In-Situ Network Telemetry Data Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In packet-switched networks, in-band OAM protocols face challenges in verifying the trustworthiness of in-situ network telemetry data due to its embedding within data traffic, making it difficult to distinguish fresh data from replayed or tampered telemetry information.

Innovation Solution

A method where network nodes encrypt and sign telemetry data using cryptographic keys, updating telemetry-data entries within data packets, allowing verification devices to decrypt and validate the data, ensuring the telemetry data is fresh and trustworthy by confirming its origin from the specific network node.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If in-situ network telemetry data is embedded in data traffic using in-band OAM protocols, then monitoring and management of network health and performance is enabled, but the trustworthiness of the telemetry data cannot be verified due to difficulty in distinguishing fresh data from replayed or tampered information

Engineering Contradiction:
Improvetrustworthiness of telemetry dataVSAvoidcomplexity of verification mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having network nodes sign telemetry data with cryptographic keys before embedding it in data packets. This advance authentication ensures that when the telemetry data is extracted and verified at the destination, its authenticity and freshness can be confirmed without requiring complex real-time verification mechanisms. The signing operation is performed in advance during packet transmission, resolving the contradiction between ensuring reliability and avoiding verification complexity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If cryptographic signing is applied to telemetry data, then authenticity and freshness of data are validated, but processing overhead and computational requirements increase

Engineering Contradiction:
Improvevalidation of data authenticityVSAvoidcomputational energy for encryption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by selectively signing only the critical telemetry data fields that require authentication, rather than encrypting or signing entire data packets. This targeted approach focuses computational resources on the specific portions of data that need verification, reducing overall processing overhead and energy consumption while maintaining the reliability of the authenticated fields.

Inventive Principle:
Principle #3Local quality

3Productivity

If telemetry data is embedded within data packets, then in-band monitoring is achieved, but the data cannot be distinguished from replayed or tampered information

Engineering Contradiction:
Improveefficiency of network monitoringVSAvoidintegrity of telemetry data
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces cryptographic signatures as an intermediary mechanism between the telemetry data generation and verification processes. These signatures act as mediators that carry authenticity information along with the embedded telemetry data in packets. When data is extracted for monitoring, the signatures enable verification of whether the data is fresh and un tampered, resolving the contradiction between efficient in-band monitoring and maintaining data integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11979412B2Verification of in-situ network telemetry data in a packet-switched network
Publication Date: 2024.05.07 CISCO TECHNOLOGY INC
  • US11979412B2 patent drawing
  • US11979412B2 patent drawing
  • US11979412B2 patent drawing

AI summary

Techniques to facilitate verification of in-situ network telemetry data of data packet of data traffic of packet-switched networks are described herein. A technique described herein includes a network node obtaining a data packet of data traffic of a packet-switched network. The data packet includes an in-situ network telemetry block. The network node obtains telemetry data and cryptographic key. The cryptographic key confidentially identifies the network node. The node encrypts at least a portion of the telemetry data based on the cryptographic key to produce signed telemetry data and updates telemetry-data entry of the in-situ network telemetry block. The telemetry data and signed telemetry data is inserted into the telemetry-data entry. The node forwards the data packet with the updated telemetry-data entry to another network node of the packet-switched network.