Improved Packet Forwarding
The method addresses the challenges of remote sensor devices in telecommunication networks by implementing packet handling and modification in the network core, enhancing performance, security, and flexibility while extending device lifespan and reducing battery consumption.
Patent Information
- Application Number
- JP2022548971
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-02-13
- Filing Date
- 2021-02-12
- Publication Date
- 2025-05-19
- Estimated Expiration
- 2041-02-12
AI Technical Summary
Remote sensor devices in telecommunication networks face challenges in performance, security, and flexibility due to increasing encryption requirements, battery power depletion, and vulnerability to malicious access.
A method implemented in the network core of a telecommunication network that involves receiving and decrypting packets, finding and performing predetermined actions stored in an action database associated with the subscriber identification, and optionally modifying the packets by replacing identifiers or modifying payload data.
This solution enhances the performance, security, and flexibility of remote sensor devices by offloading computationally intensive tasks to the network core, extending device lifespan, reducing battery consumption, and improving security against malicious access.
Smart Images

Figure 0007679389000001 
Figure 0007679389000002 
Figure 0007679389000003
Abstract
Description
Technical Field
[0001] The present invention relates to a method for improving data handling, packet routing, and operation thereof in a packet switching network core of a telecommunication network, and a computer system, program, and physical storage medium for executing the method.
Background Art
[0002] What is important in the new developments of automation, Internet of Things (IoT), and the Fourth Industrial Revolution is an embedded sensor that enables device and process monitoring. Due to increased usage stability and cost reduction, such sensor devices have become more cost-effective in a greater number of industries. Such devices also have a microcontroller, memory, and often an antenna for communication over a network.
[0003] The software installed in such devices becomes obsolete due to the ever-increasing encryption requirements on the network and data packet receiving side. So-called "zero-day" vulnerabilities are just one example of events that can also expose sensor devices to malicious third parties, and others are the improvement of hackers' computing power. Today, this is solved by software updates and the installation of new and better sensor devices.
[0004] Embedded sensors are often remotely located and thus cannot be powered via cables. Conventionally, this has been solved by using a battery in the sensor to supply power for sensing, data manipulation, and data packet transmission. The need for improved encryption to avoid malicious third parties requires more computing power and data transmission, further depleting battery power and increasing device cost. Also, if a malicious third party gains access to the sensor device, that third party may misuse the sensor device to find the recipient's address and potentially find keys that compromise the encryption of multiple devices. This is solved by using sufficiently strong encryption and / or making the sensor device inaccessible.
[0005] Accordingly, there is a need for a solution to increase the performance, security, and flexibility of remote sensor devices. SUMMARY OF THE INVENTION
[0006] In one aspect, a method implemented by a computer, comprising: receiving a packet from a user device via an access network of a telecommunications network, the packet having a subscriber identification of the user device and being encrypted in the access network according to the protocol of the telecommunications network; decrypting the packet according to the protocol of the telecommunications network using the subscriber identification in the network core of the telecommunications network; comprising: finding a predetermined action stored in an action database of the network core that is pre-associated with the subscriber identification of the packet; performing the predetermined action on the packet in the network core; A method characterized by is provided.
[0007] In a second aspect, a method implemented by a computer, comprising: receiving, via an access network of a telecommunication network, a packet from a user equipment, the packet having a subscriber identifier of the user equipment and being encrypted in the access network according to the protocol of the telecommunication network; decrypting the packet in the network core of the telecommunication network according to the protocol of the telecommunication network using the subscriber identifier; The method further comprises: finding a predetermined action stored in an action database of the network core pre-associated with the subscriber identifier of the packet; performing the predetermined action on the packet in the network core; The method is characterized in that the predetermined action is: replacing the subscriber identifier in the packet with a second identifier from a correlation database, the second identifier being specific to the subscriber identifier and useful for identifying and / or authenticating the user equipment by a recipient of the packet after transmission on the public Internet; or generating a modified packet by modifying the payload data of the packet A method is provided.
[0008] This enables improvements such as those described above to be implemented centrally in the network core when regulations change, when errors in the device's firmware are identified, or when optimization is performed on the firmware. And the update becomes quick and inexpensive and is immediately applied to all user devices affected. By enabling such easy firmware updates, the computing requirements on the computer for the firmware no longer depend on the computing power of the user device, so the lifespan of the user device is significantly extended. This also liberates firmware design from platform-specific work and optimization at the hardware level. Instead, in one or several larger systems, the firmware can be made as efficient and effective as possible.
