Encrypted Packet Routing Using External Metadata Tags
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security solutions require decryption of traffic for policy and routing decisions, which is computationally expensive and exposes customer data, compromising privacy and network performance.
Innovation Solution
Applying metadata tags externally to encrypted packets to enable routing and policy enforcement without decrypting the packets, using encapsulation protocols like (D)TLS and IPsec to protect the metadata tags from inspection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If decryption operations are performed on packets for routing and policy decisions, then routing accuracy and policy enforcement are improved, but computational cost and network performance deteriorate
Solution Approach 1:
The packet is segmented into encrypted payload and unencrypted metadata portions. The metadata contains routing and policy information that can be processed without decryption, while the payload remains encrypted. This segmentation allows routing decisions to be made on unencrypted metadata, eliminating the need for full packet decryption and maintaining network performance.
Solution Approach 2:
Routing and policy information is extracted from the packet and placed in metadata that remains unencrypted. This extracted metadata is separate from the encrypted payload, allowing network devices to perform routing and policy enforcement on the extracted metadata without performing computationally expensive decryption operations on the entire packet.
2Reliability
If decryption operations are performed on packets for policy enforcement, then security policy compliance is improved, but data privacy and security are worsened
Solution Approach 1:
The packet structure is segmented into encrypted payload and unencrypted metadata. The metadata contains all necessary information for policy enforcement (such as user identity, data class, routing information) while the sensitive payload remains encrypted. This allows security policies to be enforced on the metadata without exposing the actual data content.
Solution Approach 2:
Metadata acts as an intermediary that carries routing and policy information without requiring decryption of the actual payload. The metadata serves as a mediator between the encrypted data and the security enforcement mechanisms, enabling policy compliance while maintaining data confidentiality through the use of encryption protocols like (D)TLS and IPsec.
Data Source
AI summary
A system and computer-implemented method for routing an encrypted packet through a cloud enforcement network based on a metadata tag. The cloud enforcement network applies policy and routing attributions or tags outside of the encrypted packet payload in such a way as to not require an inner packet to first be decrypted. Traffic prioritization, data protection, and per application policies are achieved by using such metadata tags for internode routing without the need for DPI or decryption. Furthermore, the metadata itself can also be signed or encrypted depending on the provenance of the data. As such, applying meta-tagging external to an encrypted packet, the payload would not be needed to be decrypted during transit of the packet to express end-to-end policy and routing decisions.


