Verifiable Network Traffic via L2 Frame HMAC Timestamps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions fail to effectively detect evidence of tampering in network traffic data, particularly in electronic trading markets, where falsified records can undermine market stability and regulatory compliance.

Innovation Solution

A method and system for generating and authenticating verifiable network traffic by augmenting Layer-2 (L2) frames with timestamp trailers containing hash-based message authentication codes (HMAC) and timestamps, using a frame signer and auditor to ensure data integrity and authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If network traffic data is transmitted without authentication mechanisms, then transmission speed and simplicity are improved, but data integrity and reliability deteriorate

Engineering Contradiction:
Improvetransmission speedVSAvoiddata integrity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent applies preliminary action by computing HMAC authentication codes and appending timestamp trailers to L2 frames before transmission. This pre-authentication approach ensures data integrity is verified in advance, allowing receiving systems to process authenticated frames without requiring complex real-time verification, thus maintaining transmission speed while ensuring reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces HMAC (hash-based message authentication code) as an intermediary mechanism. The HMAC acts as a mediator between the transmitted data and the verification process, providing cryptographic proof of authenticity without requiring the transmitting and receiving parties to share secret keys, thus enabling reliable verification while maintaining transmission efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If HMAC authentication is implemented for all network frames, then data authenticity is improved, but computational overhead and processing time worsen

Engineering Contradiction:
Improvedata authenticityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by implementing authentication selectively rather than uniformly for all frames. The system can choose to authenticate only critical frames or use different authentication levels based on frame importance, reducing overall processing overhead while maintaining security for essential data transmissions.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent utilizes parameter changes by employing hash-based authentication (HMAC) instead of traditional symmetric or asymmetric cryptographic methods. This parameter change in the authentication mechanism provides comparable security with reduced computational requirements, thereby decreasing processing time while maintaining data authenticity verification.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If timestamp trailers are appended to L2 frames, then tampering detection capability is improved, but frame size and network bandwidth consumption worsen

Engineering Contradiction:
Improvetampering detection capabilityVSAvoidframe size
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies segmentation by dividing the authentication data into separate timestamp trailer components that are appended to L2 frames. This segmentation allows the authentication information to be processed independently from the main frame data, enabling efficient verification without requiring the entire frame to be reprocessed, thus improving tampering detection while minimizing the impact on frame size.

Inventive Principle:
Principle #1Segmentation

4Reliability

If traditional authentication methods are used, then security is improved, but device complexity and implementation difficulty worsen

Engineering Contradiction:
ImprovesecurityVSAvoidimplementation difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex cryptographic mechanical systems with hash-based authentication. Instead of using traditional symmetric or asymmetric encryption mechanisms that require key management, certificate validation, and complex cryptographic operations, the system uses HMAC which relies on simpler hash functions, thereby reducing device complexity and implementation difficulty while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11277269B2System and methods for generating and authenticating verifiable network traffic
Publication Date: 2022.03.15 ARISTA NETWORKS INC
  • US11277269B2 patent drawing
  • US11277269B2 patent drawing
  • US11277269B2 patent drawing

AI summary

System and methods for generating and authenticating verifiable network traffic. Specifically, the system and methods disclosed herein describe solutions for augmenting layer-2 (L2) frames with additional verifiable information entailing, for example, hash-based message authentication code encryption or digital signature authentication. These solutions may address scenarios where evidence of tampering, through deceptive practices, of network traffic data may prove difficult to detect.