Improved packet transmission

By decrypting and executing predetermined actions in the core of the telecommunications network and replacing the user identity with a mapped identifier, the computational power requirements and security issues of embedded sensor devices are solved, enabling miniaturization, low cost, and long battery life of user equipment, and supporting efficient and secure firmware updates and data processing.

CN115152180BActive Publication Date: 2026-03-31ONOMONDO PTE LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-02-12
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Existing embedded sensor devices face increasing demands for computing power due to the ever-growing encryption requirements of networks and data packet receivers. This leads to increased battery consumption and device costs, while also posing a risk of malicious tampering and making efficient and secure firmware updates difficult.

Method used

By decrypting and executing predetermined actions in the network core of the telecommunications network, replacing user identities with mapping identifiers, and encrypting and modifying data packets in the network core, the computational burden on user equipment is reduced, thereby achieving centralized firmware updates and enhanced security.

Benefits of technology

It enables miniaturization, low cost, and long battery life of user equipment, avoids the need for frequent firmware updates, improves the security and flexibility of sensor devices, and supports instant firmware updates and efficient data processing for telecommunications networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115152180B_ABST
    Figure CN115152180B_ABST
Patent Text Reader

Abstract

Interrelated computing devices and systems require more powerful devices to meet the growing need for encryption. This is improved by providing a computer-implemented method comprising receiving a packet (50) from a user device (10) through an access network (20) of a telecommunications network (1), the packet (50) having a user identity of the user device (10) and a telecommunications encryption layer (52) following an encryption protocol of the telecommunications network (1); decrypting the telecommunications encryption layer (52) of the packet (50) according to the protocol of the telecommunications network (1) using the user identity in a network core (30) of the telecommunications network (1); finding a predetermined action pre-associated with the user identity of the packet (50) stored in an action database (31) of the network core (30); and performing the predetermined action on the packet (50) in the network core (30).
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an improved method for data processing, packet routing and manipulation in the packet-switched network core of a telecommunications network, as well as a computer system, program and physical storage medium for performing this method. Background Technology

[0002] Amidst the emerging trends of automation, the Internet of Things (IoT), and Industry 4.0, embedded sensors are crucial for monitoring devices and processes. Improved stability and reduced costs have made these sensor devices increasingly cost-effective across a growing number of industries. These devices typically include microcontrollers and memory, and often also feature antennas for communication over networks.

[0003] The software installed on such devices has become obsolete due to the increasing encryption requirements of networks and packet receivers. So-called "zero-day" vulnerabilities are just one example of events that could expose sensor devices to malicious actors; another example is the ever-increasing computing power of hackers. Today, this problem is addressed through software updates and the installation of newer, better sensor devices.

[0004] Embedded sensors are typically located in remote areas, making cable power unavailable. This is usually addressed by using batteries in the sensor to provide power for sensing, data manipulation, and packet transmission. However, this requires greater computing power and data transmission due to the need for improved encryption to evade malicious actors, which further consumes battery power and increases device cost. Furthermore, if a malicious actor gains access to the sensor device, they could potentially tamper with it to find the recipient's address and key, compromising the encryption of multiple devices. This is addressed by using sufficiently strong encryption and / or by rendering the sensor device inaccessible.

[0005] Therefore, a solution is needed to improve the performance, security, and flexibility of remote sensor devices. Summary of the Invention

[0006] In one aspect, a computer-implemented method is provided, the method comprising the following steps:

[0007] - A packet is received from the user equipment via the access network of the telecommunications network. This packet contains the user's identity and is encrypted in the access network according to the protocol of the telecommunications network.

[0008] - The method of using the user identity in the network core of the telecommunications network to decrypt the packet according to the protocol of the telecommunications network is characterized by:

[0009] - Locate the pre-defined action stored in the network core's action database that is pre-associated with the user identity of the packet, and

[0010] - The predetermined action is performed on the packet in the network core.

[0011] In a second aspect, a computer-implemented method is provided, the method comprising the following steps:

[0012] - A packet is received from the user equipment via the access network of the telecommunications network. This packet contains the user's identity and is encrypted in the access network according to the protocol of the telecommunications network.

[0013] - The method of using the user identity in the network core of the telecommunications network to decrypt the packet according to the protocol of the telecommunications network is characterized by:

[0014] - Locate the pre-defined action stored in the network core's action database that is pre-associated with the user identity of the packet, and

[0015] - The predetermined action is performed on the packet in the network core, wherein the predetermined action includes:

[0016] - Replace the user identity in the packet with a second identifier from a mapping database. This second identifier is specific to the user identity and is used by the packet recipient to identify and / or authenticate the user device after transmission over the public internet.

