Obscuring Network Traffic Characteristics via Link Layer Padding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
As distributed computer systems become more complex and users prioritize information security, maintaining privacy of network traffic becomes increasingly challenging due to sophisticated unauthorized access attempts, despite existing encryption methods.
Innovation Solution
The solution involves encrypting and padding network traffic characteristics at the link layer, using a physical transceiver device to add variable-length padding and insert filler packets, making packet sizes appear random to observers, thereby obscuring traffic patterns and patterns of network packets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to network traffic, then information security is improved, but traffic characteristics such as packet size and timing patterns remain observable
Solution Approach 1:
The patent applies preliminary action by adding padding to packets before encryption and inserting filler packets before actual traffic transmission. This pre-processing ensures that traffic characteristics are obscured before observers can analyze the encrypted traffic patterns, addressing the limitation of standard encryption that leaves metadata visible.
Solution Approach 2:
The patent introduces filler packets as an intermediary element between the actual encrypted traffic and the network observers. These filler packets act as a mediator that masks the true traffic characteristics by creating artificial traffic patterns that observers cannot distinguish from legitimate traffic, thereby protecting the information security while hiding traffic metadata.
2Difficulty of detecting and measuring
If padding is added to packets to obscure size characteristics, then traffic pattern analysis is hindered, but network bandwidth utilization decreases
Solution Approach 1:
The patent applies local quality by adding variable-length padding to packets based on their individual characteristics and the specific security requirements of different traffic flows. Rather than uniformly padding all packets to maximum size, the system adjusts padding locally to provide adequate obfuscation while minimizing unnecessary bandwidth consumption.
Solution Approach 2:
The patent implements partial action by adding only the necessary amount of padding required to obscure traffic characteristics, rather than excessive padding that would waste bandwidth. The system calculates the minimum padding needed to prevent traffic analysis and applies only that amount, balancing security effectiveness with network efficiency.
3Reliability
If filler packets are inserted to mask traffic patterns, then observer ability to determine content is reduced, but network latency increases
Solution Approach 1:
The patent applies periodic action by inserting filler packets at regular intervals or based on periodic traffic patterns rather than continuously. This approach maintains privacy protection by ensuring sufficient masking of traffic characteristics while reducing the overall number of filler packets compared to continuous insertion, thereby minimizing latency.
Solution Approach 2:
The patent uses preliminary action by inserting filler packets in advance of actual traffic transmission to establish masked traffic patterns. By preparing the traffic stream with appropriate filler content before sensitive data transmission, the system achieves privacy protection without adding excessive latency during the critical data transfer phase.
Data Source
AI summary
The following description is directed to encrypting the characteristics of network traffic. In one example, a method can include receiving an unencrypted link layer packet including a first payload of a first size. The method can include encrypting the first payload of the unencrypted link layer packet. The method can include generating an encrypted link layer packet including a second payload. The second payload can include the encrypted payload and a variable length padding field so that the second payload of the encrypted link layer packet is a different size than the first size of the first payload. The encrypted link layer packet can then be transmitted.