[0009] For example, it is not uncommon for a user device manufacturer to provide firmware updates for a particular product for only a few years, such as five or ten years, after which the manufacturer is not guaranteed that the user device can still perform the necessary computer operations to run the firmware properly. By offloading the computer operations to the network core, such updates can be executed centrally and the computer operations can grow without removing the user device.
[0010] As a result, the user device can be small, inexpensive, and simple. It can also be user-friendly as it no longer requires firmware updates.
[0011] Also, since the user device can be constructed to take advantage of this computing offloading, it can be produced without significant computing power in the first place. And such user devices can be very small, inexpensive, simple, and have an even longer battery life.
[0012] Furthermore, older user / sensor devices that are approaching the end of their lifespan or are no longer used for reasons related to the computer can be made to remain in service or be reintroduced through the use of this method. This is achieved by installing updated firmware in the network core, receiving packets from the older devices, performing any necessary legacy decryption, and then finding and executing a predetermined action.
[0013] Subscriber identification is also referred to as the first identifier, and the associated identifier becomes the second identifier.
[0014] Furthermore, the method enables the network core to receive telecommunications-specific packets and prepare them for transmission over the public Internet by associating the associated identifier with the subscriber identification. Such an associated identifier identifies the subscriber identification, and as a result, when a packet is received at a private server such as a cloud database, the associated identifier enables the user device to be traced by referring to a collation association database. The second identifier can be a pre-shared key, private key, or login authentication information that a user or the like has.
[0015] This association enables a private server such as a cloud server to identify and authenticate the device, thus ensuring that it is legitimate. Any authentication information or keys can be further changed without the need to update the firmware or software for any individual device if they are compromised.
[0016] In one embodiment, pre-associated actions are adapted to act on legacy packets generated using legacy firmware on a user device. Legacy firmware is here the firmware installed on the device that has become worthless because it has fallen out of the firmware update cycle. Such legacy firmware may not conform to best practices such as, among other deficiencies, the cipher for 128 or 264-bit encryption of Secure Sockets Layer (SSL) or Transport Layer Security (TLS). This adaptation may include pre-associated actions to decrypt any legacy encryption, or act in the legacy data formats used by such legacy firmware, and / or act on the legacy packets according to instructions designed to act by any legacy encryption.
[0017] A packet may comprise a number of parts. For the purposes of the present invention, a packet comprises at least a payload having data for use by an intended recipient. The packet may further have a header having metadata such as receiver / destination information. The packet header may also have information regarding the packet sender. The packet sender may provide or be identical to information regarding the subscriber identification of the user device that sent the packet. When the packet is encrypted, while the payload is encrypted, the header remains unencrypted. Whether or not the packet has a header, the packet can always be associated with subscriber identification by the network operator by using the header as described above or making the packet part of a data session associated with subscriber identification.
[0018] Subscriber identification, as a rule, means an International Mobile Subscriber Identity (hereinafter, IMSI) number, which can be an Integrated Circuit Card Identifier (hereinafter, ICCID), Subscriber Identity Module (hereinafter, SIM), Subscriber Identity Module Identification (hereinafter, SIM ID), International Mobile Equipment Identity (hereinafter, IMEI) number, any such positive identification information or number, Endpoint Identifier (hereinafter, EID), source Internet Protocol (hereinafter, IP) address, or any other such positive identification information, such as any code, number, or other data that positively identifies a user equipment or mobile device / sensor device. In certain embodiments, subscriber identification is an IMSI, SIM ID, ICCID, SIM, or IMEI. In certain embodiments, subscriber identification can be, for example, a SIM ID or an IMSI number, as it positively identifies the subscriber. In certain embodiments, subscriber identification is an IMSI number.
[0019] The public Internet means the network generally referred to as the Internet, where specific cryptographic protocol standards and rules, such as SSL / TLS, are in place.
[0020] The terms mobile network and telecommunications network are used synonymously throughout this disclosure to denote any generation of telecommunications network that provides services to mobile devices worldwide on a per-subscriber basis. The network so denoted must be higher than the circuit-switched domain and is preferably packet-switched. At the time of this disclosure, this includes at least 2G as well as 3G, 4G, 5G, and generations in between.