[0017] - The modified packet is generated by modifying the payload data of the packet.

[0018] Therefore, when rules change, when device firmware errors are identified, or when firmware optimizations are needed, such improvements can be centrally implemented in the network core. Updates are then quick, inexpensive, and immediately applied to all affected user equipment. By allowing this simple firmware update, user equipment lifespan is significantly increased because the firmware's computational requirements are no longer dependent on the user equipment's computing power. This further frees firmware designers from platform-specific work and hardware-level optimizations. Instead, firmware can be made as efficient and effective as possible across one or several larger systems.

[0019] For example, it is not uncommon for user equipment manufacturers to provide firmware updates for only a few years (e.g., five or ten years) for a specific product, after which they cannot guarantee that the user equipment will still be able to perform the necessary computing work to fully run the firmware. By offloading the computing work to the network core, such updates can be performed centrally, and the computing work can grow without obviating user equipment.

[0020] Therefore, user devices can be miniaturized, inexpensive, and simple. It can also be further made more user-friendly, as it no longer requires firmware updates.

[0021] Furthermore, user equipment can be built to take advantage of this computational offloading, thus allowing for the initial production of user equipment without significant computing power. Consequently, such user equipment could be very small, inexpensive, simple, and potentially have significantly longer battery life.

[0022] Furthermore, this method allows for the retention or reintroduction of legacy user equipment / sensor devices that are nearing the end of their lifespan or retiring due to computational reasons. This can be achieved by installing updated firmware in the network core and, upon receiving packets from legacy devices, performing any necessary legacy encryption / decryption, and then searching for and executing predetermined actions.

[0023] The user identity is also called the first identifier, where the mapping identifier is the second identifier.

[0024] Furthermore, by mapping a mapping identifier to a user identity, this method allows the network core to receive telecommunications-specific packets and prepare them for transmission over the public internet. This mapping identifier identifies the user, so when a packet is received on a private server such as a cloud database, the mapping identifier can be traced back to the user's device by querying a matching mapping database. The second identifier can be a pre-shared key, a private key, or, for example, the user's login credentials.

[0025] This mapping allows private servers, such as cloud servers, to identify and verify devices, thus ensuring legitimacy. If any login credentials or keys are compromised, they can be further altered without updating the firmware or software on any single device.

[0026] In this embodiment, the pre-associated action is adapted to operate on top of a legacy packet generated using legacy firmware on the user device. The legacy firmware here refers to firmware installed on the device that has exited its firmware update cycle and is therefore degraded. Among other shortcomings, such legacy firmware is unlikely to meet best practices as well as 128-bit or 264-bit encryption ciphers of Secure Sockets Layer (SSL) or Transport Layer Security (TLS). This adaptation may include a pre-associated action to decrypt any legacy encryption, or to use a legacy data format used by such legacy firmware, and / or it may include operating on top of the legacy packet according to instructions designed to work with any legacy encryption.

[0027] A data packet may include many parts. For the purposes of this invention, a packet includes at least a payload containing data intended for use by the intended recipient. The packet may further include a header with metadata, such as receiver / destination information. The packet header may also contain information about the packet sender. The packet sender may provide information about the user identity of the user equipment sending the packet, or information identical to the user identity of the user equipment sending the packet. When the packet is encrypted, the header remains unencrypted, while the payload is encrypted. Regardless of whether the packet has a header, network operators can always associate the packet with a user identity by using the aforementioned header or by including the packet as part of a data session associated with that user identity.

[0028] User identity primarily refers to the International Mobile Subscriber Identity (IMSI) number, but it can be any code, number, or other data that explicitly identifies the user equipment or mobile / sensor device, such as an Integrated Circuit Card Identifier (ICCID), Subscriber Identity / Identification Module (SIM), Subscriber Identification Module Identifier (SIMID), International Mobile Equipment Identity (IMEI) number, or any such explicitly identifying information or number, Endpoint Identifier (EID), Source Internet Protocol (IP) address, or any other such explicitly identifying information. In embodiments, user identity is IMSI, SIM ID, ICCID, SIM, or IMEI. In embodiments, user identity explicitly identifies the user and therefore can be, for example, a SIM ID or IMSI number. In embodiments, user identity is an IMSI number.

[0029] The public internet refers to the network commonly known as the internet, where certain encryption protocols have become the norm and rules, such as SSL / TLS.

