Encrypted Packet Stream Detection via Feedback Probing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Encryption obscures the contents of electronic communications, making it difficult for communications service providers to determine the type of data within encrypted streams, leading to inadequate prioritization and processing, which can affect the quality of services like internet telephony.
Innovation Solution
The method involves generating probe streams with known observable parameters associated with specific types of data, which are sent through the network to correct for network-induced variations, allowing accurate detection and identification of data types within encrypted streams.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to electronic communications, then security and privacy are improved, but the ability to determine data types and provide priority processing deteriorates
Solution Approach 1:
The patent introduces probe streams as an intermediary mechanism that carries observable parameters through the encrypted communication channel. These probe streams serve as mediators between the encrypted data and the detection system, allowing data type identification without decrypting the actual communication content, thus maintaining security while enabling information extraction.
Solution Approach 2:
The patent replaces traditional content-based detection methods with a parameter-based observation system. Instead of examining the actual data content (mechanical inspection), the system substitutes this with observing statistical and temporal parameters of the encrypted stream, such as packet size distributions, timing patterns, and frequency characteristics.
2Reliability
If encryption is applied to electronic communications, then privacy is improved, but the ability to provide priority processing deteriorates
Solution Approach 1:
Probe streams act as intermediaries that carry observable parameters through the encrypted channel, enabling the detection system to identify data types and apply appropriate priority processing without compromising the privacy-protecting encryption of the actual communication content.
Solution Approach 2:
The system employs feedback mechanisms where detected parameters from probe streams are used to adjust and refine the identification of data types in real-time. This feedback loop enables dynamic priority processing decisions based on observed characteristics, maintaining both privacy and processing efficiency.
3Adaptability or versatility
If network variations are present, then network robustness is improved, but measurement precision of observable parameters deteriorates
Solution Approach 1:
The system performs preliminary characterization of network effects using probe streams before actual data detection. By pre-measuring and storing network-induced variations in parameters during probe stream transmission, the system can later compensate for these effects when analyzing actual encrypted data, maintaining measurement precision despite network robustness requirements.
Solution Approach 2:
The patent employs parameter changes by adjusting observation thresholds and compensation factors based on measured network conditions. When network variations are detected through probe streams, the system dynamically modifies its parameter measurement criteria to account for these changes, maintaining accuracy across varying network conditions.
Data Source
AI summary
Methods, systems, and devices are disclosed for detecting encrypted Internet Protocol packet streams. A probe stream having a known observable parameter is generated. The observable parameter exhibits a known characteristic of a known type of data encrypted within a stream of packets. The probe stream is communicated to a network element via a communications network. When the probe stream is received by the network element, the network element can compare the known observable parameter to an actual value. Any difference between the known observable parameter and the actual value can be used to correct for network-induced variation and other effects, thus ensuring accurate detection and identification of data types within encrypted streams of packets.


