Emulated HTTPS Session Testing for Network Device Throughput

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Testing devices that support HTTPS communications between servers and clients is processor-intensive due to the need for encryption and decryption of data packets, which slows down the testing process.

Innovation Solution

Implementing pseudo HTTPS communications between emulated servers and clients, using multiple state machines on processor cores to establish and test HTTPS sessions without actual encryption and decryption, allowing for faster data throughput through the device under test.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional HTTPS testing with encryption and decryption is used, then security testing accuracy is improved, but testing speed deteriorates

Engineering Contradiction:
Improvesecurity testing accuracyVSAvoidtesting speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent performs HTTPS handshaking and encryption protocol negotiation in advance before the actual stress test. The encrypted channel is established beforehand, allowing the subsequent stress test to use pre-negotiated encryption parameters without repeated handshaking, thus improving testing speed while maintaining security testing accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a simplified copy of the HTTPS testing environment using emulated servers and clients that replicate real HTTPS behavior without requiring full encryption/decryption processing. This allows speed testing to proceed without the computational overhead of actual cryptographic operations, resolving the contradiction between security accuracy and testing speed

Inventive Principle:
Principle #26Copying

2Productivity

If emulated servers and clients are used to increase throughput testing capacity, then device testing capability is improved, but complexity of setting up HTTPS sessions worsens

Engineering Contradiction:
Improvedevice testing capabilityVSAvoidcomplexity of setting up HTTPS sessions
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal HTTPS testing framework where a single test system can simultaneously manage multiple emulated servers and clients across different processor cores. The system provides unified HTTPS session management and encryption handling, allowing high-volume throughput testing without proportionally increasing operational complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary testing system that mediates between emulated servers and clients, handling the complex HTTPS session establishment and encryption negotiations centrally. This intermediary layer simplifies the interface for individual test components while maintaining full HTTPS functionality, enabling high productivity without proportional complexity increase

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11824740B2Method and system for inducing secure communications between one or more emulated servers and emulated clients to test a device therebetween
Publication Date: 2023.11.21 SPIRENT COMM INC
  • US11824740B2 patent drawing
  • US11824740B2 patent drawing
  • US11824740B2 patent drawing

AI summary

The technology disclosed provides a method of testing handling of HTTPS sessions of a plurality of clients with a plurality of servers by a switching, bridging or routing device (i.e., a DUT), where the testing is conducted by a test system coupled to ports on the DUT. The method includes using client state machines running on at least four processor cores, communicating through the DUT with server state machines running on at least four additional processor cores. The method also includes, for each connection between a client represented by a client state machine and a server represented by a server state machine, setting up an HTTPS session by negotiating an encryption protocol and completing an HTTPS handshake. Further, the method includes following the setup of between 100,000 HTTPS sessions and 10,000,000 HTTPS sessions, conducting a stress test including combining payload data and header information without using the negotiated encryption.