Encrypted Network Packet Classification for QoS Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise network environments, it is challenging to classify and prioritize encrypted network packets effectively for quality of service (QoS) techniques due to varying performance requirements and encryption, compression, or other alterations, leading to inefficiencies in network performance optimization.

Innovation Solution

The system classifies encrypted network packets through a first classifier at the network stack's initial portion, assigning an application identifier, and reclassifies them after decryption using a second classifier at a higher portion of the stack, providing application-specific information to QoS and acceleration engines, thus optimizing network performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If encrypted packets are classified before decryption, then classification can be performed on encrypted data, but the classification accuracy is insufficient due to encryption obscuring packet content

Engineering Contradiction:
Improveclassification accuracyVSAvoidpacket content visibility
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent segments the classification process into two distinct stages: a first classification before decryption using limited visible packet headers, and a second classification after decryption using the full packet content. This segmentation allows each classification stage to operate on the type of data most appropriate for its analytical needs, resolving the contradiction between early classification and accurate classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first classification is performed as a preliminary action before decryption occurs. This preliminary classification uses available packet header information to create an initial categorization that guides subsequent processing, while the final accurate classification is refined after decryption provides complete packet visibility.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If packets are decrypted before classification, then full packet content is available for accurate classification, but network performance degrades due to lack of prioritization in decryption processing

Engineering Contradiction:
Improveclassification accuracyVSAvoidnetwork processing efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The first classification is performed preliminarily before decryption to establish priority levels. This allows the decryption process to be orchestrated with proper prioritization, ensuring that high-priority encrypted packets are decrypted first, thus maintaining network processing efficiency while still achieving accurate final classification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the decryption processing order based on the priority information obtained from the first classification. Packets are decrypted in a dynamic sequence that prioritizes time-sensitive and high-importance traffic, optimizing overall network performance while enabling accurate second-stage classification.

Inventive Principle:
Principle #15Dynamics

3Productivity

If a single classification is performed, then the process is simple and fast, but QoS and acceleration engines cannot obtain packet-specific information for optimization

Engineering Contradiction:
Improveprocessing speedVSAvoidapplication-specific information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The classification function is segmented into two specialized stages: a fast first classification that provides immediate priority information to QoS and acceleration engines, and a more comprehensive second classification that extracts detailed application-specific information. This segmentation allows both speed and information completeness to be achieved.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first classification acts as an intermediary that provides initial packet identification information to QoS and acceleration engines, enabling them to begin optimization processes. The second classification then provides supplementary detailed information, allowing the system to achieve both rapid response and comprehensive optimization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2604020B1Systems and methods for quality of service of encrypted network traffic
Publication Date: 2021.01.06 CITRIX SYSTEMS INC
  • EP2604020B1 patent drawingFigure 1A
  • EP2604020B1 patent drawingFigure 1B
  • EP2604020B1 patent drawingFigure 1C

AI summary

The present invention is directed towards systems and methods for providing classification of an encrypted network packet for performing QoS and acceleration techniques. Encrypted packets may be classified by a first classifier at a first portion of a network stack of a device as corresponding to a first predetermined application, and an application identifier may be included with the packet. In some embodiments, the packets may be decrypted in an order dependent on a first classification of the encrypted network packet. After decryption, packets may be reclassified as corresponding to a second predetermined application by a second classifier operating at a second portion of a network stack of the device above the first portion. Thus, network performance may be enhanced and optimized by providing QoS and acceleration engines with packet- or data-specific information corresponding to the application, while avoiding inefficiencies due to a lack of prioritization of decryption.