Verifiable and Privacy-Preserving Deep Packet Inspection for Multiple Rule Service Providers

  • Zhentao Long
  • , Pengfei Wu
  • , Kai Zhang*
  • , Junqing Gong
  • , Jianting Ning
  • *Corresponding author for this work

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Secure outsourced middleboxes provide deep packet inspection (DPI) for encrypted traffic that enables the detection of malicious activities in communications. However, existing DPI systems generally support only a single rule service provider (RSP), whose rule sets are limited to specific attack types. This constraint reduces inspection coverage and diminishes the accuracy of detecting diverse malicious traffic. In this paper, we present MRv-DPI, a new privacy-preserving DPI system that supports inspection rules from multiple RSPs, enabling targeted inspection for any type of attack pattern. Additionally, by considering that the middleboxes may only use partial subscribed RSPs’ rule sets to inspect each packet, our system also provides inspection results verification. To support multiple RSPs, MRv-DPI employs a key-homomorphic pseudo-random function, allowing matching between rules encrypted under distinct keys and packets encrypted under a shared key. For result verification, we design a temporal-hashed substring search trie based on trusted hardware, ensuring tamper-resistant verification against untrusted cloud-based middleboxes. To address efficiency challenges arising from increased rule sets across multiple RSPs, MRv-DPI segments both packets and rules, and assigns each rule a main sub-segment to facilitate fast filtering of benign packets. We evaluate MRv-DPI through comprehensive experiments using four public rule sets in a real client-to-server environment. Compared to existing DPI solutions, MRv-DPI not only enhances both security and functionality but also achieves up to 2× faster packet inspection and reduces communication overhead by 36.1% – 57.4%.

Original languageEnglish
Title of host publicationInformation Security and Cryptology - 21st International Conference, Inscrypt 2025, Revised Selected Papers
EditorsRongmao Chen, Robert H. Deng, Moti Yung
PublisherSpringer Science and Business Media Deutschland GmbH
Pages275-295
Number of pages21
ISBN (Print)9789819562022
DOIs
StatePublished - 2026
Event21st International Conference on Information Security and Cryptology, Inscrypt 2025 - Xi'an, China
Duration: 19 Oct 202522 Oct 2025

Publication series

NameLecture Notes in Computer Science
Volume16409 LNCS
ISSN (Print)0302-9743
ISSN (Electronic)1611-3349

Conference

Conference21st International Conference on Information Security and Cryptology, Inscrypt 2025
Country/TerritoryChina
CityXi'an
Period19/10/2522/10/25

Keywords

  • Deep packet inspection
  • Key homomorphic pseudo-random function
  • Multiple rule service providers
  • Privacy preserving

Fingerprint

Dive into the research topics of 'Verifiable and Privacy-Preserving Deep Packet Inspection for Multiple Rule Service Providers'. Together they form a unique fingerprint.

Cite this