Transparent Bridge for Crypto-Partitioned WAN Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wide-area networks (WANs) are susceptible to equipment failures and cyber-attacks, leading to impaired connectivity for mission applications, with existing approaches being inefficient for UDP-based applications and multicast data flows.
Innovation Solution
A computing device positioned in a plain-text enclave behind an inline network encryptor monitors the status of a cipher-text WAN by analyzing data packets, using a signaling mechanism to share network state information and implement congestion prevention strategies and transport layer-independent overlay routing to correct errors and restore connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If a fully distributed network optimization technique based on cooperative game theory is used to allocate network resources, then network resource allocation efficiency is improved, but performance for UDP-based applications and multicast data flows deteriorates
Solution Approach 1:
The patent segments the network into multiple enclaves with dedicated monitoring devices, allowing independent optimization for different traffic types (UDP, multicast, TCP) rather than applying a single distributed optimization approach to all traffic, thus resolving the contradiction between overall resource allocation efficiency and specific application performance
Solution Approach 2:
The patent introduces intermediary monitoring devices positioned in each enclave that actively monitor network status and coordinate with other enclaves. These intermediaries enable efficient resource allocation while providing specialized support for UDP and multicast traffic, maintaining both overall efficiency and specific application performance
2Reliability
If monitoring and correction operations are performed within enclaves using plain-text-side and overlay routing, then connectivity protection is improved, but network overhead increases
Solution Approach 1:
The patent implements preliminary action by proactively monitoring network status indicators in data packets before connectivity issues occur. The monitoring devices detect potential problems early and can preemptively route around issues, providing connectivity protection without requiring extensive reactive corrections that would increase network overhead
Solution Approach 2:
The patent uses feedback mechanisms where monitoring devices continuously analyze network status and adjust routing decisions in real-time. This feedback loop enables efficient connectivity protection by making targeted routing adjustments only when and where needed, rather than applying blanket overhead across all network traffic
3Productivity
If existing distributed network optimization approaches are used, then cumulative network performance is maximized, but recovery time from network events increases
Solution Approach 1:
The patent prepares for network events in advance by continuously monitoring network status indicators and maintaining ready-to-execute routing alternatives. When network events occur, the system can immediately switch to pre-planned recovery paths, significantly reducing recovery time while maintaining cumulative network performance through coordinated enclave responses
Solution Approach 2:
The patent implements dynamic response mechanisms where monitoring devices can rapidly adjust routing decisions based on real-time network conditions. This dynamic capability allows the system to maintain optimal cumulative performance during normal operation and quickly adapt to network events, reducing recovery time through flexible, real-time reconfiguration rather than static optimization
Data Source
AI summary
This disclosure is directed to monitoring a crypto-partitioned, or cipher-text, wide-area network (WAN). A first computing device may be situated in a plain-text portion of a first enclave behind a first inline network encryptor (INE). A second device may be positioned in a plain-text portion of a second enclave behind a second INE. The two enclaves may be separated by a cipher-text WAN, over which the two enclaved may communicate. The first computing device may receive a data packet from the second computing device. The first computing device may then determine contents of a header of the data packet. The first computing device may, based at least in part on the contents of the header of the data packet, determine a status of the cipher-text WAN.