[0021] Multiple telecommunications networks exist with partially overlapping functions and infrastructure, such as 2G, 3G, 4G, and 5G. What is common to all of these is that they are subscriber-based, at least to some extent operated by commercial organizations, and some of them install access network infrastructure, communication between access networks, and / or a network core, or operate one or more services of the network core. Specific protocols are established for communication on such operator-driven networks, such as encryption requirements and packet format and / or structure. Also included are satellite networks and networks including satellites.
[0022] Any type or kind of user equipment can be used according to the present invention. Useful examples are sensor devices / sensor modules. Sensor devices on container ships can measure the temperature and pressure of delicate cargo. Here, the present invention is beneficial because not only can the device move through different networks, but as a result, the device can be made smaller and simpler, and the lifespan of the installed sensors can be extended.
[0023] Sensor devices may be installed on wind turbines for continuous sensing, taking advantage of the fact that they are small devices and / or have a longer battery life, and can update firmware without the need for manual inspection and updating. Military and police devices can benefit from enhanced security. Other security-sensitive applications can be user devices used when there is a risk or threat of packet eavesdropping. Here, the present invention makes the packet tamper-resistant by removing transmission metadata such as the destination.
[0024] In the following, the present invention will be described in detail through its exemplary embodiments, which should not be construed as limiting the scope of the present invention.
[0025] In one embodiment, the method further comprises the step of transmitting data packets over the public Internet. Thereby, while enabling advanced data manipulation in the network core, the packets are easily transmitted to the recipient via conventional channels. The packets are preferably transmitted over the public Internet by encryption of best practices associated with the public Internet such as SSL and / or TLS. The packets are preferably transmitted to a destination specified by the recipient.
[0026] In one embodiment, a predetermined action includes at least one of encrypting the packet according to a public Internet cryptography protocol or generating a modified packet by modifying the packet data of the packet.
[0027] Thereby, the network core is utilized to reduce the need for calculations on user devices such as sensor devices by providing processed data from the telecommunications network without requiring each user device to perform this calculation itself. This enables cheaper, smaller and more reliable devices.
[0028] In one embodiment, the second identifier is a key or authentication code compliant with a public Internet cryptography protocol such as a pre-shared key, a private key or login authentication information. Thereby, even if the packet is damaged, the identification of the device can be securely transmitted over the public Internet without the risk of device exposure.
[0029] In one aspect, the present invention relates to a computing unit comprising means for performing the steps of the method of the present invention. Thereby, a system is provided that enables smaller, longer-lived and cheaper user equipment by removing the SSL / TLS encryption layer conventionally added to user equipment while providing easier and better control to the network core. The packets will be even more tamper-resistant.
[0030] In one aspect, the present invention relates to a computer program comprising instructions that, when executed by a computing unit, cause the computing unit to perform the steps of the present invention.
[0031] In one aspect, the present invention relates to a computer-readable storage medium comprising instructions that, when executed by a computing unit, cause the computing unit to perform the steps of the present invention.
[0032] Example A - Encryption In certain embodiments, the method comprises: performing a predetermined action including encrypting a packet according to a public internet encryption protocol; and optionally, transmitting the packet over the public internet. It further includes the above.
[0033] Thereby, when the user equipment is involved, the packet remains encrypted with respect to the internet while eliminating the need to perform computationally intensive encryption.
[0034] Thereby, benefits are chained. It reduces the required computing power at the user equipment and as a result the size and cost of the device. It reduces telecommunications transmission requirements, enabling the same payload to be transmitted while using fewer packets and a smaller total data volume. It reduces battery consumption and as a result battery size and cost, and extends battery life. It eliminates the need for expensive and difficult firmware updates that were conventionally required each time the encryption standard changed. And it further avoids rendering the device obsolete in the event that such firmware updates become unavailable on "computationally light" user equipment.
[0035] As long as the encryption layer complies with a specific channel / network for which the packet is intended to be routed, the added encryption layer can comply with any other area of activity instead of the public internet.
[0036] In one embodiment, the packet has encryption substantially only in accordance with the cryptographic protocol of the telecommunications network.
[0037] In one embodiment, the public Internet cryptographic protocol is the Secure Sockets Layer protocol or the Transport Layer Security protocol. In one embodiment, the public Internet cryptographic protocol is the Transport Layer Security protocol.
[0038] If necessary, some types of user equipment may be programmed to perform a relatively simple encryption that makes it difficult or impossible for an operator of the telecommunications network to obtain the plain text packet, or the simple encryption may be performed for other reasons. Thereafter, the encryption applied to the network core will simply be added "on top" of this receiver encryption layer. The reduction in data transmission requirements that provides the above benefits remains.
