Routing privacy-sensitive traffic from a user device to a privacy-preserving next-hop network

The system addresses the metadata privacy issue in 5G networks by classifying and routing privacy-sensitive traffic to a privacy-preserving next-hop network, enhancing user privacy and reducing operational overhead.

WO2025132474A1PCT designated stage expired Publication Date: 2025-06-26KONINK KPN NV +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/086954
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-19
Filing Date
2024-12-17
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Existing mechanisms in 5G cellular networks protect user identities within the network but fail to safeguard metadata privacy once traffic leaves the cellular infrastructure and enters the internet, where eavesdroppers can observe and analyze metadata.

Method used

A system that classifies network traffic from a user device as privacy-sensitive or non-privacy-sensitive based on received privacy requirements and routes only privacy-sensitive traffic to a privacy-preserving next-hop network over a secure session, thereby reducing overhead for user devices and operators.

Benefits of technology

This approach enhances user privacy by ensuring that only sensitive traffic is routed through privacy-preserving networks, reducing costs, and minimizing latency for non-privacy-sensitive traffic, while simplifying access to privacy-preserving networks for users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024086954_26062025_PF_FP_ABST
    Figure EP2024086954_26062025_PF_FP_ABST
Patent Text Reader

Abstract

A system (21) for routing network traffic or causing the network traffic to be routed to a next-hop network is configured to obtain privacy requirements which are received from a user device (16) or are associated with the user device, classify network traffic originating from the user device as privacy sensitive or non-privacy sensitive based on the privacy requirements, route the network traffic or cause the network traffic to be routed to a non-privacy-preserving next-hop network (13) if the network traffic is classified as non- privacy sensitive, and route the network traffic or cause the network traffic to be routed to a privacy-preserving next-hop network (12) over a secure session if the network traffic is classified as privacy sensitive.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] ROUTING PRIVACY-SENSITIVE TRAFFIC FROM A USER DEVICE TO A PRIVACY¬

[0002] PRESERVING NEXT-HOP NETWORK

[0003] FIELD OF THE INVENTION

[0004] The invention relates to a system for routing network traffic or causing the network traffic to be routed to a next-hop network and also relates to a user device.

[0005] The invention further relates to a method of routing network traffic or causing the network traffic to be routed to a next-hop network.

[0006] The invention also relates to a computer program product enabling systems to perform such a method.

[0007] BACKGROUND OF THE INVENTION

[0008] Privacy of cellular telecommunication users has been discussed widely within standardization bodies such as 3GPP. The main concern addressed there is the protection of a user’s identifiers exchanged over the air between User Equipment (such as mobile phone) and Radio Network (e.g. a 4G / 5G base station). This is achieved broadly in two ways: with the usage of temporary identifiers representing the user’s subscription that is refreshed regularly, and by encrypting the traffic between the devices and radio network.

[0009] While the existing mechanisms in 5G could hide the identity of users in the cellular network, once the traffic leaves the infrastructure of the cellular network towards the internet, eavesdroppers can passively observe the metadata of the traffic even when the traffic is end-to-end encrypted. Numerous studies show how metadata, such as packet size, order of packets, order of messages, time intervals between packets and other timing patterns, can be used to estimate the behavior of the user. There are several known solutions that try to solve issues of metadata privacy against different types of adversaries, e.g. privacy-preserving networks such as VPN, TOR, and NYM.

[0010] The NYM service aims at providing metadata privacy to communication network users. NYM is a multi-purpose mixnet that prevents traffic analysis by an adversary capable of watching the entire network. The NYM mixnet is run decentralized with the help of NYM tokens. The user must obtain NYM tokens which are associated with a fixed amount of bandwidth. These tokens along with credentials are used to authenticate and authorize the user’s device to use NYM service. Every time the user’s bandwidth limit is exhausted, the user will have to obtain new credentials, authenticate and authorize the user device before accessing the NYM service again. This leads to extra overhead to the user device and the user.

[0011] SUMMARY OF THE INVENTION

[0012] It is advantageous to provide a system, which can be used to provide a user access to a privacy-preserving next-hop network without much effort from the user.

