Precalculated Cryptography Data for SSL Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Testing packet switched networks and devices that perform deep packet inspection (DPI) requires establishing a large number of SSL/TLS connections, which is processing-intensive, especially when decrypting pre-master secrets, limiting the rate at which SSL connections can be established.
Innovation Solution
The use of pre-computed cryptography data (PCCD) sets stored in memory within port units to simulate SSL connections without actual encryption or decryption processing, allowing for the establishment of multiple secure connections that appear secure to network devices but are not actually secure, thereby reducing processing load.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If real SSL/TLS connections are established for testing network devices performing DPI, then the testing accuracy and reliability are improved, but the processing load and time required increase significantly
Solution Approach 1:
The patent pre-calculates and stores encrypted pre-master secrets and master secrets in lookup tables before the actual testing begins. During testing, these pre-computed cryptographic values are retrieved directly from memory rather than performing real-time encryption and decryption operations, thereby reducing the time required to establish SSL/TLS connections while maintaining testing accuracy.
Solution Approach 2:
The patent creates simulated SSL connections that replicate the appearance of real secure connections without actually performing the full encryption and decryption process. By using pre-computed cryptographic data stored in memory, the system generates fake encrypted traffic that looks authentic to network devices performing DPI, thereby reducing processing load while maintaining testing reliability.
2Reliability
If real encryption and decryption operations are performed during SSL connection establishment, then the authenticity of tested connections is improved, but the processing intensity and computational resources required increase
Solution Approach 1:
The patent performs all encryption and decryption calculations beforehand, storing the results in lookup tables. During actual testing, the system only retrieves pre-computed values from memory rather than performing computationally intensive cryptographic operations in real-time, thereby reducing processing load while maintaining connection authenticity.
Solution Approach 2:
The patent creates simulated SSL connections that copy the appearance and behavior of real secure connections without actually executing the full encryption and decryption process. By using pre-computed cryptographic values stored in memory, the system generates authentic-looking traffic patterns while significantly reducing computational resource requirements.
3Productivity
If a large number of SSL connections are established rapidly for comprehensive network testing, then the testing coverage and effectiveness are improved, but the cryptographic processing requirements and system resources increase
Solution Approach 1:
The patent pre-computes cryptographic values for multiple SSL connections and stores them in lookup tables before testing begins. This allows the system to rapidly establish numerous SSL connections during testing by simply retrieving pre-computed values from memory rather than performing expensive cryptographic operations for each connection, thereby increasing testing throughput while reducing per-connection processing requirements.
Solution Approach 2:
The patent creates multiple simulated SSL connections that replicate authentic secure connection behavior without actually performing full encryption and decryption for each one. By using pre-computed cryptographic data stored in memory, the system can rapidly generate a large number of authentic-looking connections, significantly improving testing coverage and throughput while reducing overall cryptographic processing requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and computer readable storage media to test secure network connections. One or more pre-calculated encryption data (PCCD) sets may be defined in accordance with a secure communications protocol. The one or more PCCD sets may be stored in a first PCCD memory and a second PCCD memory located respectively within a first port unit and a second port unit of a plurality of port units. Each PCCD set may include at least a first parameter and a second parameter generated by encrypting the first parameter. A simulated secure connection between the first port unit and the second port unit via a network under test may be opened using a selected PCCD set from the one or more PCCD sets without performing decryption processing.