[0039] In one embodiment, any additional encryption layer for the received packet in addition to the telecommunications encryption layer has a key length of 127 bits or less. In one embodiment, any additional encryption layer in addition to the telecommunications encryption of the received packet has a key length of 256 bits or less, 255 bits or less, 250 bits or less, 195 bits or less, 190 bits or less, 127 bits or less, 125 bits or less, 120 bits or less, 111 bits or less, 110 bits or less, 105 bits or less, 55 bits or less, 50 bits or less, 39 bits or less, 35 bits or less, 15 bits or less, 7 bits or less, or 3 bits or less. This allows more payload data to be transmitted for each packet, thus reducing transmission requirements, computation time, battery consumption, etc. in the network and user equipment.
[0040] Example B - Packet Re - routing In one embodiment, the method is, The packet initially optionally has a packet destination, and the predetermined action includes supplying to the packet a recipient packet destination different from any of the initial packet destinations of the packet and replacing any of the initial packet destinations of the packet, and optionally transmitting the packet to the recipient packet destination further includes.
[0041] The packet may initially have no destination address at all, may have a destination address within the network core, or may have a destination address outside the network core. The operator extracts the packet, evaluates it against an action database, swaps out the packet, or provides a predetermined recipient destination to the packet.
[0042] In some embodiments, the recipient packet destination is reached via the public Internet.
[0043] This allows the user equipment not to have information about where the packet is intended to be transmitted. Conventional user equipment has an encryption protocol and advanced firmware installed with an address, both of which are useful information for malicious third parties who want to access a private server. If a malicious third party can control through a conventional user equipment, such a third party can reverse-engineer the firmware or use it directly, gaining access to the private server.
[0044] In some embodiments, the received packet has no destination, and the predetermined action includes supplying a recipient packet destination to the packet.
[0045] In some embodiments, the received packet has an initial destination, and the predetermined action includes replacing the initial packet destination with a recipient packet destination different from the initial destination.
[0046] When the packet destination is outside the user equipment but is handled within the network core, the firmware need not be installed on the user equipment. Instead, any such firmware may be installed in the network core, such as an action database. Thus, there is no firmware subject to tampering to discover an address or encryption protocol. In some embodiments, data transmitted from such user equipment is not handled as conveniently as possible, such as primary sensor data. For example, temperature sensor data may be transmitted as a conductivity measurement between any two points that depends on the hardware, and then the conversion to degrees Celsius (the original sensor data) is performed within the network core. This will strip away as many contexts as possible for a given user equipment, making tampering useless.
[0047] In the present disclosure, destination and address are used interchangeably to describe the intended endpoint of a packet transmission. The recipient's destination / recipient's address is reachable via any other convenient channel, such as via the public Internet as described for Example A, or via the telecommunications network itself.
[0048] In some embodiments, the recipient packet destination may be a null destination. In other words, in this embodiment, the present invention relates to holding a packet and maintaining or deleting it. This packet holding is preferably one of a set of possible actions for a given packet, and this packet holding depends on packet or payload parsing. The packet holding is performed in the network core.
[0049] Example C - Payload Modification In some embodiments, the method generating a modified packet by modifying the packet data of the above packet, and optionally, transmitting the modified packet to the recipient further includes.
[0050] Modifications include changes by conversion, addition, subtraction, and other types of alterations. Modifying packet data includes modifying the payload data as well as other packet data such as headers, padding, and / or destinations.
[0051] In certain embodiments, modifying the packet includes modifying the payload data. Modifying the payload includes a plurality of actions that can be taken on the packet, some of which are described below.
[0052] In certain embodiments, the received packet comprises raw sensor data or primary sensor data.
[0053] In certain embodiments, modifying the packet includes converting the primary sensor data of the packet to raw sensor data.
[0054] Primary sensor data is here hardware - dependent data such as binary data describing a conductivity measurement between any two points that is hardware - dependent. The conductivity of such a sensor circuit can correspond, for example, to the temperature of a temperature sensor or the brightness of the environment of a light sensor or motion sensor. Raw sensor data is here hardware - dependent data such as temperature in any unit such as Celsius, Kelvin, or Fahrenheit, or a numerical value representing lumens for brightness / light. And converting primary sensor data to raw sensor data includes referring to sensor - specific tables / functions of the hardware, such as associating conductivity and temperature or conductivity and brightness. Such conversions are conventionally performed by the microprocessor of the sensor module.
