US2021144075A1PendingUtilityA1

Secure traffic visibility and analytics for encrypted traffic

Assignee: CISCO TECH INCPriority: Jul 24, 2018Filed: Jan 22, 2021Published: May 13, 2021
Est. expiryJul 24, 2038(~12 yrs left)· nominal 20-yr term from priority
H04L 45/745H04L 43/062H04L 63/029H04L 63/164H04L 63/1408H04L 63/0272H04L 63/0236H04L 12/4641H04L 63/20H04L 63/0428H04L 12/4633H04L 2212/00H04L 69/22H04L 43/045
53
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Presented herein is an exemplified system and method that provides visibility, for traffic analytics, into secured encapsulated packet (e.g., secure VXLAN-GPE packet, a secure metadata-GPE packet or other GPE standards). The exemplified system and method facilitate encryption of traffic in a granular manner that also facilitate the monitoring of said secure traffic in a fabric network in an end-to-end manner throughout the network. Such monitoring can be beneficially used for analytics, performance analysis, and network debugging/troubleshooting.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method of collecting security, flow, and/or routing information associated with an encrypted-encapsulated packet, the method comprising:
 in a network, receiving, at an ingress network node, a packet to selectively apply, according to one or more policies enforced at the ingress network node, an encrypted encapsulation to generate an encrypted-encapsulated packet;   generating, at the ingress network node, the encrypted-encapsulated packet by (i) encrypting the packet having included a packet header and a packet payload to form an encrypted payload of the encrypted-encapsulated packet and (ii) inserting an encapsulation header to the encrypted-encapsulated packet, wherein the encapsulation header comprises one or more metadata information derived, or retrieved, from the header or the payload of the received packet, wherein the one or more metadata information is inserted as a string into one or more pre-defined fields in the encapsulation header; and   transmitting, at the ingress network node, over a tunnel, the encrypted-encapsulated packet to an egress network node located in the network,   wherein the one or more metadata information is subsequently collected, by an intermediary node located between, or able to observe traffic between, the ingress network node and egress network node, to be subsequently analyzed individually or in combination with other collected metadata information, wherein the intermediary node collects the one or more metadata information by interrogating the string in the one or more pre-defined fields of the encapsulation header.   
     
     
         2 . The method of  claim 1 , further comprising:
 forwarding, at the intermediary node, the one or more metadata information to a collector for subsequent analysis.   
     
     
         3 . The method of  claim 2 , wherein the collector is configured to store the one or more metadata information and other metadata information collected from other encrypted-encapsulated packets. 
     
     
         4 . The method of  claim 3 , wherein the collector is further configured to store IP traffic data collected from the network. 
     
     
         5 . The method of  claim 1 , further comprising:
 receiving, at the egress network node, the encrypted-encapsulated packet; and   generating, at the egress network node, the packet, wherein the packet having included the packet header and packet payload is generated by decrypting the encrypted payload.   
     
     
         6 . The method of  claim 1 ,
 wherein the encapsulation header comprises a VXLAN-GPE header, and   wherein the VXLAN-GPE header comprises a number of allocate-able bits for inclusion of the one or more metadata information selected from the group consisting of: at least 16 bits, at least 32 bits, and at least 48 bits.   
     
     
         7 . The method of  claim 1 ,
 wherein the encapsulation header comprises a metadata GPE header, and   wherein the metadata GPE header comprises a number of allocate-able bits for inclusion of the one or more metadata information selected from the group consisting of at least 24 bits and at least 56 bits (e.g., one or more bits located between bit location 0 and bit location 23 and/or between bit location 32 and bit location 63 of the header).   
     
     
         8 . The method of  claim 1 , wherein the one or more metadata information are specified in the one or more policies, wherein the one or more policies are editable i) by a controller located in the network and/or ii) by a network administrator through a computing terminal having access to the network. 
     
     
         9 . The method of  claim 1 , wherein the one or more metadata information includes an identifier selected from the group consisting of:
 a source IP address associated with the packet;   a destination IP address associated with the packet;   a security group tag (SGT) associated with the packet;   a VXLAN network identifier (VNI) associated with the packet;   a user identifier associated with the packet;   a user-group identifier associated with the packet;   a subnet address associated with the packet;   a subnet group address associated with the packet;   an application identifier associated with an application executing on a computing device that is origin to the packet;   a virtualized instance identifier of a computing device in the network that is origin to the packet; and   a combination thereof.   
     
     
         10 . The method of  claim 1 , wherein the one or more metadata information are inserted as one or more unencrypted strings into one or more pre-defined fields in the encapsulation header. 
     
     
         11 . The method of  claim 1 , wherein the one or more metadata information is inserted as one or more encrypted strings into one or more pre-defined fields in the encapsulation header. 
     
