Cloud Packet Routing Using External Tags Instead of Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security solutions require decryption of traffic for policy and routing decisions, which is computationally expensive and exposes customer data, compromising privacy and network performance.

Innovation Solution

Applying metadata tags externally to encrypted packets to enable routing and policy decisions without decrypting the payload, using encapsulation protocols like (D)TLS and IPsec to protect the metadata tags from inspection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If decryption operations are performed on packets for routing and policy decisions, then routing accuracy and policy enforcement capability are improved, but computational cost increases and network performance deteriorates

Engineering Contradiction:
Improverouting accuracyVSAvoidnetwork performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the necessary routing information (source IP, destination IP, port numbers) from the packet header before encryption, storing it in metadata tags. This allows routing decisions to be made without decrypting the entire packet payload, thus maintaining routing accuracy while avoiding the computational overhead of full decryption operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs routing information extraction and metadata tag attachment before the packet is encrypted and transmitted through the network. By preparing routing information in advance and attaching it externally to the encrypted packet, the system enables fast routing lookups without requiring decryption at routing nodes, thereby improving network performance.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If decryption operations are performed on packets for policy enforcement, then security policy compliance is improved, but data privacy is compromised

Engineering Contradiction:
Improvesecurity policy complianceVSAvoiddata privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the minimal necessary information for policy enforcement (source IP, destination IP, port numbers, protocol type) and stores it in metadata tags attached externally to the encrypted packet. This allows security policies to be enforced based on header information without exposing the encrypted payload, thus maintaining policy compliance while preserving data privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces metadata tags as an intermediary between the encrypted packet and the security policy enforcement mechanism. These tags contain the necessary routing and policy information in an unencrypted form that can be read by network nodes, while the actual packet payload remains encrypted and private throughout transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If full packet decryption is performed for inspection, then deep packet inspection capability is improved, but computational overhead increases

Engineering Contradiction:
Improveinspection capabilityVSAvoidcomputational overhead
Core Design Contradiction:
Difficulty of detecting and measuringVSUse of energy by moving object

Solution Approach 1:

The patent extracts essential inspection information (source IP, destination IP, port numbers, protocol type) from the packet header and places it in metadata tags. This enables network nodes to perform effective packet inspection and routing decisions based on these extracted fields without the need to decrypt and process the entire packet payload, significantly reducing computational overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies partial decryption or inspection by only examining the metadata tags and packet headers that contain routing information, rather than performing full packet decryption. This partial action approach provides sufficient inspection capability for routing and basic security policies while avoiding the excessive computational cost of complete packet decryption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12476947B2Wire-speed routing and policy enforcement without DPI or decryption
Publication Date: 2025.11.18 CISCO TECHNOLOGY INC
  • US12476947B2 patent drawing
  • US12476947B2 patent drawing
  • US12476947B2 patent drawing

AI summary

A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.