[0055] By converting the primary sensor data into raw sensor data in the network core, the user equipment can be made smaller, lighter, and less expensive than user equipment that performs its own calculations. Since such primary sensor data is hardware-dependent and meaningless without context, the packets and payload data can be made even more tamper-resistant.
[0056] In certain embodiments, modifying the payload data includes converting the raw sensor data into cleaned sensor data by cleaning the raw sensor data for outliers and / or error measurements. This can be performed on the raw sensor data provided in the packet by the user equipment or on the raw sensor data generated from the primary sensor data in the network core. By cleaning the raw sensor data to produce cleaned data, redundant data is removed, reducing the transmission requirements.
[0057] In certain embodiments, the predetermined action includes generating a modified packet, the modified packet being generated by analyzing the payload data of the packet and modifying the packet data based on the analysis.
[0058] Thereby, advanced analysis can be performed on the data transmitted from the user device. For example, this enables an error or emergency signal to be transmitted in a different manner based on a specific value, which qualitatively speeds up delivery compared to situations where the data needs to be transmitted over the public Internet to a private server for data analysis. Also, if the predetermined action includes changing the recipient based on packet data analysis, such rerouting qualitatively further speeds up the receipt of the packet by the recipient.
[0059] In certain embodiments, the payload data is subjected to trend analysis, such as statistical analysis or grouping of results. In certain embodiments, the payload data is subjected to statistical analysis of trends, such as determining / evaluating the median, normal value, or average value.
[0060] In certain embodiments, a test is performed on the payload, and if it has a particular value, one change is made, and if it has another value, another change is made. A simple over / under test may be performed, or complex calculations may be performed where the function changes as a result of the input value.
[0061] In certain embodiments, the packet data is compressed based on analysis of the packet payload. For example, if specific sensor measurements repeat the same value, they may be grouped into a single measurement along with multiple timestamps.
[0062] In certain embodiments, a packet is received and analyzed, and the data is resent from the network core regardless of the original packet segmentation.
[0063] In certain embodiments, extremely computationally intensive calculations are performed on packets in the network core. Such calculations can sometimes be prohibitively expensive to perform on conventional user equipment. In that embodiment, blockchain calculations are executed on packets in the network core. This makes the sensor data traceable and enables it to be collected and processed in a tamper-resistant manner.
[0064] In certain embodiments, modifying a packet consists of modifying the packet payload.
[0065] Example D - User Channel In one embodiment, the method further includes providing a publicly accessible communication channel to the action database, where the subscriber identification belongs to a user profile, and a user who accesses the communication channel using the user profile is permitted to modify a predetermined action associated with the subscriber identification belonging to the user profile.
[0066] The channel provides a way for the owner and administrator of the device to control the behavior of the device. The channel may be a user-friendly web page with a login screen, and behind the login screen there is a user page having information about all subscriber identifications belonging to the user. It may also be an address accessible via other means, such as being accessed via the public Internet through other means such as providing an application programming interface. The user profile may have a plurality of subscriber identifications and a plurality of predetermined actions.
[0067] Thereby, a user such as an operator or owner of the device can access the programming of the network core, modify it to install updates, or change the user equipment packet modification rules as deemed appropriate. Such changes become effective immediately across all user equipment without the risk of errors in device updates. In one embodiment, modifying a predetermined action includes enabling a user-friendly interface to select between alternative actions. In one embodiment, modifying a predetermined action includes providing an application programming interface through which the user can interface with the firmware.
[0068] This enables a convenient and user-friendly control of predetermined actions while maintaining lightweight and tamper-resistant packet transmission in a telecommunications network.
[0069] In the following, exemplary embodiments will be described in accordance with the present invention.
Brief Description of the Drawings
[0070]
Figure 1
Figure 2
Figure 3
Figure 4
Embodiments for Carrying Out the Invention
[0071] Hereinafter, the present invention will be described in detail through its embodiments, which should not be construed as limiting the scope of the present invention.
[0072] FIG. 1 is a schematic diagram of a conventional telecommunication / telecommunication network 1 such as a broadband telecommunication network, and a packet 50 transmitted via the telecommunication network. The telecommunication network 1 includes user equipment 10 that communicates with an access network 20. The access network 20 is a wireless access network and can connect the user equipment 10 to a network core 30 that performs telecommunication network actions on the packet 50. Regarding the packet further transmitted to the public Internet 40 or the like, this can also be reached via the network core 30. The private server 41 is reachable via the public Internet 40.
