Encrypted Connection Monitoring via EAP-kdTLS Key Disclosure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for monitoring encrypted communication connections in industrial networks require specific adaptations of network protocols and interfaces, limiting their applicability across different network types.

Innovation Solution

The use of an extensible authentication protocol (EAP) with a transport layer security protocol featuring a key disclosure function (EAP-kdTLS) allows for monitoring of encrypted connections without modifying existing network protocols or interfaces, enabling decryption and analysis of payload data traffic by providing security information to a monitoring apparatus through an intermediate device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If specific network protocols and interfaces are adapted to monitor encrypted communication connections, then monitoring capability is improved, but device complexity and protocol compatibility deteriorate

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidprotocol adaptation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a key disclosure function as an intermediary mechanism between the encrypted communication channels and the monitoring system. This function acts as a mediator that selectively discloses decryption keys to authorized monitoring apparatus without requiring modifications to the existing TLS protocol or network infrastructure. The intermediary enables monitoring capability while maintaining protocol compatibility and avoiding device complexity increases.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption protocols are used to protect data transmission, then security is improved, but monitoring and diagnosis capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidmonitoring access
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies local quality by implementing selective key disclosure only to authorized monitoring apparatus while maintaining encryption for all other communication channels. The key disclosure function is localized to specific trusted entities rather than being universally applied. This allows monitoring and diagnosis information to be accessed by authorized parties without compromising the overall security of the encrypted communication system.

Inventive Principle:
Principle #3Local quality

3Loss of information

If key disclosure functions are implemented to enable monitoring, then monitoring access is improved, but security risk deteriorates

Engineering Contradiction:
Improvemonitoring accessVSAvoidsecurity risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by establishing authentication and authorization mechanisms before any key disclosure occurs. The key disclosure function is only activated after verifying the identity and authority of the requesting monitoring apparatus. This preliminary verification step ensures that only authorized entities can access decryption keys, thereby enabling monitoring access while minimizing security risks through pre-emptive security checks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11368485B2Method, apparatuses and computer program product for monitoring an encrypted connection in a network
Publication Date: 2022.06.21 SIEMENS AG
  • US11368485B2 patent drawing
  • US11368485B2 patent drawing
  • US11368485B2 patent drawing

AI summary

Provided is an arrangement for monitoring, a monitoring device and intermediary device and method for monitoring an encrypted connection between a client and an access point in a network, wherein—an Extensible Authentication Protocol is used for access authentication of the client to the network on an authentication server, and—a transport layer security protocol having a key disclosure function is executed within the Extensible Authentication Protocol, in which security information for the cryptographic protection of the connection is provided to an intermediary device and is transmitted from the intermediary device to a monitoring device for monitoring the connection. Also provided is a computer program product of the same.