Virtual Tap Element Decrypting Encrypted Packet Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtual network environments, physical network taps are ineffective in monitoring 'east-west' traffic between virtual machines due to their reliance on traditional hardware infrastructure, and encrypted packet flows further complicate this challenge.

Innovation Solution

Implementing a virtual tap element within the virtual network environment to obtain cryptographic key information, decrypt encrypted packet flows, and send the decrypted packets to a packet analyzer, allowing for the monitoring of encrypted traffic between virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical network taps are used to monitor packet traffic, then monitoring capability in traditional networks is achieved, but monitoring of virtual packet flows in virtual network environments becomes ineffective

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidcompatibility with virtual network environment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a virtual tap element as an intermediary component within the virtual network environment that acts as a mediator between virtual machines and the packet analyzer. This virtual tap element captures encrypted packet flows between VMs, decrypts them using obtained cryptographic keys, and forwards the decrypted traffic to the analyzer, thereby enabling monitoring in virtualized networks where physical taps are ineffective.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the physical hardware-based network tap with a software-based virtual tap element that operates within the virtual network environment. This substitution allows the monitoring system to adapt from traditional hardware infrastructure to virtualized network architectures, enabling effective capture and analysis of east-west traffic between virtual machines.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of information

If cryptographic key information is obtained from virtual machines to decrypt packet flows, then encrypted traffic monitoring is enabled, but system security and complexity increase

Engineering Contradiction:
Improveencrypted traffic visibilityVSAvoidcryptographic key management
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The virtual tap element serves as a trusted intermediary that obtains cryptographic key information from virtual machines through secure key sharing mechanisms. This intermediary then uses the obtained keys to decrypt packet flows for monitoring purposes, balancing the need for encrypted traffic visibility with maintaining security through controlled key access and management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10855694B2Methods, systems, and computer readable media for monitoring encrypted packet flows within a virtual network environment
Publication Date: 2020.12.01 KEYSIGHT TECH SINGAPORE (SALES) PTE LTD
  • US10855694B2 patent drawing
  • US10855694B2 patent drawing
  • US10855694B2 patent drawing

AI summary

Methods, systems, and computer readable media for packet monitoring in a virtual environment are disclosed. According to one method executed at a virtual tap element residing in between a first virtual machine and a second virtual machine in a virtual network environment, the method includes obtaining cryptographic key information from either the first virtual machine or the second virtual machine and detecting an encrypted packet flow being communicated in the virtual network environment between the first virtual machine and the second virtual machine via the virtual tap element. The method further includes decrypting the encrypted packet flow using the cryptographic key information, generating a decrypted packet flow set comprising at least a portion of the decrypted packet flow, and sending the decrypted packet flow set to a packet analyzer.