[0013] It is advantageous to provide a method, which can be used to provide a user access to a privacy-preserving next-hop network without much effort from the user.

[0014] In a first aspect of the invention, a system for routing network traffic or causing the network traffic to be routed to a next-hop network comprises at least one processor configured to obtain privacy requirements, the privacy requirements being received from a user device or being associated with the user device, classify network traffic originating from the user device as privacy sensitive or non-privacy sensitive based on the privacy requirements, route the network traffic or cause the network traffic to be routed to a non-privacy-preserving next-hop network if the network traffic is classified as non-privacy sensitive, and route the network traffic or cause the network traffic to be routed to a privacypreserving next-hop network over a secure session if the network traffic is classified as privacy sensitive.

[0015] By using a system different from the user device to route network traffic to the privacy-preserving next-hop network, or cause the network traffic to be routed to the privacy-preserving next-hop network, the user does not need to obtain credentials, authenticate and authorize the user’s device before accessing the privacy-preserving network. Instead, the operator responsible for the system, e.g. the network operator, may obtain credentials for all its users and ensure that the user devices of all its users are authenticated and authorized. The privacy-preserving next-hop network may be a NYM mixnet, for example. The non-privacy -preserving next-hop network may be the internet for example. Network traffic may be received by the user device from the privacy-preserving next-hop network over the same secure session. The at least one processor may be configured to select the privacy-preserving next-hop network from multiple available privacy-preserving nexthop networks.

[0016] By letting the system route only privacy-sensitive network traffic to the privacy-preserving next-hop network, the cost of using the privacy-preserving next-hop network may be reduced. Furthermore, the network traffic from latency sensitive applications may be routed via the non-privacy-preserving next-hop network to avoid that the use of the privacy-preserving next-hop network causes additional latency. Even if it would be possible for all user devices to setup their own connections to a privacy-preserving next-hop network, it may not be possible for all user-devices to only use the privacypreserving next-hop network for certain network traffic, e.g. from certain applications.

[0017] The at least one processor may be configured to receive the network traffic from the user device. In this case, a single system classifies network traffic as privacy sensitive or non-privacy sensitive and also sends the network traffic to a different next system based on this classification. The system may be a gateway in a mobile communication network (e.g. a 5G UPF system or a 4G P-GW system) or in a fixed access network, for example.

[0018] The at least one processor may be configured to cause the network traffic to be routed to the privacy-preserving next-hop network if the network traffic is classified as privacy sensitive by selecting a privacy-preserving gateway and sending the network traffic to the privacy-preserving gateway or causing the network traffic to be sent to the privacypreserving gateway, the privacy-preserving gateway routing the network traffic to the privacy-preserving next-hop network over the secure session. The privacy-preserving gateway may be a dedicated gateway, for example. A benefit of the use of a privacypreserving gateway may be that other systems are also able to route (e.g. privacy-sensitive) network traffic via the same privacy-preserving gateway.

[0019] The at least one processor may be configured to cause the network traffic to be routed to the non-privacy-preserving next-hop network if the network traffic is classified as non-privacy sensitive by selecting a non-privacy-preserving gateway and sending the network traffic to the non-privacy-preserving gateway or causing the network traffic to be sent to the non-privacy-preserving gateway, the non-privacy-preserving gateway routing the network traffic to the non-privacy-preserving next-hop network. The non-privacy-preserving gateway may be a generic gateway, for example. A benefit of the use of a non-privacypreserving gateway may be that other systems are also able to route (e.g. non-privacysensitive) network traffic via the same non-privacy-preserving gateway.

[0020] The at least one processor may be configured to route the network traffic or cause the network traffic to be routed to a non-privacy-preserving network via the privacypreserving next-hop network over the secure session if the network traffic is classified as privacy sensitive. The non-privacy -preserving network may be the internet for example. Alternatively, the network traffic may be routed to a third party server via the privacypreserving next-hop network, for example.

