Latency Assessment in Secure Packet Data Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current latency assessment methods require decrypting packets to match original and encrypted data packets, which is impractical for infrastructure providers lacking cryptographic keys, especially when measuring latency at a ciphering end point in secure communication channels.
Innovation Solution
A method and traffic analyzer that generate and transmit test traffic with uniquely sized packets, allowing timestamp pairs to be used for latency assessment without decrypting packets, by associating encrypted packet sizes with their original packet sizes and timestamps, using protocols like ESP or WireGuard, to calculate latency at the ciphering end point.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If conventional latency assessment methods are used, then latency measurement is possible, but packet decryption is required which is impractical for infrastructure providers
Solution Approach 1:
The patent extracts the packet identification information from the encrypted payload and places it in the packet header where it remains accessible without decryption. This allows the identifier to be used for matching original and encrypted packets without requiring cryptographic keys, thus resolving the contradiction between measurement accuracy and operational feasibility.
Solution Approach 2:
The patent introduces a packet identifier as an intermediary element that bridges the original packet and its encrypted version. This identifier acts as a mediator that allows correlation between packets without requiring access to the encrypted content, enabling latency measurement while maintaining security constraints.
2Measurement precision
If packets are decrypted for latency assessment, then original packet matching is possible, but cryptographic keys are required which infrastructure providers lack
Solution Approach 1:
The patent extracts the packet identifier from the encrypted packet structure and makes it accessible in the header portion. This extraction allows packet matching without decryption, eliminating the need for cryptographic key management while maintaining accurate packet correlation for latency measurement.
Solution Approach 2:
The patent creates a copy of the packet identifier that exists in both the original packet and the encrypted packet. This copy mechanism allows the identifier to be used for matching purposes without requiring access to the original unencrypted packet or cryptographic keys.
3Reliability
If traditional performance assessment methods are used, then service quality monitoring is possible, but the methods are not suitable for secure communication channels
Solution Approach 1:
The patent introduces a packet identifier as an intermediary that enables service quality monitoring in secure channels. This identifier allows traditional performance assessment methods to adapt to encrypted traffic by providing a mechanism for packet correlation without breaking encryption, thus improving versatility while maintaining reliability.
Solution Approach 2:
The patent changes the parameter of packet structure by adding an accessible identifier field that does not require decryption. This parameter change makes the packet suitable for both secure transmission and performance monitoring, enhancing adaptability to secure communication channels while maintaining service quality assurance capabilities.
Data Source
Figure 1a
Figure 1b
Figure 1c
AI summary
There are provided a method and system for assessing latency of ciphering end point of secure communication channel. The method comprises: generating a test traffic comprising a series of original data packets, wherein, for each original data packet, size of a given packet is uniquely indicative of the packet's place in a sequence of data packets in the series and enables unique correspondence with a size of the given packet upon its encryption; successively transmitting the original packets to the ciphering end point, whilst associating with respective departure time stamps; receiving encrypted packets from the ciphering end point and associating them with respective arrival time stamps; using a size of a given encrypted packet with a timestamp TSa to identify a size of a matching original packet, its place in the sequence of original packets and, thereby, its departure timestamp TSd, thus giving rise to a plurality of timestamp pairs (TSd; TSa).