[0030] The terms mobile network and telecommunications network are used synonymously in this disclosure to refer to any generation of telecommunications network that provides services to mobile devices worldwide based on users. The network referred to not only needs to have a circuit-switched domain, but is preferably packet-switched. As of this disclosure, at least 2G, as well as 3G, 4G, 5G, and intermediate generations, fall within this scope.

[0031] Some telecommunications networks, such as 2G, 3G, 4G, and 5G, have partially overlapping functions and infrastructure. What all these have in common is that they are user-based and at least partially operated by commercial entities, some of whom have installed access network infrastructure, communication between the access network and / or network core, or operate one or more services of the network core. Certain protocols, such as encryption requirements and packet formats and / or structures, are established for communication on such operator-driven networks. Satellite networks and networks containing satellites are also included.

[0032] This invention can be used with any type of user equipment or manufacturing user equipment. Useful examples are sensor devices / sensor assemblies / sensor modules. Sensor devices on container ships can measure the temperature and pressure of sensitive cargo. This invention is advantageous there, not only because the device can move through different networks, but further because the device can therefore be smaller and simpler, and the lifespan of the installed sensors can be extended.

[0033] Sensor devices can be installed in wind turbines for continuous sensing, offering advantages such as smaller size and / or longer battery life, and firmware updates without manual inspection and updates. Military and police equipment may benefit from enhanced security. Other security-sensitive applications could be user equipment used in situations where there is a risk or possibility of packet interception, in which case the invention achieves packet tamper-proofing by avoiding the transmission of metadata such as destination.

[0034] The invention is described in detail below by way of exemplary embodiments which should not be considered as limiting the scope of the invention.

[0035] In an embodiment, the method further includes the step of transmitting data packets over the public internet. Therefore, packets can be easily transmitted to the recipient via conventional channels while allowing for complex data operations within the network core. Preferably, packets are transmitted over the public internet with best practice encryption (e.g., SSL and / or TLS). Packets are preferably transmitted to a destination determined based on the recipient.

[0036] In an embodiment, the predetermined action includes at least one of encrypting the packet according to a public internet encryption protocol or generating a modified packet by modifying the packet data of the packet.

[0037] Therefore, the network core reduces the computational demands on user devices (such as sensor devices) by providing processed data from the telecommunications network, eliminating the need for each user device to perform that computation itself. This makes the devices cheaper, smaller, and more reliable.

[0038] In this embodiment, the second identifier is a key or authentication code that conforms to public internet encryption protocols, such as a pre-shared key, private key, or login credentials. Therefore, even if the packet is compromised, the device's identifier can be securely transmitted over the public internet without the risk of exposing the device.

[0039] In one aspect, the present invention relates to a computing unit comprising tools for performing the steps of the method of the invention. Therefore, a system is provided that enables user equipment to be miniaturized, durable, and inexpensive by eliminating the SSL / TLS encryption layer traditionally added to user equipment, while providing easier and better control in the network core. Furthermore, it makes packets more tamper-resistant.

[0040] In one aspect, the present invention relates to a computer program including instructions that, when executed by a computing unit, cause the computing unit to perform the steps of the present invention.

[0041] In one aspect, the present invention relates to a computer-readable storage medium including instructions that, when executed by a computing unit, cause the computing unit to perform the steps of the present invention.

[0042] Example A - Encryption

[0043] In an embodiment, the method further includes:

[0044] The pre-defined actions include encrypting the packet according to public internet encryption protocols, and

[0045] The packet can optionally be transmitted via the public internet.

[0046] Therefore, user equipment does not need to perform computationally intensive encryption, but it is still an internet encryption packet when relevant conditions apply.

[0047] This has a series of benefits: it reduces the computing power required on user devices, thereby reducing device size and cost; it reduces telecommunications transmission requirements, allowing the same payload to be transmitted with fewer packets and less total data; it reduces battery consumption, thereby reducing battery size and cost, and thus extending battery life; it eliminates the expensive and difficult firmware updates that are traditionally required whenever encryption standards change; and it further avoids obsolescence on “light computing” user devices when such firmware updates are no longer possible.

[0048] In addition to the public internet, the added encryption layer can be applied to any other domain, as long as the encryption layer follows the specific channel / network through which the packet is intended to be routed.

[0049] In one embodiment, the packet includes encryption that is essentially based solely on the encryption protocol of the telecommunications network.