[0073] The user device 10 has a SIM 12 for identifying subscribers on the network, which is important for charging, network access, and other protocols internal to the functions of the telecommunications network 1. This SIM 12 can be a physical card or an embedded SIM, and among other elements, it appropriately has an International Mobile Subscriber Identity (IMSI) that uniquely identifies the subscriber. The user device 10 can be a mobile device such as a smartphone or a tablet. In the following description, it is assumed that it has a sensor module adapted to transmit sensor data from a remote area, and the telecommunications network 1 provides the best or the only coverage. Such a sensor module is mounted on a container and can transmit live temperature data, location data, images, or other types of sensor data that may be valuable to obtain continuously or intermittently.
[0074] The packet 50 can be one of the sensor data generated by the sensors of the mobile device 13. Thus, when the user device 10 creates a packet 50 for a remote recipient to be transmitted over the telecommunications network 1 according to the prior art, the following is the conventional process. The packet 50 is prepared for transmission to the recipient on the private server 41.
[0075] First, the packet 50 is prepared for one of the user devices 10 and includes adding an Internet encryption layer 51. Such a user device 10 is usually pre-programmed to apply this encryption by using firmware developed by the operator of the private server 41. To comply with the strict encryption requirements of the public Internet 40, this Internet encryption layer 51 is computationally intensive and data-heavy. Such encryption is usually SSL or TLS.
[0076] A packet comprises a payload and a recipient address, by use of which a telecommunications network can ultimately route the packet to the recipient's destination via a series of transmissions. Subscriber networks such as broadband telecommunications network 1 require various protocols to meet various encryption needs, such as ensuring that no one on the network can access the content of packet 50. The telecommunications encryption layer 52 is applied to each user device using subscriber identification or device identification. This can be, for example, a SIM, IMSI or ICCID.
[0077] Packet 50 passes through the network core 30 when proceeding towards the private server 41. Here, the subscriber identification is reused by the service provider of a particular user device 10 to lift the telecommunications encryption layer 52.
[0078] After lifting the telecommunications encryption layer 52, packet 50 still has the Internet encryption layer 51 and is then transmitted to the private server 41 via the public Internet 40. At the private server 41, the Internet encryption layer 51 is then decrypted using firmware.
[0079] Here, the receiver at the private server 41 unpacks packet 50 for sensor data verification, analysis and other types of data manipulation. And when multiple packets 50 are transmitted, the payload data of the packets, if not encrypted, constitutes continuous sensor measurements such as those of a data transmission session, interval measurements, etc., and the packets can comprise one measurement or a portion of multiple measurements or some other portion of a data file, in a practical or standard manner in the network.
[0080] The Internet encryption layers 51, 52 significantly increase the packet size, thus increasing the load on the resources of the user device 10 and the telecommunication network 1. The difference between an unencrypted packet and an encrypted packet can be at least a 1:10 or 1:100 magnification in terms of data size. Also, as the encryption standard is tightened, the capabilities of an increasingly large-scale user device 10 are required to keep up with the necessary computing power.
[0081] Figure 2 shows packet transmission on the telecommunication network 1 according to the present invention. The telecommunication network 1 itself is substantially the same. The method of the present invention is considered useful in many situations, one of which is when used with the sensor device 14 and located remotely or in a location with intermittent WIFI or Internet coverage, where the telecommunication network 1 can provide stability or bandwidth. This also shows that such sensor devices can be fixedly installed.
[0082] As can be understood, the user device 10 is not required to provide an Internet encryption layer. Instead, the telecommunication encryption layer 52 is used alone to maintain sufficient encryption via the telecommunication network 1. In the network core 30, an action database 31 with a list of subscriber identifications and a matching list of actions is provided. When a packet 50 is received in the network core, the telecommunication encryption layer 52 is decrypted, and the action database 31 is referenced to identify the packet sender and match it with a predetermined action or a set of actions.
[0083] Packet 50 may still be encrypted at one of the user devices 10 according to the recipient encryption layer 55 so that the payload is tamper-resistant. However, this encryption does not need to comply with Internet standards. Also, when such a recipient encryption layer 55 is provided, the analysis and actions performed on packet 50 are similarly adapted to take it into account. In other words, any encryption remaining in packet 50 can be made transparent with respect to the actions performed in the network core 30 after the telecommunications encryption has been decrypted. This does not mean that the operator of the network core 30 can understand packet 50, but only that tools acting on packet 50 via or on top of any remaining recipient encryption layer 55 are provided to the operator of the network core 30.
