Privacy-Enhancing Man-in-the-Middle Traffic Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of encryption in computer networks, while enhancing privacy, also poses security concerns as it can conceal malicious activities, and existing methods for analyzing encrypted traffic, such as man-in-the-middle approaches and network traffic analysis, either expose cleartext data or invade privacy by decrypting traffic or analyzing telemetry data.

Innovation Solution

A privacy-enhancing man-in-the-middle approach that involves a device intercepting traffic, sending a padding request to an endpoint, receiving a padding response, and adjusting the traffic by adding frames or bytes to obfuscate it from unwanted network traffic analysis, thereby preventing unauthorized assessment of encrypted traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If encryption is used to preserve privacy of sensitive information, then privacy protection is improved, but security monitoring capability deteriorates as malicious activities can be concealed

Engineering Contradiction:
Improveprivacy protectionVSAvoidsecurity monitoring capability
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent introduces a man-in-the-middle device as an intermediary that establishes separate encrypted channels with both endpoints. This mediator can observe traffic patterns, timing, and metadata without decrypting actual content, enabling security monitoring while preserving endpoint privacy. The device acts as a trusted third party that facilitates both privacy protection and security oversight simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters being monitored from content-based (requiring decryption) to metadata-based (patterns, timing, packet sizes, flow characteristics). By shifting monitoring focus to these alternative parameters, the system maintains security monitoring capability without compromising encryption-induced privacy protection.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network traffic analysis is used to assess encrypted traffic, then security detection capability is improved, but privacy protection deteriorates as encryption purpose is defeated

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprivacy protection
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies different quality levels to different parts of the traffic analysis process. Metadata and traffic patterns are analyzed in detail for security detection, while actual encrypted content remains completely protected. This local differentiation allows security monitoring of traffic characteristics without invading the privacy protection that encryption provides for content.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The man-in-the-middle device serves as an intermediary that performs analysis on traffic patterns and metadata rather than directly analyzing endpoint communications. This intermediary approach enables security detection of anomalies and threats while maintaining the privacy-integrity of the actual encrypted traffic between endpoints.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If man-in-the-middle approaches are used to decrypt and assess traffic, then security monitoring is improved, but privacy protection deteriorates as cleartext data is exposed

Engineering Contradiction:
Improvesecurity monitoringVSAvoiddata exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a man-in-the-middle device that acts as a trusted intermediary establishing separate encrypted connections with both endpoints. This mediator can perform security monitoring on traffic patterns and metadata without exposing actual cleartext data, as it never needs to fully decrypt the communication content between endpoints.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts only the necessary security-relevant information (metadata, patterns, timing, packet characteristics) from the encrypted traffic for analysis, while leaving the actual sensitive content protected. This extraction approach enables security monitoring without requiring exposure of cleartext data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11671447B2Privacy enhancing man-in-the-middle
Publication Date: 2023.06.06 CISCO TECHNOLOGY INC
  • US11671447B2 patent drawing
  • US11671447B2 patent drawing
  • US11671447B2 patent drawing

AI summary

In one embodiment, a device in a network receives traffic sent from a first endpoint. The device sends a padding request to the second endpoint indicative of a number of padding bytes. The device receives a padding response from the second endpoint, after sending the padding request to the second endpoint. The device adjusts the received traffic based on the received padding response by adding one or more frames to the received traffic. The device sends the adjusted traffic to the second endpoint.