[0021] The at least one processor may be configured to route the network traffic or cause the network traffic to be routed to the privacy-preserving next-hop network over the secure session by routing the network traffic or causing the network traffic to be routed through a secure tunnel between a network in which the system is located and the privacy- preserving next-hop network. The secure tunnel may be between the system and the privacypreserving next-hop network or between the privacy-preserving gateway and the privacypreserving next-hop network, for example. The secure tunnel may be a GTP tunnel, for example, and the secure session may be an IPSec / TLS session, for example.

[0022] The at least one processor may be configured to receive information indicative of the privacy requirements from the user device. The information may be a privacy flag, for example. A user may be able to use a mobile application on the user device to indicate the privacy requirements, e.g. per application or per destination (e.g. IP address or website). A user may be able to use a web page or web interface to indicate the privacy requirements. The latter option may for example be used to indicate the privacy requirements for multiple user devices together.

[0023] The system may be configured to be used in a mobile communication network. The mobile communication network may be a 4G, 5G, or 6G network, for example. The system may be placed in the core network of the mobile communication network, for example. In a mobile communication, it is relatively easy to charge the user for use of the privacy-preserving next hop network along with use of the other services of the mobile communication network.

[0024] The at least one processor may be configured to obtain the privacy requirements from another system in the mobile communication network. For example, the system may be a 5G SMF or UPF system and obtain the privacy requirements from a 5G PCF system.

[0025] The system may be a gateway for handling data plane connectivity of the user device. The system may be a 5G UPF system or a 4G P-GW system, for example.

[0026] The system may be configured to manage sessions in the mobile communication network and the at least one processor may be configured to cause the network traffic to be routed to the privacy-preserving next-hop network if the network traffic is classified as privacy sensitive by selecting a privacy -preserving gateway for handling data plane connectivity of the user device and causing the network traffic to be sent to the privacy-preserving gateway for handling data plane connectivity of the user device, the privacy-preserving gateway for handling data plane connectivity of the user device routing the network traffic to the privacy-preserving next-hop network over the secure session, and cause the network traffic to be routed to the non-privacy-preserving next-hop network if the network traffic is classified as non-privacy sensitive by selecting a non-privacy-preserving gateway for handling data plane connectivity and causing the network traffic to be sent to the non-privacy-preserving gateway for handling data plane connectivity of the user device, the non-privacy-preserving gateway for handling data plane connectivity of the user device routing the network traffic to the non-privacy-preserving next-hop network.

[0027] The system may be a 5G SMF system and the gateways for handling data plane connectivity of the user device may be 5G UPF systems, for example. For example, the 5G SMF system may influence the selection of the 5G UPF system based on user policies stored in a 5G PCF system. Users may be able to use a web portal to indicate the privacy requirements, for example.

[0028] In a second aspect of the invention, a user device for use with the above- mentioned system comprises at least one processor configured to obtain network traffic to be sent, obtain privacy requirements, and send the network traffic and the privacy requirements to the system to cause the system to classify the network traffic as privacy sensitive or nonprivacy sensitive based on the privacy requirements, route the network traffic or cause the network traffic to be routed to a non-privacy-preserving next-hop network if the network traffic is classified as non-privacy sensitive, and route the network traffic or cause the network traffic to be routed to a privacy-preserving next-hop network over a secure session if the network traffic is classified as privacy sensitive. For example, a user may be able to use a mobile application on the user device to indicate the privacy requirements, e.g. per application or per destination (e.g. IP address or website).

[0029] The at least one processor may be configured to obtain the privacy requirements based on the network traffic, the privacy requirements applying specifically to the network traffic. For example, outgoing traffic from the user may be analyzed to identify if it is privacy sensitive. The privacy requirements may be specified in a privacy flag, for example.

[0030] In a third aspect of the invention, a method of routing network traffic or causing the network traffic to be routed to a next-hop network comprises obtaining privacy requirements, the privacy requirements being received from a user device or being associated with the user device, classifying network traffic originating from the user device as privacy sensitive or non-privacy sensitive based on the privacy requirements, routing the network traffic or causing the network traffic to be routed to a non-privacy-preserving next-hop network if the network traffic is classified as non-privacy sensitive, and routing the network traffic or causing the network traffic to be routed to a privacy-preserving next-hop network over a secure session if the network traffic is classified as privacy sensitive. The method may be performed by software running on a programmable device. This software may be provided as a computer program product.

