CAPTAIN Protocol Adapters for Tactical Network Encryption Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current In-Line Network Encryptor (INE) devices impair the operation of networking protocols and network optimization techniques, particularly in tactical networks with dynamically varying link characteristics and multiple Cypher Text-side asymmetric links, and preclude operations like multicast and disruption tolerant networking, while also rendering cybersecurity less effective due to limitations in deep packet inspection.

Innovation Solution

The implementation of Crypto-Partitioning Aware Protocol adapters for Tactical Networks (CAPTAIN), which intercept and populate pass-through fields in data packets to enable communication across INEs, allowing for the implementation of performance-enhancing proxy functions such as per-flow load balancing, denial of service attack detection, and quality of service management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data packets are encrypted through an In-Line Network Encryptor (INE) device, then network security is improved, but protocol operation and network optimization techniques are impaired

Engineering Contradiction:
Improvenetwork securityVSAvoidprotocol operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the data packet into encrypted portions and unencrypted pass-through fields. The INE device encrypts only the necessary payload while leaving specific fields (such as source/destination addresses, port numbers, and protocol identifiers) unencrypted. This segmentation allows security to be maintained while preserving protocol functionality and enabling network optimization techniques to operate on the visible header fields.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces protocol adapters as intermediary components that interface between the encrypted network traffic and network optimization functions. These adapters intercept packets, extract unencrypted fields, and make them available to network optimization techniques without requiring full decryption. This intermediary layer resolves the contradiction by enabling protocol operation while maintaining encryption security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If deep packet inspection is limited due to encryption, then network security is improved, but cybersecurity effectiveness is worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidcybersecurity effectiveness
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments packet inspection into two layers: header field inspection (unencrypted) and payload inspection (encrypted). Network security devices can perform deep inspection of unencrypted pass-through fields including source/destination addresses, port numbers, and protocol identifiers to detect anomalies and threats. The encrypted payload remains protected, maintaining security while enabling effective cybersecurity monitoring of critical packet metadata.

Inventive Principle:
Principle #1Segmentation

3Reliability

If all data fields are encrypted, then network security is improved, but communication coherence and network optimization are worsened

Engineering Contradiction:
Improvenetwork securityVSAvoidcommunication coherence
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the data packet structure into encrypted payload portions and unencrypted pass-through fields. Essential communication fields such as source address, destination address, port numbers, and protocol identifiers are kept unencrypted to maintain communication coherence and enable network optimization. Only the sensitive payload data is encrypted, achieving security without sacrificing communication functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption qualities to different parts of the data packet. Critical routing and communication fields receive no encryption (unencrypted pass-through), while sensitive payload data receives full encryption. This local differentiation of encryption quality ensures that communication coherence is maintained where needed while security is applied where required.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9191377B2Method for network communication past encryption devices
Publication Date: 2015.11.17 ARCHITECTURE TECH CORP
  • US9191377B2 patent drawing
  • US9191377B2 patent drawing
  • US9191377B2 patent drawing

AI summary

This disclosure is directed to techniques for providing communication between devices in different networks wherein the communication must first pass through an encryption mechanism and the devices do not have the stand-alone capability to encrypt or decrypt the communication. According to these techniques, an adapter may determine certain fields in a data packet that remain unencrypted when the data packet passes through the encryption mechanism. The adapter may then process those fields in such a way that, when the data packets are received by a second adapter, the second adapter may read those fields and obtain information.