[0050] In this embodiment, the public internet encryption protocol is a Secure Sockets Layer (SSL) protocol or a Secure Transport Layer (STL) protocol. In this embodiment, the public internet encryption protocol is a STL protocol.

[0051] If needed, certain types of user equipment can: remain programmed to perform relatively simple encryption, making it difficult or impossible for telecommunications network operators to retrieve plaintext packets; or may perform simple encryption for other reasons. The encryption applied in the network core is then simply added "on top" of the receiver's encryption layer. The reduced data transmission requirements that provide the aforementioned benefits remain.

[0052] In this embodiment, any encryption layer of the received packet other than the telecommunications encryption layer has a key length of 127 bits or less. In this embodiment, any encryption layer of the received packet other than the telecommunications encryption layer has the following key lengths: 256 bits or less, 255 bits or less, 250 bits or less, 195 bits or less, 190 bits or less, 127 bits or less, 125 bits or less, 120 bits or less, 111 bits or less, 110 bits or less, 105 bits or less, 55 bits or less, 50 bits or less, 39 bits or less, 35 bits or less, 15 bits or less, 7 bits or less, or 3 bits or less. Therefore, more payload data can be transmitted per packet, thereby reducing transmission requirements, computation time, battery consumption, etc., on the network and on user equipment.

[0053] Example B – Packet Rerouting

[0054] In an embodiment, the method further includes:

[0055] The package may optionally include an original package destination, and the predetermined action then includes providing the package with a recipient package destination that is different from and replaces any original package destination of the package.

[0056] Optionally, the packet can be transmitted to the recipient's packet destination.

[0057] The packet may initially have no destination address at all, or it may have a destination address within the network core, or it may have a destination address outside the network core. The operator picks up the packet, evaluates it against the action database, and then exchanges the packet or provides a predetermined receiving destination for the packet.

[0058] In this embodiment, the destination of the receiving packet is reached via the public Internet.

[0059] This allows user devices to lack information about where their data packets are intended to be transmitted. Traditional user devices have complex firmware with installed encryption protocols and addresses, which are useful information to malicious third parties seeking access to private servers. If a malicious third party gains control of a regular user device, they can reverse engineer or use the firmware directly and potentially gain access to private servers.

[0060] In one embodiment, the received packet has no destination, and the predetermined action includes providing the destination of the received packet to the packet.

[0061] In one embodiment, the received packet has an original destination, and the predetermined action includes replacing the original packet destination with a receiver packet destination that is different from the original destination.

[0062] In cases where packet destinations are processed outside the user equipment but within the network core, firmware does not need to be installed on the user equipment. Instead, any such firmware can be installed within the network core, such as the action database. Therefore, addresses or encryption protocols can be found without tampering with the firmware. In embodiments, data transmitted from such user equipment is kept as unprocessed as conveniently as possible, such as primary sensor data. For example, temperature sensor data can be transmitted as a conductivity measurement between two arbitrary hardware-dependent points, followed by a conversion to Celsius (raw sensor data) within the network core. This eliminates as much context as possible from a given component of the user equipment, making tampering less useful.

[0063] In this disclosure, destination and address are used interchangeably to describe the intended destination of packet transmission. The destination / recipient address can be reached via the public internet as described in Example A or via any other convenient channel, such as through the telecommunications network itself.

[0064] In this embodiment, the destination of the receiving packet can be an empty destination. In other words, in this embodiment, the present invention relates to retaining a packet and then saving or deleting it. This packet retention is preferably one of a set of possible actions for a given packet, and then the packet retention depends on packet or payload analysis. Packet retention is performed in the network core.

[0065] Example C – Payload Modification

[0066] In an embodiment, the method further includes:

[0067] The modified packet is generated by modifying the packet data of the original packet, and

[0068] Optionally, the modified packet can be transmitted to the recipient.

[0069] Modifications include changes made through transformations, additions, subtractions, and other types of alterations. Modifying packet data includes modifying payload data as well as other packet data, such as headers, padding, and / or destinations.

[0070] In this embodiment, modifying the packet includes modifying the payload data. Modifying the payload encompasses several actions that can be taken with the packet, some of which are described below.

[0071] In this embodiment, the received packet includes raw sensor data or primary sensor data.

[0072] In one embodiment, modifying the package includes converting the package's primary sensor data into raw sensor data.