[0084] In certain embodiments, the subscriber identification of the packet is replaced with an associated identifier having a predetermined association to a specific subscriber identification and adapted to be useful or advantageous when transmitted over the public Internet. Such an associated identifier can be a pre-shared key for cryptography, a private key for cryptography, or even user login authentication information. In any case, when the recipient receives the packet, the associated identifier enables discovery of the user device by its predetermined relationship to the subscriber identification.
[0085] For packets 50 transmitted via the public Internet 40 to the private server 41, preferably, such a set of actions includes applying a recipient encryption layer 54, which is an Internet encryption layer that preferably complies with a public Internet cryptography protocol such as SSL or TLS.
[0086] By providing a computing unit between the user equipment 10 of the telecommunications network 1 and the recipient, a number of additional options become available. Such a computing unit is located in the network core 30, acts through any of the encryption layers of the packet 50, or applies the recipient encryption layer 54 to the packet. The computing unit does this when the least amount of encryption is required and at a point in time before the encryption requirements become as strict as those of the public Internet 40.
[0087] One aspect in which the present invention operates is by extending the computing power of the user equipment to include the computing power of the network core 30.
[0088] Figure 3 is a flowchart of a method according to an embodiment of the present invention. The method begins in the network core 30 by receiving a packet 50 from the user equipment 10. The packet sender is a subscriber to the network, and the packet may have a destination such as the owner of a particular user equipment 10 or a private server commissioned by it. Alternatively, the operator of the telecommunications network can always intercept the packets of its subscribers, and packets without a destination will still arrive at the network core 30 as a result.
[0089] Next, the telecommunications encryption layer 52 is decrypted using the protocol of the telecommunications network, such as decrypting the packet using the subscriber identification. Any decryption method that matches the encryption protocol of the telecommunications network can be used in the decryption step. This ensures that the method complies with the regulations of the telecommunications network and prepares the packet for further processing.
[0090] Then, the action database 31 stored in the network core 30 is referenced. The subscriber identification is used to match a series of predetermined actions executed for the specific subscriber identification. These actions are designed by or for the recipient based on a specific example of each user device. Sensor data from the sensor module on the container ship has a series of actions to be executed before being transmitted to the administrator of the ship or container, while the pump operation sensor may require a different set of actions before being transmitted to the pump operator.
[0091] After an action or a list of actions is identified, the action is executed in the network core of the telecommunications network.
[0092] For most packets, they are then transmitted to the recipient's destination.
[0093] FIG. 4 is a schematic diagram of a core computing unit according to the present invention. The access network 20 captures the packet 50 transmitted from the user device 10. Then, it is routed through the telecommunications network and finally enters the network core 30 and passes through to the core computing unit 36 via the network interface 34. The core computing unit 36 is a computing unit located in the network core 30 adapted to perform various actions on the traffic on the telecommunications network.
[0094] The core computing unit 36 has a processor 33 for executing instructions and a memory 35 for storing data necessary for the execution of instructions. The core computing unit 36 further has an action database 31 and at least one other associated database 32, and can refer to these. When a packet arrives at the core computing unit 36, after the telecommunication encryption is decrypted, the action database 31 is referred to in order to find out what the core computing unit 36 is to do with a particular packet 50. Such actions can in principle be unique for all subscriber identifications. Alternatively, a single action or a set of actions can result from a series of subscriber identifications, such as when belonging to the same recipient.
[0095] When the core computing unit 36 performs a prescribed action on the packet, the currently potentially modified packet 50´ is further transmitted to its intended destination.
Claims
1. 1. A computer-implemented method comprising: receiving a packet (50) from a user equipment (10) via an access network (20) of a telecommunications network (1), the packet (50) comprising a subscriber identity of said user equipment (10) and encrypted according to a protocol of said telecommunications network (1); - decoding said packets (50) in a network core (30) of said telecommunications network (1) using said subscriber identity according to a protocol of said telecommunications network (1); finding a predefined action stored in an action database (31) of said network core (30) that is pre-associated with said subscriber identity of said packet (50); performing said predetermined action on said packet (50) in said network core (30); wherein the predetermined action is generating a subscriber-specific modified packet (50') by modifying payload data of said packet (50); A method comprising:
2. The method of claim 1 , wherein the associated identifier is a key or authenticator that complies with a public Internet cryptography protocol, such as a pre-shared key, a secret key, or a login credential.
