In-Service Encryption Verification via Test Packet Injection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption hardware in cloud infrastructure data center interconnect solutions is not effectively tested during service, leading to potential unnoticed issues that can compromise encryption and data integrity.
Innovation Solution
Implementing a method for in-service encryption verification by injecting test data packets into the data stream with client data packets, using separate security parameters, and verifying the encryption process to ensure proper functioning of the encryption device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-service testing methods (KATs or on-chip self-tests) are used to test encryption hardware, then testing capability is provided, but the ability to test during service in active data plane is lost
Solution Approach 1:
The patent applies preliminary action by pre-configuring test data packets with known plaintext and expected ciphertext values before service deployment. These test packets are embedded in the encryption hardware and automatically injected into the data plane during runtime, enabling continuous verification without requiring separate testing phases or interrupting service operations.
Solution Approach 2:
The encryption hardware performs self-verification by comparing its actual encryption output against pre-stored expected results for test packets. This self-service mechanism allows the hardware to autonomously detect encryption failures or deviations without external testing equipment, maintaining continuous operation while ensuring reliability.
2Reliability
If test data packets are injected into the data stream with client data packets, then continuous testing is enabled, but bandwidth or data integrity may be affected
Solution Approach 1:
The patent applies local quality by designing test packets with specialized characteristics that distinguish them from client data packets. Test packets use specific packet types or markers that trigger dedicated handling paths in the encryption hardware, allowing them to be processed with appropriate security parameters without interfering with the encryption of regular client data. This localized treatment ensures test packets can be injected and verified without reducing overall bandwidth or affecting client data integrity.
Data Source
AI summary
A method of executing in-session encryption verification includes receiving a plurality of client data packets for transmission through a network; receiving one or more test data packets for verifying an encryption device; merging the client data packets and the one or more test packets into a data stream; selecting security parameters for each packet in the data stream based on a corresponding packet type; encrypting each packet in the data stream using the encryption device and the corresponding security parameters; and transmitting the data stream comprising encrypted packets through the network. The method also includes decrypting the encrypted packets at a receiving system using congruent techniques.