[0073] The primary sensor data here is hardware-dependent data, such as binary data describing conductivity measurements between two arbitrary hardware-dependent points. The conductivity of such a sensor circuit could, for example, be mapped to the temperature of a temperature sensor, or the brightness of an ambient light, or that of a motion sensor. The raw sensor data here is hardware-independent data, such as numbers representing temperature in any unit, such as Celsius, Kelvin, or Fahrenheit, or lumens for brightness / light. The conversion of the primary sensor data to raw sensor data then involves querying sensor-specific hardware tables / functions, such as mapping conductivity to temperature or vice versa. This conversion is traditionally performed by the sensor module's microprocessor.

[0074] By converting primary sensor data into raw sensor data within the network core, user equipment can be smaller, lighter, and cheaper than user equipment that performs its own computations. Packet and payload data can be further made more tamper-proof because such primary sensor data is hardware-dependent and meaningless without context.

[0075] In this embodiment, modifying the payload data includes converting raw sensor data into cleaned sensor data by cleaning outliers and / or erroneous readings from the raw sensor data. This can be performed on top of the raw sensor data in a packet provided by the user equipment, or it can be performed on raw sensor data generated from primary sensor data in the network core. By cleaning the raw sensor data and generating cleaned data, useless data can be removed, thereby reducing transmission requirements.

[0076] In one embodiment, the predetermined action includes generating a modified packet, wherein the modified packet is generated by analyzing the payload data of the packet and modifying the data of the packet based on the analysis.

[0077] Therefore, complex analyses can be performed on data transmitted from user equipment. For example, compared to situations where data must be transmitted over the public internet to a private server for analysis, this allows for the differentiated transmission of error or emergency signals based on specific values, thus necessarily speeding up transmission. Furthermore, if the predetermined action includes changing the recipient based on packet data analysis, this rerouting will further accelerate the recipient's reception of the packet.

[0078] In this embodiment, trend analysis is performed on the payload data, such as statistical analysis or grouping of the results. In this embodiment, trend statistical analysis is performed on the payload data, such as finding / evaluating the median, normal value, or average value.

[0079] In this embodiment, the payload is tested; if it has certain values, a change is performed; if it has other values, another change is performed. Simple overtesting / undertesting can be performed, as well as complex calculations, the functionality of which varies depending on the input values.

[0080] In this embodiment, packet data is compressed based on data analysis of the packet payload. For example, if some sensor readings repeat the same value, these readings can be packaged into a single reading with multiple timestamps.

[0081] In this embodiment, packets are received and analyzed, and data is retransmitted from the network core without regard to the original packet segmentation.

[0082] In one embodiment, extremely computationally intensive calculations are performed on packets within the network core. Such calculations could be prohibitively expensive to implement in traditional user equipment. In this embodiment, blockchain computations are performed on packets within the network core. Therefore, sensor data can be tracked, collected, and processed in a tamper-proof manner.

[0083] In this embodiment, the modification package includes a modification package payload.

[0084] Example D – User Channel

[0085] In one embodiment, the method further includes providing a publicly accessible communication channel to the action database, wherein the user identity belongs to a user profile, and wherein a user who is allowed to access the communication channel using the user profile modifies a predetermined action associated with a user identity belonging to the user profile.

[0086] Channels provide device owners and administrators with a way to control device behavior. A channel can be a user-friendly webpage that leads to the system, followed by a user page containing information about all user identities belonging to that user. It can also be an address accessible through other means, such as the public internet, or an address providing an application programming interface (API). User profiles can have multiple user identities and multiple pre-defined actions.

[0087] Therefore, users such as equipment operators or owners can access and modify the network core programming to install updates or change user equipment package modification rules as they deem appropriate. Such changes take effect immediately on all user equipment without the risk of errors related to equipment updates, etc. In one embodiment, the modification of the predetermined action includes a user-friendly interface that allows selection from alternative actions. In another embodiment, the modification of the predetermined action includes providing an application programming interface (API) that users can use to connect to the firmware.

[0088] This allows for convenient and user-friendly control over pre-defined actions, while maintaining lightweight and tamper-proof packet transmission over telecommunications networks. Attached Figure Description

[0089] In the following description, exemplary embodiments are presented according to the present invention, wherein...

[0090] Figure 1 This is a schematic diagram of existing technologies for packet transmission on mobile networks.

[0091] Figure 2 This is a schematic diagram of packet transmission on a mobile network according to an embodiment of the present invention.

[0092] Figure 3 This is a flowchart of packet transmission according to an embodiment of the present invention, and

[0093] Figure 4 This is a schematic diagram of the core computing unit according to an embodiment of the present invention. Detailed Implementation

[0094] The invention is described in detail below by way of embodiments, which should not be considered as limiting the scope of the invention.