[0031] Moreover, a computer program for carrying out the methods described herein, as well as a non-transitory computer readable storage-medium storing the computer program are provided. A computer program may, for example, be downloaded by or uploaded to an existing device or be stored upon manufacturing of these systems.

[0032] A non-transitory computer-readable storage medium stores at least a software code portion, the software code portion, when executed or processed by a computer, being configured to perform executable operations for routing network traffic or causing the network traffic to be routed to a next-hop network.

[0033] The executable operations comprise obtaining privacy requirements, the privacy requirements being received from a user device or being associated with the user device, classifying network traffic originating from the user device as privacy sensitive or non-privacy sensitive based on the privacy requirements, routing the network traffic or causing the network traffic to be routed to a non-privacy-preserving next-hop network if the network traffic is classified as non-privacy sensitive, and routing the network traffic or causing the network traffic to be routed to a privacy-preserving next-hop network over a secure session if the network traffic is classified as privacy sensitive.

[0034] As will be appreciated by one skilled in the art, aspects of the present invention may be embodied as a device, a method or a computer program product. Accordingly, aspects of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that may all generally be referred to herein as a "circuit", "module" or "system." Functions described in this disclosure may be implemented as an algorithm executed by a processor / microprocessor of a computer. Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer readable medium(s) having computer readable program code embodied, e.g., stored, thereon.

[0035] Any combination of one or more computer readable medium(s) may be utilized. The computer readable medium may be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium may be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer readable storage medium may include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the context of the present invention, a computer readable storage medium may be any tangible medium that can contain, or store, a program for use by or in connection with an instruction execution system, apparatus, or device.

[0036] A computer readable signal medium may include a propagated data signal with computer readable program code embodied therein, for example, in baseband or as part of a carrier wave. Such a propagated signal may take any of a variety of forms, including, but not limited to, electro-magnetic, optical, or any suitable combination thereof. A computer readable signal medium may be any computer readable medium that is not a computer readable storage medium and that can communicate, propagate, or transport a program for use by or in connection with an instruction execution system, apparatus, or device.

[0037] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber, cable, RF, etc., or any suitable combination of the foregoing. Computer program code for carrying out operations for aspects of the present invention may be written in any combination of one or more programming languages, including an object oriented programming language such as Java(TM), Smalltalk, C++ or the like and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0038] Aspects of the present invention are described below with reference to flowchart illustrations, sequence diagrams and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to a processor, in particular a microprocessor or a central processing unit (CPU), of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer, other programmable data processing apparatus, or other devices create means for implementing the fimctions / acts specified in the flowchart and / or block diagram block or blocks. These computer program instructions may also be stored in a computer readable medium that can direct a computer, other programmable data processing apparatus, or other devices to function in a particular manner, such that the instructions stored in the computer readable medium produce an article of manufacture including instructions which implement the function / act specified in the flowchart and / or block diagram block or blocks.

[0039] The computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable apparatus or other devices to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide processes for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0040] The flowchart and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of devices, methods and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagrams may represent a module, segment, or portion of code, which comprises one or more executable instructions for implementing the specified logical function(s).

[0041] It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions.

[0042] BRIEF DESCRIPTION OF THE DRAWINGS

[0043] These and other aspects of the invention are apparent from and will be further elucidated, by way of example, with reference to the drawings, in which:

[0044] Fig. 1 is a flow chart of an embodiment of the method of routing network traffic or causing the network traffic to be routed to a next-hop network;

[0045] Fig. 2 is a block diagram of a first embodiment of the system;

[0046] Fig. 3 is a block diagram of a second embodiment of the system;

[0047] Fig. 4 is a block diagram of a third embodiment of the system;

[0048] Fig. 5 is a sequence diagram illustrating communication between the systems of Fig. 4; Fig. 6 is a block diagram of an implementation of the system of Fig. 4;

[0049] Fig. 7 is a block diagram of a fourth embodiment of the system;

[0050] Fig. 8 is a block diagram of an embodiment of the user device; and

[0051] Fig. 9 is a block diagram of an exemplary data processing system for performing the methods of the invention.

