Distributed Network Instrumentation System for Encryption Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End-to-end encryption reduces network visibility, hindering network instrumentation and policy enforcement in distributed environments by limiting the ability to classify traffic patterns and enforce security policies effectively.

Innovation Solution

A distributed network instrumentation system (DNIS) that includes a security management station (SMS), instrumentation management system (IMS), and enhanced capability network interfaces (ECNI) on compute platforms, which offload processing of local security policies and encryption, allowing for real-time analysis and enforcement of policies before encryption occurs, using components like global network policy decomposer, authenticator, data stream collector, and network instrumentation processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end encryption is implemented, then security is improved, but network visibility deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system segments the network infrastructure into distributed ECNI devices at multiple network points, each capable of independent policy enforcement and traffic analysis. This segmentation allows encryption to be applied end-to-end while maintaining visibility at distributed interception points, resolving the contradiction between security and visibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces ECNI devices as intermediary components that can intercept, analyze, and enforce policies on traffic before it is encrypted or after it is decrypted. These intermediaries maintain network visibility without compromising end-to-end encryption by operating at strategic points in the network architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traffic analysis is performed to classify patterns, then policy enforcement capability is improved, but processing complexity increases

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidprocessing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system divides policy enforcement and traffic analysis functions across multiple distributed ECNI devices rather than concentrating them in a single complex system. Each device handles local policy enforcement, reducing individual processing complexity while maintaining overall system capability through collective intelligence.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The ECNI devices perform preliminary traffic classification and policy evaluation before traffic is encrypted or forwarded. By pre-processing traffic at the network edge, the system reduces the complexity of later analysis stages and enables faster policy enforcement decisions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2630749B1Distributed network instrumentation system
Publication Date: 2019.01.30 HEWLETT PACKARD ENTERPRISE DEV LP
  • EP2630749B1 patent drawingFigure 1
  • EP2630749B1 patent drawingFigure 2

AI summary

A distributed network instrumentation system (100) includes a security management station (110) including a global network policy decomposer (112) configured to decompose global network security policies to local security policies for distributed policy enforcement, and a network interface (220) communicatively coupled to a compute platform (200). The network interface (220) is configured to off-load processing of the local security policies and end-to-end encryption from an operating system (210) of the compute platform (200) for facilitating network instrumentation.