[0095] Figure 1 This is a schematic diagram of a traditional long-distance communication / telecommunications network 1, such as a broadband telecommunications network, and packets 50 transmitted through the telecommunications network. Telecommunications network 1 includes user equipment 10 communicating with an access network 20. Access network 20 may be a radio access network and connects user equipment 10 to a network core 30, which performs telecommunications network actions on the transmitted packets 50. Packets further transmitted to, for example, the public internet 40, also arrive through the network core 30. Private servers 41 can be reached via the public internet 40.

[0096] User equipment 10 has a SIM 12 for identifying subscribers on the network. SIM 12 is important for billing, network access, and other protocols within the functions of telecommunications network 1. Such a SIM 12 can be a physical card or an embedded SIM, and conveniently includes, among other elements, an International Mobile Subscriber Identity (IMSI) that uniquely identifies the user. User equipment 10 can be a mobile device, such as a smartphone or tablet. In the following description, it will be assumed that it is a sensor module suitable for transmitting sensor data from remote areas where telecommunications network 1 provides optimal or unique coverage. Such a sensor module can be mounted in a container to transmit real-time temperature data, location data, images, or other such sensor data that may be valuable for continuous or intermittent retrieval.

[0097] Data packet 50 may be a piece of sensor data generated by the sensor of mobile device 13. When user equipment 10 thus creates packet 50 to be transmitted over telecommunications network 1 for a remote recipient according to existing technology, the following is a standard procedure: Prepare packet 50 for transmission to the recipient on private server 41.

[0098] Initially, packet 50 is prepared on user equipment 10, including the addition of an internet encryption layer 51. User equipment 10 is pre-programmed to apply this encryption using firmware typically developed by the operator of a private server 41. This internet encryption layer 51 is computationally intensive and involves large amounts of data to comply with the stringent encryption requirements of the public internet 40. This encryption is typically SSL or TLS.

[0099] The packet includes a payload and a recipient address. The telecommunications network uses the recipient address to route the packet to its final destination via a series of transmissions. User networks, such as broadband telecommunications network 1, require different protocols to meet different encryption needs, such as ensuring that no one can access the contents of packet 50 on the network. A telecommunications encryption layer 52 is applied to this user device using user or device identity. This could be, for example, a SIM, IMSI, or ICCID.

[0100] When packet 50 is transmitted to private server 41, it passes through network core 30, where the service provider of specific user equipment 10 uses the user identity again to decrypt telecommunications encryption 52.

[0101] After the telecommunications encryption layer 52 is decrypted, packet 50 still has the internet encryption layer 51 and is then transmitted to private server 41 via the public internet 40. On private server 41, firmware is then used to decrypt the internet encryption layer 51.

[0102] Now, the receiver on private server 41 has disassembled packet 50 for sensor data verification, analysis, and other types of data operations. Several packets 50 are then transmitted, and the payload data of the packets, when unencrypted, can constitute continuous sensor readings, interval readings, and such as part of a data transmission session, and depending on the specific circumstances or standards on the network, the packets may include a portion of readings or several readings or any other part of a data file.

[0103] Encryption layers 51 and 52 significantly increase packet size, thereby increasing the load on user equipment 10 and telecommunications network 1 resources. The difference in data size between unencrypted and encrypted packets can be at least 1:10 or 1:100. Furthermore, tightening encryption standards requires increasingly larger user equipment 10 capacities to keep up with the required computing power.

[0104] Figure 2 The diagram illustrates packet transmission via telecommunication network 1 according to the present invention. Telecommunication network 1 is substantially the same. The method of the present invention is considered useful in many situations, one of which is when used with sensor device 14 located at a remote location or in a location with intermittent WIFI or internet coverage, in which case telecommunication network 1 can provide stability or bandwidth. This also illustrates that such sensor device can be fixedly installed.

[0105] It can be seen that user equipment 10 does not need to set up an Internet encryption layer. Instead, a separate telecommunications encryption layer 52 is used to maintain sufficient encryption through the telecommunications network 1. In the network core 30, an action database 31 is set up, which includes a list of user identities and an action matching list. When a packet 50 is received in the network core, the telecommunications encryption layer 52 is decrypted, and the action database 31 is queried to identify the packet sender and match it with a predetermined action or a set of actions.

