Encrypted Data Stream Identification via TLS Handshake Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security technologies cannot effectively identify encrypted data streams without relying on plaintext identifiers, which are insecure and no longer supported by subsequent TLS protocols.

Innovation Solution

A method that involves a core network device receiving authentication data from user equipment, obtaining a second authentication result using a pre-stored parameter, and establishing an association relationship between data packet characteristics and an application identifier to identify encrypted data streams, eliminating the need for plaintext identifiers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If plaintext identifiers are used to identify encrypted data streams, then identification capability is improved, but security deteriorates

Engineering Contradiction:
Improveidentification capabilityVSAvoidsecurity
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent extracts and removes the plaintext identifier component from the TLS protocol identification mechanism. Instead of using Application Layer Record Layer Plaintext Identifiers (ALPIS) that expose application information in plaintext, the solution extracts only the necessary authentication functionality through cryptographic parameters exchanged during TLS handshake, eliminating the security vulnerability while preserving identification capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using TLS handshake parameters (such as Client Random, Server Random, and cryptographic keys) as mediators. These parameters serve as secure intermediaries that enable network devices to authenticate and identify encrypted data streams without exposing plaintext application information, thus maintaining security while achieving identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication mechanisms are implemented to improve security, then computational resources required for configuration and maintenance increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs authentication actions preliminarily during the TLS handshake process itself. By integrating the authentication mechanism into the existing handshake protocol, the system establishes security credentials and identification parameters in advance, before actual data transmission begins. This preliminary authentication avoids the need for separate, resource-intensive authentication operations during data flow processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables the TLS protocol to self-authenticate by utilizing authentication parameters that are inherently generated and exchanged during the handshake process. The Client Random, Server Random, and derived cryptographic keys serve as self-contained authentication credentials that allow network devices to verify and identify encrypted streams without requiring external authentication infrastructure or additional computational overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11418951B2Method for identifying encrypted data stream, device, storage medium and system
Publication Date: 2022.08.16 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • US11418951B2 patent drawing
  • US11418951B2 patent drawing
  • US11418951B2 patent drawing

AI summary

A method for identifying an encrypted data stream, a device, a readable storage medium and a system are provided. The method includes: receiving a data packet carrying authentication data which is sent by a user equipment (UE), where the authentication data includes a first authentication parameter, a first authentication result and an application identifier; obtaining, based on the first authentication parameter and a second authentication parameter, a second authentication result according to a set authentication algorithm, where the second authentication parameter is a pre-stored authentication parameter corresponding to the application identifier; establishing an association relationship between characteristic information of the data packet and the application identifier when the second authentication result is consistent with the first authentication result in comparison, where the association relationship is used for subsequently identifying an encrypted data stream which is sent by the UE and corresponds to the application identifier.