Encrypted Tunnel Latency Measurement via Metadata Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Measuring network performance parameters like latency and jitter in encrypted communication tunnels is challenging, especially in secure networks, as injecting specific packets for measurement increases traffic and is not feasible in costly or constrained communication networks, and existing passive measurement methods are limited to specific protocols and host-to-host communication.

Innovation Solution

A method that estimates transmission time in encrypted communication tunnels by obtaining metadata from packets without decrypting them, using a processor to determine sequences of signature packets and calculate parameters like latency and jitter, applicable to traffic between sub-networks with multiple sessions, without increasing network traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If specific packets are injected to measure latency and jitter in encrypted communication tunnels, then measurement precision is improved, but network traffic increases and latency increases

Engineering Contradiction:
Improvelatency measurement accuracyVSAvoidnetwork traffic volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the necessary metadata fields (timestamp, packet size, source/destination addresses) from the packet headers without decrypting the entire payload. This allows latency measurement through packet sequence analysis while avoiding the need to inject additional measurement traffic, thus resolving the contradiction between measurement accuracy and network traffic volume.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses an intermediary measurement device positioned at network nodes that passively collects packet metadata and analyzes transmission time based on timestamp differences and packet sequencing. This intermediary approach enables accurate latency measurement without requiring active injection of test packets, thereby avoiding additional traffic burden on the encrypted tunnel.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If specific packets are injected to measure latency and jitter, then measurement precision is improved, but transmission time increases

Engineering Contradiction:
Improvelatency measurement accuracyVSAvoidtransmission time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent continuously monitors and records packet metadata timestamps in real-time as packets naturally traverse the encrypted tunnel. By maintaining continuous passive observation of packet arrival times and using timestamp differences to calculate latency, the system achieves accurate measurement without interrupting or delaying packet transmission, thus eliminating the trade-off between measurement accuracy and transmission time.

Inventive Principle:
Principle #20Continuity of useful action

3Quantity of substance

If passive measurement using user application packets is performed, then network traffic is not increased, but measurement is limited to specific protocols and host-to-host communication

Engineering Contradiction:
Improvenetwork traffic volumeVSAvoidprotocol and communication mode compatibility
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal measurement approach that works across multiple communication protocols (TCP, UDP, ICMP) and communication modes (host-to-host, host-to-network, network-to-network) by analyzing generic packet metadata fields. The measurement device can identify and process packets from different protocols based on their header structures, enabling versatile latency measurement in encrypted tunnels regardless of the underlying protocol or communication paradigm.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Quantity of substance

If metadata is obtained from packets without decrypting them, then network traffic is not increased and encryption security is maintained, but measurement complexity increases

Engineering Contradiction:
Improvenetwork traffic volumeVSAvoidmeasurement processing complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent segments the packet data into two distinct parts: unencrypted metadata fields (timestamp, packet size, source/destination addresses) that can be processed locally at network nodes, and encrypted payload data that remains protected. By analyzing only the segmented metadata portion for latency measurement, the system avoids the complexity of decrypting entire packets while maintaining measurement capability, thus resolving the contradiction between traffic volume and processing complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3664377B1Method and device for measuring a parameter representative of the transmission time on an encrypted tunnel
Publication Date: 2021.07.21 THALES SA

AI summary

The invention relates to a method and device for measuring a parameter representative of a transmission time in an encrypted communication tunnel adapted to transport encrypted data in packets over an open communications network, between a first and a second closed network, the transport implementing at least one transport protocol having an associated protocol signaling signature comprising a predetermined sequence of packets.The device includes a processor configured to implement, for each packet of a plurality of packets, a module for obtaining (26) without decrypting metadata associated with said packet; for at least one communication protocol, a module for determining (28, 34), from said metadata and stored characteristics (S(P)) of the packets forming part of the protocol signaling signature of said communication protocol, at least one sequence of packets capable of forming a protocol signaling signature, and an estimation module (36) of a parameter representative of a transmission time from at least one determined sequence of packets.