Order-Preserving Encryption for Network Traffic Timestamps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Publicly available network traffic traces are rare due to concerns over privacy and confidentiality, and existing methods for analyzing network logs lack adequate security and privacy measures, making it difficult for ISPs and organizations to share data while ensuring protection of sensitive information.
Innovation Solution
The implementation of encryption and anonymization techniques that preserve useful information such as IP address prefixes, timestamp orders, and URLs, allowing for secure analytics to be performed on encrypted data without decryption, using order-preserving encryption for timestamps and format-preserving encryption for URLs and IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network traffic traces are made publicly available for analysis, then research and development can benefit from real-world data, but privacy and confidentiality of sensitive information may be compromised
Solution Approach 1:
The patent introduces an encryption system as an intermediary between the network traffic traces and the analysts. The encryption layer transforms sensitive data into ciphertext while preserving analytical utility, allowing traces to be made available for research without exposing private information. The system uses order-preserving encryption and format-preserving encryption to maintain data usefulness while protecting confidentiality.
Solution Approach 2:
The patent changes the state of the data from plaintext to encrypted form, transforming sensitive information into a protected representation. By applying cryptographic transformations, the system modifies the data parameters (from readable to encrypted) while preserving the structural properties needed for analysis, thus resolving the contradiction between availability and privacy protection.
2Object-affected harmful factors
If network logs are stored in encrypted format to protect privacy, then security and confidentiality are improved, but analytics and analysis capabilities are reduced
Solution Approach 1:
The patent applies encryption transformations to the network traffic traces before they are stored or analyzed. By pre-processing the data with order-preserving encryption and format-preserving encryption, the system ensures that when analysts access the data, it is already in a form that maintains analytical utility. This preliminary encryption action enables both privacy protection and analytics capability to coexist.
Solution Approach 2:
The encryption system acts as an intermediary that preserves analytical capabilities while protecting privacy. The specific encryption methods used (order-preserving and format-preserving) maintain the structural properties of the data needed for analytics, allowing researchers to perform meaningful analysis on encrypted data without compromising security.
3Reliability
If encryption is applied to all network traffic data, then security is improved, but the ability to perform efficient analysis and simulation is reduced
Solution Approach 1:
The patent applies different encryption approaches to different parts of the network traffic data based on their analytical requirements. Order-preserving encryption is used for timestamp fields where temporal relationships are important, while format-preserving encryption is used for other fields. This localized application of encryption methods maintains analysis efficiency for specific data types while providing security guarantees.
Solution Approach 2:
The patent applies encryption selectively to specific fields and properties of the network traffic traces rather than encrypting all data uniformly. By encrypting only the necessary fields with appropriate encryption methods, the system achieves adequate security protection while minimizing the impact on analysis efficiency and maintaining the usability of non-sensitive data.
Data Source
AI summary
According to examples, an apparatus may include a processor and a memory on which is stored machine readable instructions to cause the processor to access network traffic traces including a plurality of timestamps, the plurality of timestamps having an order with respect to each other. The instructions may also cause the processor to encrypt the plurality of timestamps to anonymize the plurality of timestamps while preserving the order of the plurality of timestamps with respect to each other and to store the encrypted plurality of timestamps in a data store.


