In-Situ Network Telemetry Data Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In packet-switched networks, in-band OAM protocols face challenges in verifying the trustworthiness of in-situ network telemetry data due to its embedding within data traffic, making it difficult to distinguish fresh data from replayed or tampered telemetry information.
Innovation Solution
A method where network nodes encrypt and sign telemetry data using cryptographic keys, updating telemetry-data entries within data packets, allowing verification devices to decrypt and validate the data, ensuring the telemetry data is fresh and trustworthy by confirming its origin from the specific network node.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If in-situ network telemetry data is embedded in data traffic using in-band OAM protocols, then monitoring and management of network health and performance is enabled, but the trustworthiness of the telemetry data cannot be verified due to difficulty in distinguishing fresh data from replayed or tampered information
Solution Approach 1:
The patent applies preliminary action by having network nodes sign telemetry data with cryptographic keys before embedding it in data packets. This advance authentication ensures that when the telemetry data is extracted and verified at the destination, its authenticity and freshness can be confirmed without requiring complex real-time verification mechanisms. The signing operation is performed in advance during packet transmission, resolving the contradiction between ensuring reliability and avoiding verification complexity.
2Reliability
If cryptographic signing is applied to telemetry data, then authenticity and freshness of data are validated, but processing overhead and computational requirements increase
Solution Approach 1:
The patent applies local quality by selectively signing only the critical telemetry data fields that require authentication, rather than encrypting or signing entire data packets. This targeted approach focuses computational resources on the specific portions of data that need verification, reducing overall processing overhead and energy consumption while maintaining the reliability of the authenticated fields.
3Productivity
If telemetry data is embedded within data packets, then in-band monitoring is achieved, but the data cannot be distinguished from replayed or tampered information
Solution Approach 1:
The patent introduces cryptographic signatures as an intermediary mechanism between the telemetry data generation and verification processes. These signatures act as mediators that carry authenticity information along with the embedded telemetry data in packets. When data is extracted for monitoring, the signatures enable verification of whether the data is fresh and un tampered, resolving the contradiction between efficient in-band monitoring and maintaining data integrity.
Data Source
AI summary
Techniques to facilitate verification of in-situ network telemetry data of data packet of data traffic of packet-switched networks are described herein. A technique described herein includes a network node obtaining a data packet of data traffic of a packet-switched network. The data packet includes an in-situ network telemetry block. The network node obtains telemetry data and cryptographic key. The cryptographic key confidentially identifies the network node. The node encrypts at least a portion of the telemetry data based on the cryptographic key to produce signed telemetry data and updates telemetry-data entry of the in-situ network telemetry block. The telemetry data and signed telemetry data is inserted into the telemetry-data entry. The node forwards the data packet with the updated telemetry-data entry to another network node of the packet-switched network.


