In-Service Encryption Verification via Test Packet Injection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encryption hardware in cloud infrastructure data center interconnect solutions is not effectively tested during service, leading to potential unnoticed issues that can compromise encryption and data integrity.

Innovation Solution

Implementing a method for in-service encryption verification by injecting test data packets into the data stream with client data packets, using separate security parameters, and verifying the encryption process to ensure proper functioning of the encryption device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-service testing methods (KATs or on-chip self-tests) are used to test encryption hardware, then testing capability is provided, but the ability to test during service in active data plane is lost

Engineering Contradiction:
Improveencryption hardware reliabilityVSAvoidin-service testing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring test data packets with known plaintext and expected ciphertext values before service deployment. These test packets are embedded in the encryption hardware and automatically injected into the data plane during runtime, enabling continuous verification without requiring separate testing phases or interrupting service operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption hardware performs self-verification by comparing its actual encryption output against pre-stored expected results for test packets. This self-service mechanism allows the hardware to autonomously detect encryption failures or deviations without external testing equipment, maintaining continuous operation while ensuring reliability.

Inventive Principle:
Principle #25Self-service

2Reliability

If test data packets are injected into the data stream with client data packets, then continuous testing is enabled, but bandwidth or data integrity may be affected

Engineering Contradiction:
Improveencryption verification continuityVSAvoidbandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by designing test packets with specialized characteristics that distinguish them from client data packets. Test packets use specific packet types or markers that trigger dedicated handling paths in the encryption hardware, allowing them to be processed with appropriate security parameters without interfering with the encryption of regular client data. This localized treatment ensures test packets can be injected and verified without reducing overall bandwidth or affecting client data integrity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11425147B2In-service data plane encryption verification
Publication Date: 2022.08.23 ORACLE INT CORP
  • US11425147B2 patent drawing
  • US11425147B2 patent drawing
  • US11425147B2 patent drawing

AI summary

A method of executing in-session encryption verification includes receiving a plurality of client data packets for transmission through a network; receiving one or more test data packets for verifying an encryption device; merging the client data packets and the one or more test packets into a data stream; selecting security parameters for each packet in the data stream based on a corresponding packet type; encrypting each packet in the data stream using the encryption device and the corresponding security parameters; and transmitting the data stream comprising encrypted packets through the network. The method also includes decrypting the encrypted packets at a receiving system using congruent techniques.