Selective Encryption of Tunneled Network Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In SD-WAN environments, existing encryption methods encrypt all network traffic, including already securely encrypted payload data, leading to increased processing overhead and latency, as they fail to differentiate between adequately encrypted and insufficiently encrypted data.

Innovation Solution

Implementing a system where intermediary devices selectively encrypt only the clear text portions of network packets, avoiding unnecessary encryption of strongly encrypted payload data by identifying the encryption protocol and applying encryption rules based on predetermined thresholds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all network traffic is encrypted, then security is improved, but processing overhead and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies encryption selectively to specific portions of network packets based on their content and security requirements. Clear text portions are encrypted while already-encrypted payload data is left unchanged, creating local differentiation in encryption application across the packet structure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of applying full encryption to entire packets, the patent implements partial encryption only for the necessary clear text portions (headers, metadata). This partial action achieves sufficient security for vulnerable sections without the excessive processing burden of encrypting all data including already-encrypted payloads.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If all network traffic is encrypted, then security is improved, but network throughput decreases

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system identifies and encrypts only the clear text portions of packets locally, leaving encrypted payload sections unchanged. This local differentiation reduces the volume of data requiring encryption processing, thereby maintaining higher network throughput while still protecting vulnerable clear text segments.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial encryption action limited to clear text portions rather than excessive full-packet encryption. This approach achieves adequate security coverage for unprotected sections while avoiding the throughput penalty of re-encrypting already-secure payload data.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If encryption is applied to all packet portions, then security coverage is improved, but processing time increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies encryption locally only to clear text portions of packets where security coverage is actually needed. By identifying and targeting only these specific portions rather than applying uniform encryption across all packet data, processing time is reduced while security coverage remains adequate for vulnerable sections.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system implements partial encryption action on clear text portions only, avoiding excessive processing time associated with full-packet encryption. This partial approach achieves sufficient security coverage for unprotected data without the time cost of processing already-encrypted payload sections.

Inventive Principle:
Principle #16Partial or excessive action

4Productivity

If selective encryption is implemented, then processing efficiency is improved, but device complexity increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the packet processing function into distinct components: identification of clear text portions, selective encryption application, and forwarding. This segmentation of the encryption process into discrete, manageable steps improves processing efficiency by enabling targeted operations while keeping device complexity organized and manageable through functional decomposition.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11349820B2Selective encryption of tunneled encrypted traffic
Publication Date: 2022.05.31 CITRIX SYSTEMS INC
  • US11349820B2 patent drawing
  • US11349820B2 patent drawing
  • US11349820B2 patent drawing

AI summary

Described embodiments provide systems and methods for selectively encrypting and decrypting portions of a network flow by intermediary devices. A first device may identify a protocol used by a network flow traversing the first device via one or more packets of the protocol. The first device may determine that a level of encryption for the network flow meets a predetermined threshold. The first device may receive networks packets to be communicated between a sender and a receiver. The packets may include a first portion that is encrypted and a second portion that has clear text information. The first device may encrypt the second portion of the one or more packets. The first device may forward the network packets with the first portion and the encrypted second portion via a tunnel to a second device for decryption of the encrypted second portion for forwarding to the receiver.