Variable Encryption Level Network Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VPN technologies employ an all-or-nothing approach to encryption, failing to provide varying encryption levels for different applications and data classes, which can lead to over- or under-encryption of network traffic, compromising security and efficiency.

Innovation Solution

A framework that allows for the specification of varying encryption rules within a VPN configuration, enabling the creation of multiple encrypted channels with different encryption keys for different applications, data types, or network destinations, ensuring appropriate encryption levels based on specific criteria.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single encrypted channel is created for all network traffic, then security is maintained for all data, but encryption overhead increases and security efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidencryption efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments network traffic into different categories (e.g., by application, data sensitivity level, or destination) and creates separate encrypted channels for each segment. This allows selective encryption where high-sensitive data receives strong encryption while less sensitive data uses lighter encryption, resolving the contradiction between comprehensive security and encryption efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different encryption strengths and types are applied to different parts of the network traffic based on their specific security requirements. The system determines encryption characteristics locally for each traffic flow or data category, enabling optimized security without uniform encryption overhead across all traffic.

Inventive Principle:
Principle #3Local quality

2Reliability

If high encryption strength is applied to all data, then sensitive data is adequately protected, but network performance decreases due to excessive encryption overhead

Engineering Contradiction:
Improvedata protectionVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies partial encryption strength to different data types rather than uniform maximum encryption. High-sensitive data receives strong encryption (adequate protection), while low-sensitive data receives minimal or no encryption, avoiding excessive encryption overhead that would degrade network performance.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes encryption parameters (key size, algorithm type, encryption mode) based on the sensitivity level and requirements of different data types. This allows optimization of the encryption-strength-to-performance ratio for each data category.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If no encryption is applied to certain data, then network efficiency is improved, but security requirements are not met for sensitive data

Engineering Contradiction:
Improvenetwork efficiencyVSAvoidsecurity compliance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments data traffic by sensitivity level and applies encryption selectively to segments that require it. This ensures network efficiency for unencrypted low-sensitive traffic while maintaining security compliance for encrypted high-sensitive traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system incorporates feedback mechanisms to monitor data sensitivity classifications and adjust encryption application accordingly, ensuring that security requirements are met without unnecessary encryption overhead for data that does not require protection.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10587579B2Varying encryption level of traffic through network tunnels
Publication Date: 2020.03.10 OMNISSA LLC
  • US10587579B2 patent drawing
  • US10587579B2 patent drawing
  • US10587579B2 patent drawing

AI summary

Disclosed are various examples for establishing encrypted channels or tunnels within a TCP or other communication session between a tunnel endpoint and tunnel client on a client device. A tunnel client on the client device can determine an encryption level based upon a bundle identifier of the application originating the network traffic, the destination of the network traffic, the category of the application, or other factors.