Encrypted Data Stream Identification via TLS Handshake Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security technologies cannot effectively identify encrypted data streams without relying on plaintext identifiers, which are insecure and no longer supported by subsequent TLS protocols.
Innovation Solution
A method that involves a core network device receiving authentication data from user equipment, obtaining a second authentication result using a pre-stored parameter, and establishing an association relationship between data packet characteristics and an application identifier to identify encrypted data streams, eliminating the need for plaintext identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If plaintext identifiers are used to identify encrypted data streams, then identification capability is improved, but security deteriorates
Solution Approach 1:
The patent extracts and removes the plaintext identifier component from the TLS protocol identification mechanism. Instead of using Application Layer Record Layer Plaintext Identifiers (ALPIS) that expose application information in plaintext, the solution extracts only the necessary authentication functionality through cryptographic parameters exchanged during TLS handshake, eliminating the security vulnerability while preserving identification capability.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using TLS handshake parameters (such as Client Random, Server Random, and cryptographic keys) as mediators. These parameters serve as secure intermediaries that enable network devices to authenticate and identify encrypted data streams without exposing plaintext application information, thus maintaining security while achieving identification.
2Reliability
If authentication mechanisms are implemented to improve security, then computational resources required for configuration and maintenance increase
Solution Approach 1:
The patent performs authentication actions preliminarily during the TLS handshake process itself. By integrating the authentication mechanism into the existing handshake protocol, the system establishes security credentials and identification parameters in advance, before actual data transmission begins. This preliminary authentication avoids the need for separate, resource-intensive authentication operations during data flow processing.
Solution Approach 2:
The patent enables the TLS protocol to self-authenticate by utilizing authentication parameters that are inherently generated and exchanged during the handshake process. The Client Random, Server Random, and derived cryptographic keys serve as self-contained authentication credentials that allow network devices to verify and identify encrypted streams without requiring external authentication infrastructure or additional computational overhead.
Data Source
AI summary
A method for identifying an encrypted data stream, a device, a readable storage medium and a system are provided. The method includes: receiving a data packet carrying authentication data which is sent by a user equipment (UE), where the authentication data includes a first authentication parameter, a first authentication result and an application identifier; obtaining, based on the first authentication parameter and a second authentication parameter, a second authentication result according to a set authentication algorithm, where the second authentication parameter is a pre-stored authentication parameter corresponding to the application identifier; establishing an association relationship between characteristic information of the data packet and the application identifier when the second authentication result is consistent with the first authentication result in comparison, where the association relationship is used for subsequently identifying an encrypted data stream which is sent by the UE and corresponds to the application identifier.


