Selective Encryption of Tunneled Network Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In SD-WAN environments, existing encryption methods encrypt all network traffic, including already securely encrypted payload data, leading to increased processing overhead and latency, as they fail to differentiate between adequately encrypted and insufficiently encrypted data.
Innovation Solution
Implementing a system where intermediary devices selectively encrypt only the clear text portions of network packets, avoiding unnecessary encryption of strongly encrypted payload data by identifying the encryption protocol and applying encryption rules based on predetermined thresholds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all network traffic is encrypted, then security is improved, but processing overhead and latency increase
Solution Approach 1:
The patent applies encryption selectively to specific portions of network packets based on their content and security requirements. Clear text portions are encrypted while already-encrypted payload data is left unchanged, creating local differentiation in encryption application across the packet structure.
Solution Approach 2:
Instead of applying full encryption to entire packets, the patent implements partial encryption only for the necessary clear text portions (headers, metadata). This partial action achieves sufficient security for vulnerable sections without the excessive processing burden of encrypting all data including already-encrypted payloads.
2Reliability
If all network traffic is encrypted, then security is improved, but network throughput decreases
Solution Approach 1:
The system identifies and encrypts only the clear text portions of packets locally, leaving encrypted payload sections unchanged. This local differentiation reduces the volume of data requiring encryption processing, thereby maintaining higher network throughput while still protecting vulnerable clear text segments.
Solution Approach 2:
The patent implements partial encryption action limited to clear text portions rather than excessive full-packet encryption. This approach achieves adequate security coverage for unprotected sections while avoiding the throughput penalty of re-encrypting already-secure payload data.
3Reliability
If encryption is applied to all packet portions, then security coverage is improved, but processing time increases
Solution Approach 1:
The patent applies encryption locally only to clear text portions of packets where security coverage is actually needed. By identifying and targeting only these specific portions rather than applying uniform encryption across all packet data, processing time is reduced while security coverage remains adequate for vulnerable sections.
Solution Approach 2:
The system implements partial encryption action on clear text portions only, avoiding excessive processing time associated with full-packet encryption. This partial approach achieves sufficient security coverage for unprotected data without the time cost of processing already-encrypted payload sections.
4Productivity
If selective encryption is implemented, then processing efficiency is improved, but device complexity increases
Solution Approach 1:
The patent segments the packet processing function into distinct components: identification of clear text portions, selective encryption application, and forwarding. This segmentation of the encryption process into discrete, manageable steps improves processing efficiency by enabling targeted operations while keeping device complexity organized and manageable through functional decomposition.
Data Source
AI summary
Described embodiments provide systems and methods for selectively encrypting and decrypting portions of a network flow by intermediary devices. A first device may identify a protocol used by a network flow traversing the first device via one or more packets of the protocol. The first device may determine that a level of encryption for the network flow meets a predetermined threshold. The first device may receive networks packets to be communicated between a sender and a receiver. The packets may include a first portion that is encrypted and a second portion that has clear text information. The first device may encrypt the second portion of the one or more packets. The first device may forward the network packets with the first portion and the encrypted second portion via a tunnel to a second device for decryption of the encrypted second portion for forwarding to the receiver.


