Network Monitoring via Encrypted Command Code Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network monitoring techniques fail to determine the success or failure of encrypted remote operations, as they rely on status values in response packets which are not accessible when communication is encrypted.

Innovation Solution

A network monitoring apparatus that includes a memory associating remote operation information with command codes and a processor to acquire command codes from encrypted execution request packets, determining the success of a remote operation by checking if the command codes match a combination in a command code list stored in a remote operation dictionary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If communication is encrypted to protect security, then security is improved, but the ability to monitor and determine remote operation success fails

Engineering Contradiction:
ImprovesecurityVSAvoidremote operation status information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces command codes as an intermediary element that bridges the gap between encrypted communication and monitoring. Instead of attempting to decrypt the entire communication, the system extracts specific command codes from the encrypted data stream that indicate remote operation status. These command codes serve as a mediator that conveys operational information without requiring decryption of the full encrypted payload, thus maintaining security while enabling monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts specific command codes from the encrypted communication stream to determine remote operation status. Rather than processing or decrypting the entire encrypted payload, the monitoring system selectively extracts and analyzes only the necessary command code portions that indicate success or failure of remote operations. This extraction approach allows monitoring functionality while preserving the confidentiality of the encrypted communication.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If status values are extracted from response packets to determine remote operation success, then monitoring capability is improved, but this approach fails when communication is encrypted

Engineering Contradiction:
Improveremote operation status detectionVSAvoidencryption blocking monitoring
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

Instead of attempting to extract status values from encrypted response packets (the traditional approach), the patent inverts the approach by extracting command codes from the encrypted data stream. Rather than looking for status indicators in decrypted or plain text response packets, the system identifies and extracts command codes that are embedded within the encrypted communication, reversing the conventional monitoring methodology to work around the encryption barrier.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

Command codes serve as an intermediary that allows status detection without requiring decryption. The monitoring system uses these command codes as intermediate indicators that convey remote operation status information while remaining extractable from encrypted streams, thus bypassing the need to break encryption while still achieving accurate status detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10819614B2Network monitoring apparatus and network monitoring method
Publication Date: 2020.10.27 FUJITSU LTD
  • US10819614B2 patent drawing
  • US10819614B2 patent drawing
  • US10819614B2 patent drawing

AI summary

There is provided a network monitoring apparatus including a memory in which information of a remote operation and a combination of one or more command codes are associated with each other, and a processor coupled to the memory and the processor configured to acquire a command code of the one or more commands codes from a header of an encrypted execution request packet for executing the one or more commands for implementing a remote operation, determine whether or not there exists the combination included in a command code list in which acquired command codes are sequentially indicated, by referring the memory, and determine that the remote operation associated with the combination is successful when it is determined that there exists the combination included in the command code list.