Selective Network Encryption for Endpoint-Secured Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network encryption methods, such as IPsec, adopt an all-or-nothing approach that is inefficient for modern networks with significant layer 7 encryption, leading to performance bottlenecks and suboptimal balancing of security and efficiency.

Innovation Solution

Implementing intelligent network encryption by inspecting traffic attributes to determine if endpoint encryption is already in use, and selectively applying network layer encryption based on this information, with caching session attributes for future sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network layer encryption is applied to all traffic, then security is improved, but network performance deteriorates due to processing overhead

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies different encryption treatments to different traffic flows based on their specific characteristics. By inspecting traffic attributes (such as port numbers, protocols, and destination addresses), the system determines whether each flow requires network layer encryption or can use endpoint encryption instead. This localized approach ensures that encryption is applied only where necessary, optimizing the balance between security and performance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of applying network layer encryption universally (excessive action), the patent applies encryption selectively only to traffic flows that lack endpoint encryption protection (partial action). This reduces unnecessary encryption overhead while maintaining security for flows that need it, directly addressing the performance bottleneck issue.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If IPsec is used for all traffic, then security coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidencryption management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system differentiates between traffic flows requiring network layer encryption and those using endpoint encryption. By inspecting traffic attributes and making per-flow decisions, the patent simplifies the overall encryption management complexity while maintaining comprehensive security coverage for all traffic types.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements dynamic encryption decision-making based on real-time traffic inspection. The system adapts its encryption application based on the specific characteristics of each traffic flow, port numbers, protocols, and destination addresses, making the encryption management more flexible and less complex compared to static all-or-nothing approaches.

Inventive Principle:
Principle #15Dynamics

3Reliability

If network layer encryption is applied to encrypted traffic, then security redundancy is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity redundancyVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent avoids excessive encryption by applying network layer encryption only to traffic flows that do not already have endpoint encryption. By inspecting traffic attributes first, the system identifies flows that would benefit from additional network layer security and applies encryption only to those, avoiding redundant processing for already-encrypted traffic.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system applies different processing treatments to different traffic flows based on their encryption status. By making localized decisions about which flows need network layer encryption and which can use endpoint encryption, the patent minimizes unnecessary processing overhead while maintaining appropriate security redundancy where needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20260067259A1Network encryption based on traffic between source and destination
Publication Date: 2026.03.05 ORACLE INT CORP
  • US20260067259A1 patent drawing
  • US20260067259A1 patent drawing
  • US20260067259A1 patent drawing

AI summary

The present disclosure relates to intelligent network encryption of traffic between a source and a destination. In an example, a network element receives, during a session between the source and the destination, first traffic exchanged between the source and the destination. The network element determines whether a traffic exchange between the source and the destination is expected to be secured by at least one of the source or the destination at any of a network layer, a transport layer, or an application layer. The network element generates a decision whether to secure the first session at the network layer based on whether the traffic exchange is expected to be secured or unsecured. The network element implements the decision on at least one of the first traffic or second traffic exchanged between the source and the destination during the first session.