[0052] Corresponding elements in the drawings are denoted by the same reference numeral.

[0053] DETAILED DESCRIPTION OF THE DRAWINGS

[0054] A first embodiment of the method of routing network traffic or causing the network traffic to be routed to a next-hop network is shown in Fig. 1. An optional step 100 comprises receiving the network traffic from a user device. A step 101 comprises obtaining privacy requirements. The privacy requirements are received from the user device, e.g. along with network traffic received in step 100, or are associated with the user device. As an example of the latter, the method may be performed by a 5G SMF or UPF system that obtains the privacy requirements from a 5G PCF system.

[0055] A step 103 comprises classifying network traffic originating from the user device as privacy sensitive or non-privacy sensitive based on the privacy requirements obtained in step 101. If step 100 was performed, the network traffic received from the user device in step 100 is classified in step 103.

[0056] A step 104 comprises determining whether the network traffic was classified as privacy sensitive or as non-privacy sensitive in step 103. A step 105 is performed if it is determined in step 104 that the network traffic was classified as non-privacy sensitive. A step 107 is performed if it is determined in step 104 that the network traffic was classified as privacy sensitive.

[0057] Step 105 comprises routing the network traffic received in step 100 and classified in step 103, or causing the network traffic classified in step 103 to be routed, to a non-privacy -preserving next-hop network. Optionally, step 105 comprises sub steps 113 and 115. Step 113 comprises selecting a non-privacy-preserving gateway. Step 115 comprises sending the network traffic to the non-privacy -preserving gateway selected in step 113 or causing the network traffic to be sent to the non-privacy-preserving gateway selected in step 113. The non-privacy -preserving gateway routes the network traffic to the non-privacypreserving next-hop network.

[0058] Step 107 comprises routing the network traffic received in step 100 and classified in step 103, or causing the network traffic classified in step 103 to be routed, to a privacy -preserving next-hop network over a secure session. Optionally, step 107 comprises sub steps 117 and 119. Step 117 comprises selecting a privacy-preserving gateway. Step 119 comprises sending the network traffic to the privacy -preserving gateway selected in step 117 or causing the network traffic to be sent to the privacy-preserving gateway selected in step 117. The privacy -preserving gateway routes the network traffic to the privacy -preserving next-hop network over the secure session.

[0059] A first embodiment of the system for routing network traffic or causing the network traffic to be routed to a next-hop network is shown in Fig. 2. The system 1 comprises a receiver 3, a transmitter 4, a processor 5, and a memory 7. The system 1 is located in a network 11, e.g. in a core network of a mobile communication network or in a fixed access network. The mobile communication network may be a 4G, 5G, or 6G network, for example. The system 1 may be a gateway for handling data plane connectivity of the user device in a mobile communication network (e.g. a 5G UPF system or a 4G P-GW system) or a fixed access network, for example.

[0060] The processor 5 is configured to obtain privacy requirements. The privacy requirements are received from a user device 16 or are associated with the user device 16. For example, the processor 5 may be configured to receive information indicative of the privacy requirements from the user device 16 or obtain the privacy requirements from another system (not shown in Fig. 2).

[0061] The processor 5 is further configured to classify network traffic originating from the user device 16 as privacy sensitive or non-privacy sensitive based on the privacy requirements, route the network traffic to a non-privacy -preserving next-hop network 13 if the network traffic is classified as non-privacy sensitive, and route the network traffic to a privacy-preserving next-hop network 12 over a secure session if the network traffic is classified as privacy sensitive.

[0062] The privacy-preserving next-hop network 12 may be a NYM mixnet, a VPN server network, a TOR network, or a peer-to-peer network, for example. The non-privacypreserving next-hop network 13 may be the public internet for example.