     
         12 . A system comprising:
 a network interface having instructions stored thereon, wherein execution of the instructions by a processor causes the interface to:   upon receipt of a packet, generate an encrypted-encapsulated packet by (i) encrypting the packet having included a packet header and packet payload to form an encrypted payload of the encrypted-encapsulated packet and (ii) inserting an encapsulation header to the encrypted-encapsulated packet, wherein the encapsulation header comprises one or more metadata information derived, or retrieved, from the header or payload of the received packet, wherein the one or more metadata information is inserted into one or more pre-defined fields of the encapsulation header; and   transmit, over a tunnel, the encrypted-encapsulated packet to an egress network node located in the network,   wherein the one or more metadata information is subsequently collected, by an intermediary node located between, or able to observe traffic between, the ingress network node and egress network node, to be subsequently analyzed individually or in combination with other collected metadata information, wherein the intermediary node collects the one or more metadata information by interrogating the string in the one or more pre-defined fields of the encapsulation header.   
     
     
         13 . The system of  claim 12 , wherein a collector is configured to store the one or more metadata information and other metadata information collected from other encrypted-encapsulated packets. 
     
     
         14 . The system of  claim 12 , wherein the encapsulation header comprises a VXLAN-GPE header, and wherein the VXLAN-GPE header comprises a number of allocate-able bits for inclusion of the one or more metadata information selected from the group consisting of: at least 16 bits, at least 32 bits, and at least 48 bits. 
     
     
         15 . The system of  claim 12 ,
 wherein the encapsulation header comprises a metadata GPE header, and   wherein the metadata GPE header comprises a number of allocate-able bits for inclusion of the one or more metadata information selected from the group consisting of at least 24 bits and at least 56 bits.   
     
     
         16 . The system of  claim 12 , wherein the encapsulation header comprises a VXLAN DTLS header or a metadata DTLS header. 
     
     
         17 . The system of  claim 12 , wherein the one or more metadata information is specified in one or more policies, wherein the one or more policies are editable i) by a controller located in the network or ii) by a network administrator through a computing terminal having access to the network, the system further comprising:
 a memory having instructions stored thereon, wherein execution of the instructions by one or more processors of the system, cause the processor to:   receive the one or more policies from a computing device external to the system; and   apply the one or more policies to incoming traffic received at the network interface.   
     
     
         18 . The system of  claim 12 , wherein the one or more metadata information includes an identifier selected from the group consisting of:
 a source IP address associated with the packet;   a destination IP address associated with the packet;   a security group tag associated with the packet;   a VXLAN network identifier (VNI) associated with the packet;   a user identifier associated with the packet;   a user-group identifier associated with the packet;   a subnet address associated with the packet;   a subnet group address associated with the packet;   a source application executing on a computing device that is origin to the packet;   a virtualized instance of a computing device in the network that is origin to the packet; and   a combination thereof.   
     
     
         19 . A system comprising:
 a network interface having instructions stored thereon, wherein execution of the instructions, cause the interface to:   upon receipt of an encrypted encapsulated packet having an encrypted-encapsulation header and an encrypted payload, generate an unencrypted packet having included a packet header and a packet payload from the encrypted payload; and   transmit the unencrypted packet to a next hop in the network based on routing information identified in the unencrypted packet,   wherein the encrypted-encapsulated packet was generated by (i) encrypting the packet having included the packet header and the packet payload to form the encrypted payload and (ii) inserting the encapsulation header to the encrypted-encapsulated packet, wherein the encapsulation header comprises one or more metadata information derived, or retrieved, from the packet header or the packet payload, wherein the one or more metadata information is inserted into one or more pre-defined fields of the encapsulation header, and   wherein the one or more metadata information is collectable, by an intermediary node located between, or able to observe traffic between, the ingress network node and egress network node, to be analyzed individually or in combination with other collected metadata information, wherein the intermediary node collects the one or more metadata information by interrogating in the one or more pre-defined fields of the encapsulation header.   
     
     
         20 . The system of  claim 19 ,
 wherein the network interface is configurable via instructions to forward the one or more metadata information to a collector located in the network, wherein the collector is configured to store the one or more metadata information and other metadata information collected from other encrypted-encapsulated,   wherein the encapsulation header comprises a VXLAN DTLS header or a GPE DTLS header, and   wherein the one or more metadata information includes an identifier selected from the group consisting of:   a source IP address associated with the packet;   a destination IP address associated with the packet;   a security group tag associated with the packet;   a VXLAN network identifier (VNI) associated with the packet;   a source IP address associated with the packet;   a destination IP address associated with the packet;   a security group tag associated with the packet;   a VXLAN network identifier (VNI) associated with the packet;   a user identifier associated with the packet;   a user-group identifier associated with the packet;   a subnet address associated with the packet;   a subnet group address associated with the packet;   a source application executing on a computing device that is origin to the packet;   a virtualized instance of a computing device in the network that is origin to the packet; and   a combination thereof.

Join the waitlist — get patent alerts

Track US2021144075A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.