate metadata field (application identifier) that is inserted into packets. This extraction allows security functions to operate on simple identifier matching rather than complex payload analysis, reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If deep packet inspection is used for application recognition, then security against malicious applications is improved, but processing speed decreases

Engineering Contradiction:
ImprovesecurityVSAvoidthroughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By performing application identification and identifier insertion at the packet source before transmission, the patent eliminates time-consuming deep packet inspection at intermediate nodes. The preliminary tagging enables fast identifier-based matching downstream, significantly improving throughput while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts application identification from complex deep packet inspection operations, isolating it into a simple metadata field. This extraction transforms the security checking process from complex payload analysis to simple identifier matching, thereby improving processing speed and throughput.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If application identifiers are inserted into packets, then access control based on application identity is improved, but packet structure complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidpacket structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the application identifier field a universal component of packet structure that serves multiple functions: application recognition, access control, bandwidth management, and quality of service differentiation. This multi-functionality justifies the added packet structure element by providing versatile control capabilities across multiple network functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9240945B2Access, priority and bandwidth management based on application identity
Publication Date: 2016.01.19 CITRIX SYSTEMS INC
  • US9240945B2 patent drawing
  • US9240945B2 patent drawing
  • US9240945B2 patent drawing

AI summary

A method or system for managing packet flow is disclosed. The packets each include an inserted application identifier identifying a registered application. The method includes receiving packets destined for one or more resources, determining, by a packet processor, the inserted application identifier for each of the respective packets received and managing the packet flow of each received packet sent from a security node based at least in part on the inserted application identifier of the received packet.