Packet Sequence Watermarking for Encrypted Network Entity Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying a unique network entity's MAC address is challenging, especially in encrypted networks, as IP addresses are not unique and can change, and existing methods require resource-intensive packet inspection or low-level access, which may not be feasible.

Innovation Solution

Encoding watermarks into packet sequences by modifying properties such as packet size, inter-arrival times, or data rates, allowing for passive sniffing to identify the MAC address without decrypting packets or requiring low-level access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If packet inspection is used to map IP address to MAC address, then unique identification of network entity is achieved, but resource consumption increases significantly

Engineering Contradiction:
Improveidentification accuracyVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent embeds watermarks in packet sequences before transmission, creating pre-prepared identification markers that can be detected without intensive inspection. This preliminary encoding allows later identification to occur with minimal resource consumption while maintaining accurate MAC address mapping.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces watermarks as an intermediary element between the packet data and the identification process. These watermarks serve as mediators that carry identification information without requiring deep inspection of the encrypted packet contents, thus reducing resource consumption while enabling accurate identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If packet inspection is used to identify MAC address, then unique identification is achieved, but the method does not work in encrypted networks

Engineering Contradiction:
Improveidentification accuracyVSAvoidencrypted network compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent segments the identification function from the packet inspection function. Instead of inspecting packet contents to identify MAC addresses, the system uses separate watermark markers embedded in the packet sequence. This segmentation allows identification to work independently of packet encryption, enabling operation in encrypted networks while maintaining identification accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Watermarks serve as intermediaries that bridge the gap between encrypted packet transmission and MAC address identification. These markers carry identification information in a form that can be detected without decrypting the packets, thus enabling identification in encrypted networks while maintaining accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If querying the network entity is used to obtain MAC address, then unique identification is achieved, but application permissions are required

Engineering Contradiction:
Improveidentification accuracyVSAvoidpermission requirement
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements self-service identification where the network entity effectively identifies itself through the embedded watermarks in its transmitted packets. This eliminates the need for external querying and permission acquisition, as the identification information is passively available in the packet stream without requiring the application to request or be granted special permissions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Watermarks act as intermediaries that carry identification information from the network entity to the observing application without requiring direct interaction or permission exchanges. This intermediary mechanism enables identification to occur passively, eliminating the need for querying and permission requirements while maintaining accurate identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If low-level access is used to identify MAC address, then unique identification is achieved, but device complexity increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidaccess level requirement
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses watermark copying as a simplified alternative to low-level access. Instead of requiring direct access to network entity identifiers through complex low-level interfaces, the system copies identification information into detectable watermark forms within the packet stream. This copying approach maintains identification accuracy while eliminating the need for complex low-level access mechanisms.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

Watermarks serve as intermediaries that translate the need for low-level access into a high-level detectable signal. Rather than requiring applications to access low-level system interfaces, the watermark intermediary makes identification information available through standard packet observation, thus maintaining accuracy while reducing device complexity and access requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2795850B1Modifying a property of a sequence of sent packets to uniquely identify an entity on a network such as an encrypted network
Publication Date: 2016.08.10 NOKIA TECHNOLOGIES OY
  • EP2795850B1 patent drawingFigure 1
  • EP2795850B1 patent drawingFigure 2
  • EP2795850B1 patent drawingFigure 3

AI summary

A method includes sending over the network from a source entity to a destination entity a sequence of a plurality of packets. Each packet in the sequence includes a same identifier corresponding to a network entity on the network. Sending includes modifying a property of the sequence of packets to uniquely identify the sequence of packets. The method includes receiving information indicating the identifier corresponds to the modification of the property. Another method includes examining a sequence of packets sent over a network from a source entity to a destination entity, each packet in the sequence comprising a same identifier corresponding to a network entity on the network. The method includes determining whether a property of the sequence of packets was modified when sent to uniquely identify the sequence of packets; and responsive to the determining, associating the identifier with the network identity. Apparatus and program products are also disclosed.