Cipher Rule Feedback via Traffic Management System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in network traffic management is the variability in support for secure communication protocols among different devices and applications, leading to complexities in cipher negotiation processes, which can result in incompatible cipher suites and compromised security.

Innovation Solution

Implementing a traffic management system that monitors and records cipher negotiation information between clients and servers, using bitfields to track and analyze negotiation data, and providing reporting and visualization tools to optimize cipher selection policies and identify potential security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If devices and applications use different cipher suites for secure communication, then adaptability to various communication needs is improved, but device complexity and negotiation difficulty increase

Engineering Contradiction:
Improvecipher suite compatibilityVSAvoidnegotiation process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms that monitor and record cipher negotiation outcomes between clients and servers. This feedback data is used to automatically update and optimize cipher suite selection policies, reducing negotiation complexity while maintaining adaptability. The system learns from past negotiations to make more efficient cipher selection decisions.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system enables self-service through automated cipher suite selection and policy optimization. The traffic management system automatically analyzes negotiation data, identifies compatible cipher suites, and updates policies without requiring manual configuration. This self-service approach reduces the complexity burden on individual devices while maintaining high adaptability.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive cipher negotiation monitoring is implemented, then security visibility is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity visibilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a traffic management system as an intermediary that sits between clients and servers to monitor cipher negotiations. This intermediary consolidates the monitoring complexity into a single centralized system rather than requiring each device to implement its own monitoring capabilities. The intermediary captures negotiation data, analyzes security compliance, and provides visibility without adding complexity to individual communicating devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If cipher suite compatibility is prioritized, then ease of connection establishment is improved, but security reliability may be compromised

Engineering Contradiction:
Improveconnection establishment easeVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-establishing cipher suite compatibility matrices and security policy rules before actual communications occur. The system pre-analyzes which cipher suites are both compatible across different devices and meet security requirements. During negotiation, this pre-prepared information enables fast connection establishment without compromising security, as the system only selects from pre-validated cipher combinations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically changes parameters based on the negotiation context, selecting cipher suites that optimize both compatibility and security. The traffic management system adjusts cipher selection parameters according to the specific client-server pair, communication type, and security policy requirements. This parameter optimization enables easy connection establishment while maintaining security reliability through context-aware cipher selection.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10432406B1Cipher rule feedback
Publication Date: 2019.10.01 F5 NETWORKS INC
  • US10432406B1 patent drawing
  • US10432406B1 patent drawing
  • US10432406B1 patent drawing

AI summary

Embodiments are directed towards managing network communication. A TMC may be arranged to receive network traffic that includes cipher negotiation information from a client computer. The TMC may receive other network traffic from a server computer that may include server cipher negotiation information. The TMC provides negotiation data that may correspond to the client cipher negotiation information and other negotiation data that may correspond to the server cipher negotiation information. The TMC may store the negotiation data and the other negotiation data in a data store. Then TMC may send the server cipher negotiation information at least the client computer. If a query is received from a query client, the TMC may provide result set information based on the stored the negotiation data and the other negotiation data in the data store. The TMC may send the reporting information based on the result set information to the query client.