[0106] Packet 50 can still be encrypted on user equipment 10 according to receiver encryption layer 55 to make the payload tamper-proof. However, such encryption does not need to comply with Internet standards. Furthermore, if such receiver encryption layer 55 is set, the analysis and actions performed on packet 50 also apply to taking it into account. In other words, after the telecommunications encryption has been decrypted, any remaining encryption on packet 50 is transparent to the actions performed in network core 30. This does not mean that the operator of network core 30 can understand packet 50, but only that the operator of network core 30 has been provided with the tools to process packet 50 through any remaining encryption layer 55 or on top of any remaining encryption layer 55.

[0107] In this embodiment, the user identity of the packet is replaced by a mapping identifier that has a predetermined mapping to a specific user identity and is useful or convenient for transmission over the public internet. Such a mapping identifier can be an encrypted pre-shared key, an encrypted private key, or even user login credentials. In any case, when the receiver receives the packet, the mapping identifier allows the location of the user device through the predetermined relationship between the user device and the user identity.

[0108] For a packet 50 transmitted via the public Internet 40 to a private server 41, such a set of actions preferably includes applying a receiver encryption layer 54, which is preferably an Internet encryption layer that conforms to encryption protocols of the public Internet (such as SSL or TLS).

[0109] By placing a computing unit between the user equipment 10 and the receiver in the telecommunications network 1, a number of further options become possible. This computing unit is located in the network core 30 and operates either through any encryption layer of packet 50 or by applying the receiver's encryption layer 54 to the packet. It does this when minimal encryption is required and before the encryption requirements become most demanding (referring to the public internet 40).

[0110] One way in which the present invention works is by expanding the computing power of user equipment to include the computing power of network core 30.

[0111] Figure 3 This is a flowchart of an embodiment of the method of the present invention. The method first receives packet 50 from user equipment 10 in network core 30. The packet sender is a user on the network, and the packet may have a destination, such as the private server of the owner of a particular user equipment 10 or its subcontractor. Optionally, telecommunications network operators can always intercept packets from their users, so packets without a destination will still reach network core 30.

[0112] Next, the telecommunications encryption layer 52 is decrypted using the protocols of the telecommunications network, such as using the user's identity to decrypt the packet. Any decryption scheme that matches the encryption protocol of the telecommunications network can be used in conjunction with the decryption step. This ensures that the method complies with the regulations of the telecommunications network and prepares the packet for further processing.

[0113] Then, the action database 31 stored in the network core 30 is queried. The user identity is used to match a series of predetermined actions to be performed for that specific user identity. These actions are designed by or for the receiver based on the specific implementation of the user equipment. Sensor data from sensor modules on container ships will perform a series of actions before being transmitted to the ship or container manager, while pump operation sensors may require multiple different sets of actions before being transmitted to the pump operator.

[0114] After identifying the action or list of actions, these actions are executed in the network core of the telecommunications network.

[0115] For most packets, they are then transmitted to the receiving destination.

[0116] Figure 4 This is a schematic diagram of the core computing unit according to the present invention. The access network 20 captures packet 50 transmitted from user equipment 10. The packet is then routed through the telecommunications network, ultimately entering the network core 30 via network interface 34 and reaching the core computing unit 36. The core computing unit 36 ​​is a computing unit located in the network core 30, which is adapted to perform various actions on services over the telecommunications network.

[0117] The core computing unit 36 ​​has a processor 33 for executing instructions and a memory 35 for storing data required for executing instructions. The core computing unit 36 ​​further has an action database 31 and at least other associated databases 32, which can be queried. When a packet arrives at the core computing unit 34, and after the telecommunications encryption is decrypted, the action database 31 is queried to determine what the core computing unit 36 ​​should do for that particular packet 50. Such an action can, in principle, be unique for all user identities, or a single action or a group of actions can be attributed to a series of user identities, such as if belonging to the same recipient.

[0118] Once the core computing unit 36 ​​has performed the prescribed actions on packet 50, the now potentially modified packet 50' is further transmitted to its intended destination.

Claims

1. A computer-implemented method comprising: receiving a packet (50) from a user device (10) through an access network (20) of a telecommunication network (1), the packet (50) having a user identity of the user device (10) and being encrypted according to a protocol of the telecommunication network (1), decrypting the packet (50) according to the protocol of the telecommunication network (1) using the user identity in a network core (30) of the telecommunication network (1), finding a predetermined action stored in an action database (31) of the network core (30) that is pre-associated with the user identity of the packet (50), and performing the predetermined action on the packet (50) in the network core (30), the predetermined action comprising generating a user-specific modified packet (50') by modifying payload data of the packet (50) based on the user identity of the user device.