3. 3. The method of claim 2, wherein the public Internet cryptography protocol is a Secure Sockets Layer protocol or a Transport Layer Security protocol.
4. 4. The method of claim 1, wherein the predetermined action includes generating a modified packet (50'), the modified packet (50') being generated by analyzing payload data of the packet (50) and modifying packet data of the packet based on the analysis.
5. 5. The method according to claim 1, wherein in addition to the telecommunications encryption layer (52), any further encryption layers (51, 54) of the received packet (50) have a key length of 127 bits or less.
6. 6. The method according to any one of claims 1 to 5, wherein the packets are provided with encryption substantially exclusively in accordance with a cryptography protocol of the telecommunications network (1).
7. 7. The method of claim 1, wherein the received packet may have an original packet destination, and the predetermined action includes providing the packet with a recipient packet destination that is different from any original packet destinations of the packet, replacing any original packet destinations of the packet.
8. The method of claim 7 , wherein the recipient packet destination is reached via the public Internet.
9. The method of claim 1 , wherein the received packets comprise primary or raw sensor data.
10. The method of claim 1 , wherein the predetermined action comprises converting primary sensor data of the packet into raw sensor data.
11. The method of any one of claims 1 to 10, further comprising transmitting said packets (50) over said public Internet (40).
12. 12. The method according to claim 1, further comprising the step of providing a publicly accessible communication channel to the action database (31), the subscriber identity belonging to a user profile, and a user accessing the communication channel with said user profile being allowed to modify the predefined action associated with the subscriber identity belonging to said user profile.
13. A computing unit (36) for processing packets in a network core (30) of a telecommunications network (1), the computing unit comprising a processor (33) and a memory (35), the memory being configured to, when executed by the processor (33), perform the following method: receiving a packet (50) from a user equipment (10) via an access network (20) of a telecommunications network (1), the packet (50) comprising a subscriber identity of said user equipment (10) and encrypted according to a protocol of said telecommunications network (1); - decoding said packets (50) in a network core (30) of said telecommunications network (1) using said subscriber identity according to a protocol of said telecommunications network (1); finding a predefined action stored in an action database (31) of said network core (30) that is pre-associated with said subscriber identity of said packet (50); performing said predetermined action on said packet (50) in said network core (30); [0023] The predetermined action is: A computing unit (36) comprising the step of generating a subscriber-specific modified packet (50') by modifying payload data of said packet (50).
14. When the program is executed by the computing unit (36), it causes the computing unit (36) to perform the following method: receiving a packet (50) from a user equipment (10) via an access network (20) of a telecommunications network (1), the packet (50) comprising a subscriber identity of said user equipment (10) and encrypted according to a protocol of said telecommunications network (1); - decoding said packets (50) in a network core (30) of said telecommunications network (1) using said subscriber identity according to a protocol of said telecommunications network (1); finding a predefined action stored in an action database (31) of said network core (30) that is pre-associated with said subscriber identity of said packet (50); performing said predetermined action on said packet (50) in said network core (30); [0033] The predetermined action is: A computer program product comprising the step of generating a subscriber-specific modified packet (50') by modifying payload data of said packet (50).
15. When read and executed by the computing unit (36), it provides the computing unit (36) with: receiving a packet (50) from a user equipment (10) via an access network (20) of a telecommunications network (1), the packet (50) comprising a subscriber identity of said user equipment (10) and encrypted according to a protocol of said telecommunications network (1); - decoding said packets (50) in a network core (30) of said telecommunications network (1) using said subscriber identity according to a protocol of said telecommunications network (1); finding a predefined action stored in an action database (31) of said network core (30) that is pre-associated with said subscriber identity of said packet (50); performing said predetermined action on said packet (50) in said network core (30); wherein the predetermined action is generating a subscriber-specific modified packet (50') by modifying payload data of said packet (50); A computer-readable storage medium comprising instructions for carrying out a method comprising:
Citation Information
Patent Citations
Proxy for serving internet-of-things (IOT) devices
US20180288179A1
Gateway computer system with intermediate data processing according to rules that are specified by templates
US20190068406A1
Method and switch node for processing a packet
WO2020001781A1