Verifiable Network Traffic via L2 Frame HMAC Timestamps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions fail to effectively detect evidence of tampering in network traffic data, particularly in electronic trading markets, where falsified records can undermine market stability and regulatory compliance.
Innovation Solution
A method and system for generating and authenticating verifiable network traffic by augmenting Layer-2 (L2) frames with timestamp trailers containing hash-based message authentication codes (HMAC) and timestamps, using a frame signer and auditor to ensure data integrity and authenticity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If network traffic data is transmitted without authentication mechanisms, then transmission speed and simplicity are improved, but data integrity and reliability deteriorate
Solution Approach 1:
The patent applies preliminary action by computing HMAC authentication codes and appending timestamp trailers to L2 frames before transmission. This pre-authentication approach ensures data integrity is verified in advance, allowing receiving systems to process authenticated frames without requiring complex real-time verification, thus maintaining transmission speed while ensuring reliability.
Solution Approach 2:
The patent introduces HMAC (hash-based message authentication code) as an intermediary mechanism. The HMAC acts as a mediator between the transmitted data and the verification process, providing cryptographic proof of authenticity without requiring the transmitting and receiving parties to share secret keys, thus enabling reliable verification while maintaining transmission efficiency.
2Reliability
If HMAC authentication is implemented for all network frames, then data authenticity is improved, but computational overhead and processing time worsen
Solution Approach 1:
The patent applies partial action by implementing authentication selectively rather than uniformly for all frames. The system can choose to authenticate only critical frames or use different authentication levels based on frame importance, reducing overall processing overhead while maintaining security for essential data transmissions.
Solution Approach 2:
The patent utilizes parameter changes by employing hash-based authentication (HMAC) instead of traditional symmetric or asymmetric cryptographic methods. This parameter change in the authentication mechanism provides comparable security with reduced computational requirements, thereby decreasing processing time while maintaining data authenticity verification.
3Measurement precision
If timestamp trailers are appended to L2 frames, then tampering detection capability is improved, but frame size and network bandwidth consumption worsen
Solution Approach 1:
The patent applies segmentation by dividing the authentication data into separate timestamp trailer components that are appended to L2 frames. This segmentation allows the authentication information to be processed independently from the main frame data, enabling efficient verification without requiring the entire frame to be reprocessed, thus improving tampering detection while minimizing the impact on frame size.
4Reliability
If traditional authentication methods are used, then security is improved, but device complexity and implementation difficulty worsen
Solution Approach 1:
The patent replaces complex cryptographic mechanical systems with hash-based authentication. Instead of using traditional symmetric or asymmetric encryption mechanisms that require key management, certificate validation, and complex cryptographic operations, the system uses HMAC which relies on simpler hash functions, thereby reducing device complexity and implementation difficulty while maintaining security.
Data Source
AI summary
System and methods for generating and authenticating verifiable network traffic. Specifically, the system and methods disclosed herein describe solutions for augmenting layer-2 (L2) frames with additional verifiable information entailing, for example, hash-based message authentication code encryption or digital signature authentication. These solutions may address scenarios where evidence of tampering, through deceptive practices, of network traffic data may prove difficult to detect.