2. The method of claim 1, wherein the predetermined action further comprises: replacing the user identity in the packet with a mapping identifier from a mapping database, the mapping identifier being specific to the user identity and being used by a recipient of the packet after transmission through a public internet for identifying and / or authenticating the user device (10), the mapping identifier being a key or a digest following a public internet encryption protocol, including a pre-shared key, a private key or login credentials.

3. The method according to claim 2, wherein the public internet encryption protocol is a Secure Sockets Layer protocol or a Transport Layer Security protocol.

4. The method according to any of claims 1-3, wherein the predetermined action comprises generating a modified packet (50') wherein the modified packet (50') is generated by analyzing payload data of the packet (50) and modifying the data of the packet based on the analysis.

5. The method according to any of claims 1-4, wherein any other encryption layer (51, 54) of the received packet (50) other than a telecommunication encryption layer (52) has a key length of 127 bits or less.

6. The method according to any of claims 1-5, wherein the packet comprises encryption according to substantially only the encryption protocol of the telecommunication network (1).

7. The method according to any of claims 1-6, wherein the received packet can comprise an original packet destination, and wherein the predetermined action comprises providing the packet with a recipient packet destination that is different from and replaces any original packet destination of the packet.

8. The method according to claim 7, wherein the recipient packet destination is reached through a public internet.

9. The method according to any of claims 1-8, wherein the received packet comprises primary sensor data or raw sensor data.

10. The method according to any of claims 1-9, wherein the predetermined action comprises converting the primary sensor data of the packet to raw sensor data.

11. The method according to any of claims 1-10, further comprising transmitting the packet (50) through a public internet (40).

12. The method according to any one of claims 1-11, further comprising providing a publicly accessible communication channel to the action database (31), wherein the user identity belongs to a user profile, and wherein a user allowed to access the communication channel using the user profile is allowed to modify a predetermined action associated with the user identity belonging to the user profile.

13. A computing unit (36) for processing packets in a network core (30) of a telecommunication network (1), the computing unit comprising a processor (33) and a memory (35), the memory containing instructions which, when executed by the processor (33), cause performing the following method: receiving a packet (50) from a user equipment (10) through an access network (20) of a telecommunication network (1), the packet (50) having a user identity of the user equipment (10) and being encrypted according to a protocol of the telecommunication network (1), decrypting the packet (50) according to the protocol of the telecommunication network (1) using the user identity in a network core (30) of the telecommunication network (1), finding a predetermined action pre-associated with the user identity of the packet (50) stored in an action database (31) of the network core (30), and performing the predetermined action on the packet (50) in the network core (30), the predetermined action comprising: generating a user-specific modified packet (50') by modifying payload data of the packet (50) based on the user identity of the user equipment.

14. A computer program product comprising instructions which, when executed by a computing unit (36), cause the computing unit (36) to perform the following method: receiving a packet (50) from a user equipment (10) through an access network (20) of a telecommunication network (1), the packet (50) having a user identity of the user equipment (10) and being encrypted according to a protocol of the telecommunication network (1), decrypting the packet (50) according to the protocol of the telecommunication network (1) using the user identity in a network core (30) of the telecommunication network (1), finding a predetermined action pre-associated with the user identity of the packet (50) stored in an action database (31) of the network core (30), and performing the predetermined action on the packet (50) in the network core (30), the predetermined action comprising: generating a user-specific modified packet (50') by modifying payload data of the packet (50) based on the user identity of the user equipment.

15. A computer-readable storage medium comprising instructions which, when read and executed by a computing unit (36), cause the computing unit (36) to perform the following method: receiving a packet (50) from a user equipment (10) through an access network (20) of a telecommunication network (1), the packet (50) having a user identity of the user equipment (10) and being encrypted according to a protocol of the telecommunication network (1), decrypting the packet (50) according to the protocol of the telecommunication network (1) using the user identity in a network core (30) of the telecommunication network (1), finding a predetermined action pre-associated with the user identity of the packet (50) stored in an action database (31) of the network core (30), and generating a user-specific modified packet (50') by modifying payload data of the packet (50) based on the user identity of the user equipment. performing the predetermined action on the packet (50) in the network core (30), the predetermined action comprising: A user-specific modified packet (50') is generated by modifying the payload data of the packet (50) based on a user identity of the user equipment.

Citation Information

Patent Citations

  • Proxy for serving internet-of-things (IOT) devices

    US20180288179A1

  • Gateway computer system with intermediate data processing according to rules that are specified by templates

    US20190068406A1