Data Compliance Metadata Marking in Packet Headers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large multi-national organizations face challenges in adhering to data compliance regulations across different regions due to the lack of awareness of data compliance requirements by network infrastructure, as the data packets are often encrypted, preventing effective enforcement of network policies.

Innovation Solution

An application performance management agent inserts data compliance metadata into packet headers, allowing network devices to enforce regional and organizational-specific policies by leveraging existing network infrastructure without requiring new functionality, using methods such as embedding metadata in HTTP, TCP, or IP headers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data packets are encrypted to ensure security, then data security is improved, but network devices cannot read the data compliance requirements

Engineering Contradiction:
Improvedata securityVSAvoidcompliance information visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The solution segments compliance information from the encrypted data payload and places it in the unencrypted packet header. This allows network devices to access compliance requirements without decrypting the payload, maintaining security while enabling policy enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The packet header acts as an intermediary carrier that conveys compliance information from the application layer to network devices. This intermediary structure enables network devices to read compliance requirements without accessing the encrypted payload.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network infrastructure is made aware of data compliance requirements, then policy enforcement capability is improved, but system complexity increases

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidnetwork infrastructure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The packet header structure is enhanced to carry compliance metadata while maintaining compatibility with existing network protocols. This allows existing network devices to enforce policies without requiring new functionality, achieving multi-functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Compliance metadata is inserted into packet headers before packets enter the network infrastructure. This preliminary action enables network devices to read and enforce policies without requiring complex processing or modification of existing network protocols.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If compliance metadata is inserted into packet headers, then compliance identification accuracy is improved, but packet processing overhead increases

Engineering Contradiction:
Improvecompliance identification accuracyVSAvoidpacket processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The solution inserts compliance metadata selectively into packet headers only when compliance policies require it, rather than processing all packets uniformly. This partial action approach maintains accuracy for compliant packets while minimizing overhead for non-compliant traffic.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240380734A1Data compliance metadata marking
Publication Date: 2024.11.14 CISCO TECHNOLOGY INC
  • US20240380734A1 patent drawing
  • US20240380734A1 patent drawing
  • US20240380734A1 patent drawing

AI summary

A method is provided that is performed using an application performance management agent running on an application and/or application microservices. The method comprises detecting a request to the application and/or application microservices for data, and inserting data compliance metadata into packet headers of packets that are to be sent in response to the request by the application and/or application microservices. The data compliance metadata comprises data-compliance markings associated with the data based on user/operator-defined data compliance requirements. The method further includes causing the packets to be sent into a network so that one or more network devices or services in the network can read the data compliance metadata and apply packet handling policies.