In-band Decryptor and Scanner for Encrypted Traffic Load Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing encrypted communication systems place a high load on servers due to the requirement that VPN clients must terminate at the server and client computers, preventing load distribution across multiple servers, as only the endpoints can decrypt data traffic, making it inefficient to manage load across a set of servers.

Innovation Solution

An in-band decryptor and scanner (IBDS) intercepts encrypted data traffic, using shared keys to decrypt and analyze packets without terminating the communication session, allowing it to reroute traffic to other devices or servers, thereby reducing the load on the primary server by performing decryption and processing tasks such as aggregation, security scanning, and compression.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VPN clients terminate at the server and client computers, then security is maintained through endpoint-only decryption, but server load increases and load distribution across multiple servers becomes impossible

Engineering Contradiction:
ImprovesecurityVSAvoidserver load
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary device positioned between the client and server that can decrypt and inspect encrypted VPN traffic without terminating the session. This intermediary acts as a mediator that maintains security while enabling load distribution, as it can process encrypted packets and forward them to appropriate servers without requiring the server itself to perform decryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If VPN clients terminate at the server, then direct encrypted communication is established, but load cannot be dynamically distributed to other servers

Engineering Contradiction:
Improvedirect connectionVSAvoidload distribution
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the VPN functionality into separate components: encryption/decryption, session management, and data processing. By separating these functions, the system allows encryption to occur at the client and intermediary while enabling flexible load distribution across multiple servers for the data processing function, thus achieving both direct connection security and adaptive load balancing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic load distribution by allowing the intermediary device to redirect encrypted traffic to different servers based on current server availability and load conditions. This dynamic routing capability enables the system to adapt to changing conditions while maintaining secure encrypted communication, resolving the contradiction between direct connection requirements and load distribution flexibility.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If multiple encrypted sessions are handled by a single server, then session management is simplified, but the server becomes a bottleneck

Engineering Contradiction:
Improvesession managementVSAvoidprocessing capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The intermediary device serves as a mediator that handles the complex task of decrypting and inspecting multiple encrypted sessions, then forwarding the decrypted traffic to appropriate servers. This separates the decryption function from the server, allowing multiple sessions to be processed in parallel across multiple servers while the intermediary manages the session complexity, thus eliminating the bottleneck without increasing server-side complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8601152B1In-band security protocol decryptor and scanner
Publication Date: 2013.12.03 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8601152B1 patent drawing
  • US8601152B1 patent drawing
  • US8601152B1 patent drawing

AI summary

An in-band decryptor and scanner (IBDS) for monitoring data packets or frames of an encrypted communication session. The IBDS may reroute or process the data packets or frames prior to reaching their destination. The IBDS may be used to decrease the load on a server by decrypting, preprocessing or rerouting the incoming data without altering the endpoints of the encrypted communication session from the server and a client.