[0063] Incoming traffic, to the user device from the internet, that corresponds to the sent privacy-sensitive traffic may be also received via the privacy-preserving next-hop network 12, e.g. over the same secure session. The privacy-preserving next hop network 12 may impose strong security requirements on the incoming traffic from the internet. For instance, the privacy-preserving next-hop network 12 may allow only encrypted communication with state-of-the-art protection mechanisms from the internet to the user devices. If that is not fulfilled, the network 11 or the privacy-preserving next hop network 12 may reject the traffic or inform the user about the usage of weaker protection mechanisms, for example. A user may be able to use a mobile application on the user device 16 to indicate the privacy requirements, e.g. per application or per destination (e.g. IP address or website). A user may be able to use a web page or web interface to indicate the privacy requirements. The latter option may for example be used to indicate the privacy requirements for multiple user devices together. The user device 16 may provide a user interface which allows the user to switch on / off routing through any privacy-preserving next-hop network. Some privacy requirements may have already been pre-configured by default, which may be changed by the user.

[0064] In the embodiment of Fig. 2, the processor 5 is configured to send the network traffic to the non-privacy -preserving next-hop network 13 or to the privacypreserving next-hop network 12. In an alternative embodiment of the system, the system routes the network traffic to the non-privacy-preserving next-hop network via a non-privacypreserving gateway or to the privacy-preserving next-hop network via a privacy-preserving gateway.

[0065] In the embodiment of Fig. 2, the processor 5 is configured to route the network traffic, or cause the network traffic to be routed, to the non-privacy-preserving network 13 via the privacy-preserving next-hop network 12 over the secure session if the network traffic is classified as privacy sensitive. In the example of Fig. 2, the non-privacypreserving network 13 comprises a server 18 of a service provider or a user device 17, e.g. of a friend. Although the server 18 is part of the non-privacy -preserving network 13, it may be directly connected to the privacy-preserving network 12 such that network traffic routed via the privacy -preserving next-hop network 12 to the server 18 will not leak / reveal any privacy sensitive information of user data.

[0066] A second embodiment of the system for routing network traffic or causing the network traffic to be routed to a next-hop network is shown in Fig. 3. The system 21 comprises receiver 3, transmitter 4, a processor 25, and memory 7.

[0067] The processor 25 differs from the processor 5 of Fig. 2 in that the processor 25 is configured to route the network traffic, or cause the network traffic to be routed, to the privacy -preserving next-hop network 12 if the network traffic is classified as privacy sensitive by selecting a privacy -preserving gateway 31 and sending the network traffic to the privacy -preserving gateway 31. The privacy -preserving gateway 31 routes the network traffic to the privacy-preserving next-hop network 12 over the secure session. Additional functions of the privacy-preserving gateway 31 may include the handling of operational requirements of the privacy -preserving next-hop network 12, for example identifying network 11 towards the privacy -preserving next-hop network 12, or managing payment / billing / accounting requirements of the privacy-preserving next-hop network 12. If the system 21 is a 5G UPF system, the privacy -preserving gateway 31 may be configured to perform the functionalities of creating and managing tunnels between the 5G UPF system 21 and a first node of the privacy-preserving next-hop network 12.

[0068] The privacy -preserving gateway 31 may be a dedicated gateway, for example. If the privacy -preserving gateway 31 is not able to connect to the privacypreserving next-hop network 12, the system 21 may send a message to the user informing the user and giving the user a choice of not sending privacy-sensitive network traffic, modifying the privacy requirements, or agreeing to route the privacy-sensitive network traffic to the non-privacy preserving network 13, or the system 21 may try to connect to the privacypreserving next-hop network 12 via another privacy -preserving gateway (not shown in Fig. 2), or may try to connect to another privacy-preserving next-hop network, for example.

[0069] A third embodiment of the system for routing network traffic or causing the network traffic to be routed to a next-hop network is shown in Fig. 4. The system 41 comprises receiver 3, transmitter 4, a processor 45, and memory 7.

[0070] The processor 45 differs from the processor 25 of Fig. 3 in that the processor 45 is configured to route the network traffic, or cause the network traffic to be routed, to the non-privacy -preserving next-hop network 13 if the network traffic is classified as nonprivacy sensitive by selecting a non-privacy-preserving gateway 51 and sending the network traffic to the non-privacy-preserving gateway 51. The non-privacy -preserving gateway 51 routes the network traffic to the non-privacy -preserving next-hop network 13.

