Digital Certificate Segmentation for Encrypted Traffic Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security protocols struggle to effectively prioritize and manage encrypted traffic in enterprise and service provider networks, particularly in cloud computing and virtual desktop infrastructure environments, where different applications require varying levels of priority and quality of service, and intermediate network devices cannot make policy decisions due to encrypted identity information.

Innovation Solution

The implementation of a secure key exchange mechanism using digital certificates, where endpoint network devices obtain identity and classification certificates from a certificate authority database, allowing intermediate devices to classify and prioritize traffic based on classification information without decrypting identity information, using modified IKE exchanges and IPSec protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encrypted traffic is used to maintain security, then security is improved, but intermediate network devices cannot make policy decisions due to inability to evaluate identity information

Engineering Contradiction:
ImprovesecurityVSAvoidpolicy decision making
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The digital certificate is segmented into two distinct parts: an encrypted identity information portion and an unencrypted classification information portion. This segmentation allows intermediate network devices to access and evaluate classification information for policy decisions while the identity information remains encrypted to maintain security. The certificate authority database stores both portions, enabling selective decryption or non-decryption based on the device's needs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the certificate authority database acts as a mediator between the encrypted identity information and the intermediate network devices. The database stores both encrypted identity information and unencrypted classification information, allowing intermediate devices to obtain classification information without accessing the encrypted identity data. This intermediary structure enables policy decision-making while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity information is encrypted to protect privacy, then security is improved, but classification information becomes unavailable for traffic prioritization

Engineering Contradiction:
ImprovesecurityVSAvoidclassification information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The digital certificate is divided into separate encrypted and unencrypted portions. The identity information is encrypted to protect privacy, while the classification information is stored in an unencrypted state within the same certificate structure. This segmentation ensures that classification information remains accessible for traffic prioritization and quality of service decisions without compromising the security of identity information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the classification information from the encrypted identity information and stores it separately in an unencrypted format within the digital certificate. This extraction allows intermediate network devices to access classification information for traffic management purposes without needing to decrypt or access the sensitive identity information, thus preventing information loss while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If standard IKE exchange is used for secure key exchange, then security protocol compatibility is maintained, but classification information cannot be transmitted to intermediate devices

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidclassification information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent merges the classification information transmission into the existing IKE exchange protocol by incorporating it into the digital certificate that is already exchanged during the protocol. The modified IKE exchange includes the digital certificate with both encrypted identity information and unencrypted classification information, allowing classification information to be transmitted without requiring a separate protocol or modifying the core IKE exchange mechanics, thus maintaining protocol compatibility while enabling information transmission.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9306936B2Techniques to classify virtual private network traffic based on identity
Publication Date: 2016.04.05 CISCO TECHNOLOGY INC
  • US9306936B2 patent drawing
  • US9306936B2 patent drawing
  • US9306936B2 patent drawing

AI summary

Techniques are provided for obtaining first and second digital certificates from a certificate authority database for establishing a secure exchange between network devices. The first digital certificate contains identity information of a first network device, and the second digital certificate contains classification information of the first network device. In one embodiment, a secure key exchange is initiated with the second network device, and the first and second digital certificates are transmitted as a part of the secure key exchange to the second network device. In another embodiment, the first and second digital certificates are received by an intermediate network device. The first digital certificate is encrypted and is not evaluated by the intermediate network device. The second digital certificate is evaluated for classification information of the first network device. Source information associated with the first network device is stored, and encrypted traffic is processed between the network devices.