Traffic Mirroring Correlation for Secure VPN Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Encrypted network traffic obstructs monitoring and analysis in cloud-based infrastructure, as existing technologies hinder efficient traffic mirroring and decryption for network traffic analysis without performance impact.

Innovation Solution

An orchestrator configures security appliances to mirror network traffic and correlate packets with cryptographic keys, decrypting them using on-the-fly random keys and re-encrypting with an organization's public key for secure conveyance to a repository, preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network traffic is encrypted using IPsec VPN tunnels, then data security and privacy are improved, but traffic monitoring and analysis capabilities deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidtraffic monitoring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a cloud service provider as an intermediary that establishes its own encrypted VPN tunnels between data centers. This intermediary infrastructure allows the provider to mirror and monitor traffic flowing through its network while customers maintain their encrypted communications. The provider's tunnel endpoints can correlate mirrored traffic with cryptographic keys to enable monitoring without breaking customer encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If traffic mirroring is implemented for monitoring purposes, then network analysis capability is improved, but performance and security of original traffic deteriorate

Engineering Contradiction:
Improvenetwork analysis capabilityVSAvoidnetwork performance
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

The patent segments traffic monitoring into separate mirrored copies that are independent of the original traffic flow. Cloud service providers can mirror traffic to separate analysis channels without impacting the performance of production networks. The mirroring occurs at the network infrastructure level, allowing parallel processing of original and monitored traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cloud service provider acts as an intermediary that handles the performance burden of traffic mirroring and analysis, isolating it from customer networks. The provider's infrastructure absorbs the overhead of copying, storing, and analyzing traffic, preventing performance degradation in the original network systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Difficulty of detecting and measuring

If cryptographic keys are stored for traffic decryption, then traffic analysis capability is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvetraffic decryption capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The patent moves cryptographic key storage to a different security dimension by implementing hierarchical key management across multiple VPN tunnel layers. Customer traffic is encrypted in customer VPN tunnels, then re-encrypted in cloud provider VPN tunnels with separate key management. This dimensional separation allows the provider to access traffic for monitoring while maintaining cryptographic security boundaries that prevent unauthorized access.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The cloud service provider acts as a security intermediary that manages cryptographic keys in a controlled environment. Rather than customers managing keys that could be compromised, the provider's infrastructure securely stores and manages keys for its own VPN tunnels, providing a security boundary that protects against unauthorized access while enabling authorized monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12537797B2Enterprise traffic data correlation for traffic mirroring and decryption
Publication Date: 2026.01.27 PALO ALTO NETWORKS INC
  • US12537797B2 patent drawing
  • US12537797B2 patent drawing
  • US12537797B2 patent drawing

AI summary

An orchestrator that manages security appliances for an organization determines a sink configured for traffic mirroring and correspondingly configures components for the correlation and secure conveyance. The orchestrator also configures the security appliances. The orchestrator configures the security appliances to copy cryptographic keys (hereinafter “tunnel keys”) and identifiers associated with the keys of secure VPN tunnels established by the security appliances to a repository of the cloud-service provider. The orchestrator configures a virtual machine associated with the mirroring sink with correlation logic. The virtual machine correlates sets of packets aggregated across different mirroring streams and tunnel keys with the associated identifiers. Correlating the sets of packets and the tunnel keys allows an organization to efficiently access the content of the encrypted packets or facilitates secure conveyance.