Priority Signaling in Encrypted Network Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for priority or preemption in communication networks fail to effectively manage priority or preemption levels across networks with isolated portions, particularly in systems using encrypted and non-encrypted communications, as they assume direct communication with all nodes and lack viability in partitioned networks like those isolated by High Assurance Internet Protocol Encryptor (HAIPE) devices.
Innovation Solution
A system and method that encode communication packets with two segments, where one segment is in an unencrypted scheme and the other in an encrypted scheme, with priority-indicating bits, allowing networks to alter encoding and preempt resources for higher priority packets, even across isolated network portions, by employing High Assurance Internet Protocol Encryptor (HAIPE) devices and Quality of Service (QoS) mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If networks use encrypted communications to isolate portions for security, then security and confidentiality are improved, but priority management and resource preemption capabilities deteriorate because signaling cannot pass through encrypted segments
Solution Approach 1:
The packet is divided into two distinct segments: an encrypted payload segment for security and an unencrypted overhead segment for priority signaling. This segmentation allows each segment to serve its specific function independently, resolving the contradiction between security and priority management.
Solution Approach 2:
The unencrypted overhead segment acts as an intermediary that carries priority information between encrypted network segments. This intermediary enables priority management functionality without compromising the security of the encrypted payload, allowing routers to perform QoS operations on isolated network portions.
2Adaptability or versatility
If existing priority management solutions are used in partitioned networks, then resource allocation can be managed within each partition, but end-to-end priority treatment deteriorates because nodes cannot communicate directly across isolated portions
Solution Approach 1:
The overhead segment serves multiple functions simultaneously: it carries priority information for QoS management, enables end-to-end signaling across encrypted boundaries, and provides a universal interface that works with both encrypted and unencrypted network segments. This multi-functionality resolves the contradiction between local adaptability and global coordination.
3Ease of operation
If all communication segments are unencrypted for easy priority signaling, then priority management and resource preemption are improved, but security and confidentiality deteriorate
Solution Approach 1:
The communication packet is segmented into encrypted and unencrypted portions, with the unencrypted overhead dedicated to priority signaling and the encrypted payload for confidential data. This segmentation allows priority management to proceed easily while maintaining security for the actual communication content.
Data Source
AI summary
A system for conveying priority associated with a communication conveyed among networks includes: (a) a first network originating the communication in packets; each respective packet including two segments; a first segment containing a portion of the communication in information payload bits in a first encoding scheme; a second segment containing overhead information relating to the packet in overhead bits in a second encoding scheme; a number of the overhead bits being configured to indicate the priority; and (b) a second network cooperating with the first network to alter encoding of the first segment of a selected packet-set to express the information payload bits in a third encoding scheme that is unreadable in the second network; the second network employing the priority-indicating bits to ascertain priority for handling the communication by the second network; the second network preempting lower priority resources to reserve resources for higher priority packet-sets.


