Cloud Packet Routing Using External Tags Instead of Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions require decryption of traffic for policy and routing decisions, which is computationally expensive and exposes customer data, compromising privacy and network performance.
Innovation Solution
Applying metadata tags externally to encrypted packets to enable routing and policy decisions without decrypting the payload, using encapsulation protocols like (D)TLS and IPsec to protect the metadata tags from inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If decryption operations are performed on packets for routing and policy decisions, then routing accuracy and policy enforcement capability are improved, but computational cost increases and network performance deteriorates
Solution Approach 1:
The patent extracts only the necessary routing information (source IP, destination IP, port numbers) from the packet header before encryption, storing it in metadata tags. This allows routing decisions to be made without decrypting the entire packet payload, thus maintaining routing accuracy while avoiding the computational overhead of full decryption operations.
Solution Approach 2:
The patent performs routing information extraction and metadata tag attachment before the packet is encrypted and transmitted through the network. By preparing routing information in advance and attaching it externally to the encrypted packet, the system enables fast routing lookups without requiring decryption at routing nodes, thereby improving network performance.
2Reliability
If decryption operations are performed on packets for policy enforcement, then security policy compliance is improved, but data privacy is compromised
Solution Approach 1:
The patent extracts only the minimal necessary information for policy enforcement (source IP, destination IP, port numbers, protocol type) and stores it in metadata tags attached externally to the encrypted packet. This allows security policies to be enforced based on header information without exposing the encrypted payload, thus maintaining policy compliance while preserving data privacy.
Solution Approach 2:
The patent introduces metadata tags as an intermediary between the encrypted packet and the security policy enforcement mechanism. These tags contain the necessary routing and policy information in an unencrypted form that can be read by network nodes, while the actual packet payload remains encrypted and private throughout transmission.
3Difficulty of detecting and measuring
If full packet decryption is performed for inspection, then deep packet inspection capability is improved, but computational overhead increases
Solution Approach 1:
The patent extracts essential inspection information (source IP, destination IP, port numbers, protocol type) from the packet header and places it in metadata tags. This enables network nodes to perform effective packet inspection and routing decisions based on these extracted fields without the need to decrypt and process the entire packet payload, significantly reducing computational overhead.
Solution Approach 2:
The patent applies partial decryption or inspection by only examining the metadata tags and packet headers that contain routing information, rather than performing full packet decryption. This partial action approach provides sufficient inspection capability for routing and basic security policies while avoiding the excessive computational cost of complete packet decryption.
Data Source
AI summary
A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.


