Encrypted Connection Monitoring via EAP-kdTLS Key Disclosure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for monitoring encrypted communication connections in industrial networks require specific adaptations of network protocols and interfaces, limiting their applicability across different network types.
Innovation Solution
The use of an extensible authentication protocol (EAP) with a transport layer security protocol featuring a key disclosure function (EAP-kdTLS) allows for monitoring of encrypted connections without modifying existing network protocols or interfaces, enabling decryption and analysis of payload data traffic by providing security information to a monitoring apparatus through an intermediate device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If specific network protocols and interfaces are adapted to monitor encrypted communication connections, then monitoring capability is improved, but device complexity and protocol compatibility deteriorate
Solution Approach 1:
The patent introduces a key disclosure function as an intermediary mechanism between the encrypted communication channels and the monitoring system. This function acts as a mediator that selectively discloses decryption keys to authorized monitoring apparatus without requiring modifications to the existing TLS protocol or network infrastructure. The intermediary enables monitoring capability while maintaining protocol compatibility and avoiding device complexity increases.
2Reliability
If encryption protocols are used to protect data transmission, then security is improved, but monitoring and diagnosis capability deteriorates
Solution Approach 1:
The patent applies local quality by implementing selective key disclosure only to authorized monitoring apparatus while maintaining encryption for all other communication channels. The key disclosure function is localized to specific trusted entities rather than being universally applied. This allows monitoring and diagnosis information to be accessed by authorized parties without compromising the overall security of the encrypted communication system.
3Loss of information
If key disclosure functions are implemented to enable monitoring, then monitoring access is improved, but security risk deteriorates
Solution Approach 1:
The patent implements preliminary action by establishing authentication and authorization mechanisms before any key disclosure occurs. The key disclosure function is only activated after verifying the identity and authority of the requesting monitoring apparatus. This preliminary verification step ensures that only authorized entities can access decryption keys, thereby enabling monitoring access while minimizing security risks through pre-emptive security checks.
Data Source
AI summary
Provided is an arrangement for monitoring, a monitoring device and intermediary device and method for monitoring an encrypted connection between a client and an access point in a network, wherein—an Extensible Authentication Protocol is used for access authentication of the client to the network on an authentication server, and—a transport layer security protocol having a key disclosure function is executed within the Extensible Authentication Protocol, in which security information for the cryptographic protection of the connection is provided to an intermediary device and is transmitted from the intermediary device to a monitoring device for monitoring the connection. Also provided is a computer program product of the same.


