Secure Data Flow Classification via Metadata Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network service providers face difficulties in analyzing and understanding secure data flows due to the encryption of data traffic, which prevents them from classifying and processing encrypted data packets effectively.

Innovation Solution

A method and system that involves a servicing node positioned after the first network hop to analyze open data associated with encrypted data packets, classify the secure data flow, and process it based on subscriber data, allowing for differentiation and processing of secure data flows despite encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data traffic is encrypted to protect user privacy, then privacy protection is improved, but network service providers lose the ability to analyze and classify data traffic

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata traffic analysis capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces metadata as an intermediary element that carries information about encrypted data traffic without requiring decryption. This metadata acts as a mediator between the encrypted payload and the network service provider's analysis needs, allowing classification and analysis while preserving encryption privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments data traffic into two distinct parts: encrypted payload data and unencrypted metadata. The metadata contains classification information, subscriber data, and other analytical elements that can be processed independently from the encrypted content, enabling network providers to analyze traffic patterns without compromising privacy.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If deep packet inspection is used to analyze data traffic content, then classification accuracy is improved, but it becomes ineffective for encrypted data traffic

Engineering Contradiction:
Improveclassification accuracyVSAvoidencrypted traffic handling capability
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the analysis parameters from examining encrypted payload content to analyzing unencrypted metadata parameters. This parameter transformation allows classification to work effectively on encrypted traffic by focusing on observable characteristics such as packet size, timing, and metadata fields rather than requiring decryption of the payload.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9787581B2Secure data flow open information analytics
Publication Date: 2017.10.10 A10 NETWORKS INC
  • US9787581B2 patent drawing
  • US9787581B2 patent drawing
  • US9787581B2 patent drawing

AI summary

Provided are methods and systems for processing a secure data flow. An example method for processing a secure data flow includes receiving a data packet, determining network conditions associated with the data traffic, and determining that the data packet is associated with the secure data flow. Upon determination that the data packet is associated with the secure data flow, the data packet is analyzed. Thereafter, the method proceeds to classify the secure data flow based on the analysis. Subscriber data associated with the data packet may be obtained. The method can then process the secure data flow based on the subscriber data and the classification of the secure data flow.