Transaction-Level Network Policies for Encrypted Application Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network treatment policies are application-centric and fail to account for the varying importance of transactions within an application, as they are largely unfeasible due to encryption, leading to inadequate control over network traffic.
Innovation Solution
A device captures transaction data within online applications, associates a measure of importance with the traffic, and sends it through the network accordingly, enabling transaction-level network policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If packet inspection is used to assess transaction importance, then network traffic control precision is improved, but feasibility deteriorates due to encryption
Solution Approach 1:
The patent introduces an intermediary mechanism (application intelligence platform, instrumentation code, and agent) that bridges the gap between encrypted network traffic and the need for transaction-level policy enforcement. Instead of directly inspecting encrypted packets, the system uses instrumentation code embedded in the application to capture transaction data and generate markers, which then guide network device behavior. This intermediary approach preserves encryption while enabling precise traffic control.
Solution Approach 2:
The patent shifts the control mechanism from the network packet dimension to the application transaction dimension. Rather than attempting to decode and inspect encrypted packets at the network layer, the system operates at the application layer by instrumenting the application code itself to capture transaction information and generate control markers. This dimensional shift bypasses the encryption barrier while achieving the same control objective.
2Ease of operation
If application-centric policies are used, then network control is simplified, but transaction-level control precision is lost
Solution Approach 1:
The patent segments the monolithic application-centric policy into transaction-level granular policies. By instrumenting the application to identify individual transactions and their importance levels, the system creates distinct policy categories for different transactions within the same application. This segmentation enables precise control over individual transactions while maintaining the overall application-centric framework through hierarchical policy structure.
Solution Approach 2:
The patent applies local quality by assigning different importance levels and policy treatments to different transactions within the same application. Instead of treating all application traffic uniformly, the system identifies specific transactions (e.g., login vs. logout, data upload vs. download) and applies tailored network policies based on their local characteristics and business importance, thereby achieving both simplicity and precision.
3Reliability
If encryption is used for network traffic, then security is improved, but transaction assessment capability deteriorates
Solution Approach 1:
The patent uses an intermediary approach where instrumentation code embedded in the application serves as a mediator between the encrypted network traffic and the policy enforcement mechanism. The instrumentation code captures transaction data locally within the application context, where encryption does not interfere, and generates markers that convey transaction importance to network devices without requiring decryption of the actual traffic.
Solution Approach 2:
The patent creates a copy of the transaction information through markers generated by the instrumentation code. Instead of attempting to analyze the original encrypted packets, the system creates a parallel representation of transaction data (markers containing transaction identifiers, importance levels, and other metadata) that can be used for policy enforcement without compromising the security and confidentiality of the encrypted network traffic.
Data Source
AI summary
In one embodiment, a device obtains transaction data regarding a transaction attempted by a client of an online application within the online application. The transaction data is captured by instrumentation code inserted into the online application at runtime. The device identifies, based on the transaction data, traffic in a network associated with the transaction. The device associates, based on the transaction data, a measure of importance with the traffic. The device causes the traffic to be sent by a networking device in the network according to its associated measure of importance.


