Multi-path Router Encrypted Tunnel Routing Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Tunneling protocols prevent intermediate routers from applying unique routing rules to encrypted data packets, as the data contents are only intelligible at the endpoints, limiting the ability to optimize communication paths based on data type or source.
Innovation Solution
A method and system that generate a unique identifier for encrypted data packets, allowing a multi-path router to establish and apply routing rules based on this identifier, enabling data to be directed along specific communication paths based on data type or source, even if the data contents are unintelligible to the router.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data packets are encrypted for secure transmission through a tunnel, then security is improved, but the ability to apply unique routing rules at intermediate routers is lost
Solution Approach 1:
The encrypted data packet is segmented into multiple components: an encrypted payload portion and an unencrypted header portion. The header contains a unique identifier that is visible to intermediate routers, while the payload remains encrypted. This segmentation allows routers to apply routing rules based on the header information without compromising the security of the actual data content.
Solution Approach 2:
A unique identifier acts as an intermediary element between the encrypted data and the routing system. This identifier is included in the packet header and is readable by intermediate routers, enabling them to apply routing rules without needing to decrypt or understand the actual data content. The identifier mediates between the security requirement (encrypted payload) and the routing requirement (readable header).
2Reliability
If all data packets are treated uniformly without visible identifiers, then security is maintained, but transmission efficiency and path optimization are reduced
Solution Approach 1:
The packet structure is segmented into a security-protected encrypted payload and a routing-optimized unencrypted header. The header contains unique identifiers that enable efficient routing decisions, while the payload maintains security through encryption. This allows parallel optimization of both security and transmission efficiency.
Solution Approach 2:
Different portions of the data packet are treated with different quality requirements: the header portion is kept unencrypted with high visibility for routing optimization, while the payload portion is encrypted with high security for data protection. This local differentiation of quality attributes allows simultaneous achievement of efficiency and security goals.
Data Source
AI summary
The present disclosure is directed to a system and method for applying unique routing rules to encrypted data packets being transmitted via a tunneling protocol. Because encrypted data packets are unintelligible at intermediary points along a secured link or “tunnel,” a multi-path router located between the tunnel endpoints is typically unable to apply unique routing rules. To enable unique routing, the disclosed method relies on a unique identifier that is associated with the secured link established between an initiator and a receiver (i.e., the tunnel endpoints). The unique identifier is transmitted with one or more encrypted data packets and is used at intermediary points to differentiate the encrypted data packets so that unique routing rules can be applied.


