Group VPN Key Management for Encrypted Traffic Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network devices such as intrusion detection systems and firewalls cannot effectively perform their functions on encrypted traffic flows, as they often rely on unencrypted parts of packets for decision-making, limiting their functionality.

Innovation Solution

An apparatus and method that utilize a membership logic to control membership in a group key system, allowing devices to request and receive a set of keys and roles, enabling them to process secure network traffic by inspecting, rewriting, or validating it based on these keys, including decryption and authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network devices process encrypted traffic without decryption keys, then network security inspection functionality is maintained, but the ability to inspect and analyze encrypted payload is lost

Engineering Contradiction:
Improvenetwork security inspection functionalityVSAvoidability to inspect encrypted payload
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a key management system as an intermediary between network devices and encrypted traffic. The system issues decryption keys to authorized devices, enabling them to inspect encrypted payloads while maintaining security. The key management system mediates the balance between security inspection capabilities and encryption protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network devices obtain decryption keys to inspect encrypted traffic, then the ability to analyze encrypted payload is improved, but security control and authorization complexity increases

Engineering Contradiction:
Improveability to inspect encrypted payloadVSAvoidsecurity control and authorization
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key management system implements feedback mechanisms where network devices request keys based on their security policies and traffic inspection needs. The system evaluates these requests, grants appropriate keys, and monitors their usage. This feedback loop enables dynamic key distribution that adapts to changing security requirements without requiring complex manual authorization.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If network devices use only unencrypted packet parts for forwarding decisions, then encryption security is maintained, but forwarding decision accuracy is limited

Engineering Contradiction:
Improveencryption securityVSAvoidforwarding decision accuracy
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The system performs preliminary decryption of encrypted payloads before forwarding decisions are made. Network devices use decryption keys to decrypt traffic, inspect the full payload content for accurate classification and routing decisions, then re-encrypt the traffic before forwarding. This preliminary action enables precise forwarding decisions while maintaining end-to-end encryption security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8347073B2Inspection and rewriting of cryptographically protected data from group VPNs
Publication Date: 2013.01.01 CISCO TECHNOLOGY INC
  • US8347073B2 patent drawing
  • US8347073B2 patent drawing
  • US8347073B2 patent drawing

AI summary

Systems, methods, and other embodiments associated with processing secure network traffic are described. One example method includes determining whether a device is a preconfigured member of a group key system. If the device is not a preconfigured member then the method selectively establishes membership in the group key system by requesting membership from a group controller. The example method may also include receiving a set of keys from the group controller and being assigned a role by the group controller. The method may further include processing secure network traffic as an inspection point, a rewriting point, and/or a validation point based on the received set of keys and the assigned role(s).