Encrypted Network Performance Monitoring via Probing Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the Software as a Service (SaaS) model, end-users lack the skills and resources to monitor and enforce service level agreements (SLAs) for network performance, as they often rely on third-party providers and do not have direct tools or relationships with IT groups for managing mission-critical applications.
Innovation Solution
A method and system for monitoring encrypted communications sessions between computing devices using non-intrusive network tap points and probing devices, which derive timing information and transmit it between client-side and server-side probing devices, enabling the analysis of network performance metrics across encrypted communication segments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If end-users subscribe directly with SaaS providers, then service delivery is simplified and centralized, but end-users lose the ability to monitor and enforce service level agreements
Solution Approach 1:
The patent introduces network tap points and probing devices as intermediaries between the end-user and the SaaS provider. These intermediaries capture and analyze encrypted network traffic, deriving timing information and performance metrics without requiring decryption or direct access to the SaaS application, thus enabling monitoring while preserving the simplified SaaS delivery model
Solution Approach 2:
The monitoring system is segmented into multiple independent components: network tap points for capturing traffic, client-side probing devices for local analysis, and server-side probing devices for remote analysis. This segmentation allows each component to perform its function independently without disrupting the encrypted communication stream or requiring centralized control
2Reliability
If encrypted communications are used, then data security is improved, but network performance monitoring becomes difficult
Solution Approach 1:
The patent extracts only the necessary timing information and performance metrics from the encrypted communication stream without requiring access to the encrypted payload. Network tap points capture packets, and probing devices extract timing data from packet headers and metadata, leaving the encrypted content intact and secure while enabling performance analysis
Solution Approach 2:
The patent replaces traditional monitoring methods that require decryption (chemical/biological analogy) with a physical layer approach that monitors timing and metadata. Instead of attempting to break or decrypt the encryption, the system uses timing analysis, packet size analysis, and inter-arrival time measurements to infer performance metrics
3Measurement precision
If traditional IT groups manage software in-house, then performance and availability can be monitored directly, but the complexity of managing SaaS services increases
Solution Approach 1:
The patent positions network tap points and probing devices as intermediaries that enable corporate IT groups to monitor SaaS performance without requiring direct management relationships with SaaS providers. The intermediaries capture and analyze traffic at the network level, providing visibility into performance metrics while maintaining the simplified SaaS subscription model
Data Source
AI summary
According to one general aspect, a method of using a first probing device may include monitoring one or more encrypted communications sessions between a first computing device and a second computing device. In some implementations of the method, each encrypted communications session includes transmitting a plurality of encrypted data objects between the first and second computing devices. The method may include deriving, by the first probing device, timing information regarding an encrypted communications session. The method may also include transmitting, from the first probing device to a second probing device, the derived timing information.


