Network Service Zone Locking for Cryptographic Audit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of cryptographic protocols and standards in network traffic makes it difficult for system developers and administrators to understand and ensure the actual security levels achieved in real-world systems, particularly in networks with increasing volumes and varieties of application traffic.

Innovation Solution

A mechanism is introduced to develop a policy model that identifies and enforces cryptographic security policies between network zones by analyzing traffic flows, triggering mitigation actions when unacceptable cryptographic communication is detected, using a service that captures and evaluates traffic flow data for compliance with inter-zone policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic protocols and standards are implemented in network traffic, then security level is improved, but complexity of understanding and verifying security levels worsens

Engineering Contradiction:
Improvesecurity levelVSAvoidcomplexity of cryptographic protocols
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network service that acts as an intermediary between network traffic and security policy enforcement. This service captures traffic flow data, identifies cryptographic parameters, and determines compliance with inter-zone policies, thereby simplifying the complexity of cryptographic verification for system administrators while maintaining high security levels

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms by monitoring cryptographic parameters in real-time network traffic and automatically enforcing inter-zone policies. The network service continuously evaluates traffic flow data against defined policies and triggers mitigation actions when compliance violations are detected, creating a closed-loop security verification system

Inventive Principle:
Principle #23Feedback

2Reliability

If network security policies are implemented to control application traffic, then security compliance is improved, but difficulty of managing diverse traffic flows worsens

Engineering Contradiction:
Improvesecurity complianceVSAvoiddifficulty of managing traffic flows
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the network into distinct zones with defined security policies. By dividing network traffic into zone-based segments and applying specific inter-zone policies to each segment, the system simplifies the management of diverse traffic flows while maintaining comprehensive security compliance across the entire network

Inventive Principle:
Principle #1Segmentation

3Reliability

If cryptographic parameters are monitored and enforced, then security policy compliance is improved, but computational overhead worsens

Engineering Contradiction:
Improvepolicy complianceVSAvoidcomputational overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The network service implements partial monitoring by focusing specifically on identifying and evaluating cryptographic parameters in traffic flow data rather than analyzing all aspects of network traffic. This selective approach ensures policy compliance while minimizing unnecessary computational overhead

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11888900B2Cryptographic security audit using network service zone locking
Publication Date: 2024.01.30 CISCO TECHNOLOGY INC
  • US11888900B2 patent drawing
  • US11888900B2 patent drawing
  • US11888900B2 patent drawing

AI summary

In one embodiment, a service receives captured traffic flow data regarding a traffic flow sent via a network between a first device assigned to a first network zone and a second device assigned to a second network zone. The service identifies, from the captured traffic flow data, one or more cryptographic parameters of the traffic flow. The service determines whether the one or more cryptographic parameters of the traffic flow satisfy an inter-zone policy associated with the first and second network zones. The service causes performance of a mitigation action in the network when the one or more cryptographic parameters of the traffic flow do not satisfy the inter-zone policy associated with the first and second network zones.