Order-Preserving Encryption for Network Traffic Timestamps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Publicly available network traffic traces are rare due to concerns over privacy and confidentiality, and existing methods for analyzing network logs lack adequate security and privacy measures, making it difficult for ISPs and organizations to share data while ensuring protection of sensitive information.

Innovation Solution

The implementation of encryption and anonymization techniques that preserve useful information such as IP address prefixes, timestamp orders, and URLs, allowing for secure analytics to be performed on encrypted data without decryption, using order-preserving encryption for timestamps and format-preserving encryption for URLs and IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network traffic traces are made publicly available for analysis, then research and development can benefit from real-world data, but privacy and confidentiality of sensitive information may be compromised

Engineering Contradiction:
Improveavailability of network traffic tracesVSAvoidprivacy and confidentiality risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encryption system as an intermediary between the network traffic traces and the analysts. The encryption layer transforms sensitive data into ciphertext while preserving analytical utility, allowing traces to be made available for research without exposing private information. The system uses order-preserving encryption and format-preserving encryption to maintain data usefulness while protecting confidentiality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of the data from plaintext to encrypted form, transforming sensitive information into a protected representation. By applying cryptographic transformations, the system modifies the data parameters (from readable to encrypted) while preserving the structural properties needed for analysis, thus resolving the contradiction between availability and privacy protection.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If network logs are stored in encrypted format to protect privacy, then security and confidentiality are improved, but analytics and analysis capabilities are reduced

Engineering Contradiction:
Improveprivacy protectionVSAvoidanalytics capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies encryption transformations to the network traffic traces before they are stored or analyzed. By pre-processing the data with order-preserving encryption and format-preserving encryption, the system ensures that when analysts access the data, it is already in a form that maintains analytical utility. This preliminary encryption action enables both privacy protection and analytics capability to coexist.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption system acts as an intermediary that preserves analytical capabilities while protecting privacy. The specific encryption methods used (order-preserving and format-preserving) maintain the structural properties of the data needed for analytics, allowing researchers to perform meaningful analysis on encrypted data without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is applied to all network traffic data, then security is improved, but the ability to perform efficient analysis and simulation is reduced

Engineering Contradiction:
Improvesecurity guaranteeVSAvoidanalysis efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different encryption approaches to different parts of the network traffic data based on their analytical requirements. Order-preserving encryption is used for timestamp fields where temporal relationships are important, while format-preserving encryption is used for other fields. This localized application of encryption methods maintains analysis efficiency for specific data types while providing security guarantees.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies encryption selectively to specific fields and properties of the network traffic traces rather than encrypting all data uniformly. By encrypting only the necessary fields with appropriate encryption methods, the system achieves adequate security protection while minimizing the impact on analysis efficiency and maintaining the usability of non-sensitive data.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10878122B2Timestamp order-preserving encryption of network traffic traces
Publication Date: 2020.12.29 MICRO FOCUS LLC
  • US10878122B2 patent drawing
  • US10878122B2 patent drawing
  • US10878122B2 patent drawing

AI summary

According to examples, an apparatus may include a processor and a memory on which is stored machine readable instructions to cause the processor to access network traffic traces including a plurality of timestamps, the plurality of timestamps having an order with respect to each other. The instructions may also cause the processor to encrypt the plurality of timestamps to anonymize the plurality of timestamps while preserving the order of the plurality of timestamps with respect to each other and to store the encrypted plurality of timestamps in a data store.