Digital Certificate Segmentation for Encrypted Traffic Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security protocols struggle to effectively prioritize and manage encrypted traffic in enterprise and service provider networks, particularly in cloud computing and virtual desktop infrastructure environments, where different applications require varying levels of priority and quality of service, and intermediate network devices cannot make policy decisions due to encrypted identity information.
Innovation Solution
The implementation of a secure key exchange mechanism using digital certificates, where endpoint network devices obtain identity and classification certificates from a certificate authority database, allowing intermediate devices to classify and prioritize traffic based on classification information without decrypting identity information, using modified IKE exchanges and IPSec protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted traffic is used to maintain security, then security is improved, but intermediate network devices cannot make policy decisions due to inability to evaluate identity information
Solution Approach 1:
The digital certificate is segmented into two distinct parts: an encrypted identity information portion and an unencrypted classification information portion. This segmentation allows intermediate network devices to access and evaluate classification information for policy decisions while the identity information remains encrypted to maintain security. The certificate authority database stores both portions, enabling selective decryption or non-decryption based on the device's needs.
Solution Approach 2:
The patent introduces an intermediary mechanism where the certificate authority database acts as a mediator between the encrypted identity information and the intermediate network devices. The database stores both encrypted identity information and unencrypted classification information, allowing intermediate devices to obtain classification information without accessing the encrypted identity data. This intermediary structure enables policy decision-making while preserving security.
2Reliability
If identity information is encrypted to protect privacy, then security is improved, but classification information becomes unavailable for traffic prioritization
Solution Approach 1:
The digital certificate is divided into separate encrypted and unencrypted portions. The identity information is encrypted to protect privacy, while the classification information is stored in an unencrypted state within the same certificate structure. This segmentation ensures that classification information remains accessible for traffic prioritization and quality of service decisions without compromising the security of identity information.
Solution Approach 2:
The patent extracts the classification information from the encrypted identity information and stores it separately in an unencrypted format within the digital certificate. This extraction allows intermediate network devices to access classification information for traffic management purposes without needing to decrypt or access the sensitive identity information, thus preventing information loss while maintaining security.
3Adaptability or versatility
If standard IKE exchange is used for secure key exchange, then security protocol compatibility is maintained, but classification information cannot be transmitted to intermediate devices
Solution Approach 1:
The patent merges the classification information transmission into the existing IKE exchange protocol by incorporating it into the digital certificate that is already exchanged during the protocol. The modified IKE exchange includes the digital certificate with both encrypted identity information and unencrypted classification information, allowing classification information to be transmitted without requiring a separate protocol or modifying the core IKE exchange mechanics, thus maintaining protocol compatibility while enabling information transmission.
Data Source
AI summary
Techniques are provided for obtaining first and second digital certificates from a certificate authority database for establishing a secure exchange between network devices. The first digital certificate contains identity information of a first network device, and the second digital certificate contains classification information of the first network device. In one embodiment, a secure key exchange is initiated with the second network device, and the first and second digital certificates are transmitted as a part of the secure key exchange to the second network device. In another embodiment, the first and second digital certificates are received by an intermediate network device. The first digital certificate is encrypted and is not evaluated by the intermediate network device. The second digital certificate is evaluated for classification information of the first network device. Source information associated with the first network device is stored, and encrypted traffic is processed between the network devices.