[0071] The non-privacy -preserving gateway 51 may be a generic gateway, for example. If the privacy -preserving gateway 31 is not able to connect to the privacypreserving next-hop network 12, the system 41 may send a message to the user informing the user and giving the user a choice of not sending privacy-sensitive network traffic, modifying the privacy requirements, or agreeing to route privacy-sensitive network traffic to the non- privacy preserving gateway 51, or the system 41 may try to connect to the privacy -preserving next-hop network 12 via another privacy -pre serving gateway (not shown in Fig. 3), or may try to connect to another privacy-preserving next-hop network for example.

[0072] In the embodiments of Figs. 2-4, the processor of the system may be configured to route the network traffic to the privacy -preserving next-hop network 12 over the secure session by routing the network traffic or causing the network traffic to be routed through a secure tunnel between the network 11 and the privacy-preserving next-hop network 12. The secure tunnel may start at the system 11 of Fig. 2 or at the privacypreserving gateway 31 of Figs. 3 and 4, for example. The secure tunnel may be a GTP tunnel, for example, and the secure session may be an IPSec / TLS session, for example. In the embodiments of Figs. 2-4, the network traffic is routed to the nonprivacy-preserving next-hop network 13 or to the privacy-preserving next-hop network 12 by the system itself. In an alternative embodiment of the system, the system causes another system to route the network traffic to the non-privacy-preserving next-hop network 13 or to the privacy-preserving next-hop network 12.

[0073] Fig. 5 shows an example of communication between the systems of Fig. 4. First, the privacy -preserving gateway 31 establishes a secure bidirectional channel with the privacy -preserving next-hop network 12 in a step 201. Then, when the user device 16 sends network traffic 203 to the system 41, the system 41 analyzes this network traffic 203 and classifies it as privacy sensitive or non-privacy sensitive in a step 205 based on obtained privacy requirements. The user’s privacy requirements used in step 205 may be collected from the user and stored on another system, e.g. in the core network of a mobile communication network. This step is not shown in Fig. 5.

[0074] If the network traffic is classified as privacy sensitive, the system 41 routes the network traffic to the non-privacy -preserving network 13 via the privacy-preserving gateway 31 and the privacy -preserving next-hop network 12 over the secure bidirectional channel established between the privacy-preserving gateway 31 and the privacy-preserving next-hop network 12. If the network traffic is classified as non-privacy sensitive, the system 41 routes the network traffic to the non-privacy -preserving next-hop network 13 via the nonprivacy-preserving gateway 51.

[0075] A first implementation of the system of Fig. 4 is shown in Fig. 6. In this implementation, the system 41 is configured to be used in a mobile communication network, specifically in a 5G network.

[0076] Actual communication between user’s devices and the internet occurs on the data plane traffic and this is the place which needs protection as it passes through to the untrusted “internet”. Within the 5G core architecture, the UPF is the function that handles the data plane traffic connection with the user’s device and acts as an interconnection point between the 5G core network and the internet. It is therefore best to place the privacypreserving network 12 after the UPF and before the data plane traffic is sent to the internet. This ensures that strongly increased metadata privacy mechanisms (with respect to adversaries on the internet) are in place before the network traffic is sent to the internet.

[0077] Therefore, in the implementation of Fig. 6, the system 41 is a gateway for handling data plane connectivity of the user device 16, specifically a 5G UPF system. Thus, the privacy -preserving network 12 is placed after the UPF 41 and before the data plane traffic is sent to the internet. In the implementation of Figs. 6, the gateways 31 and 51 of Fig. 4 are also UPFs. Furthermore, in the implementation of Fig. 6, the processor of the UPF system 41 is configured to obtain the privacy requirements from another system in the mobile communication network: from PCF system 62 (via SMF system 64). In the implementation of Fig. 6, the user’s privacy requirements are collected out of band through an external service 69, for instance a mobile application or a web portal. For example, a user may be able to choose per application or per destination (e.g. IP address or website) which traffic needs to be sent through the privacy-preserving next-hop network 12.

[0078] These requirements are then fed into a NEF system 63 and stored as user policies in PCF system 62. The user policies are obtained from the PCF system 62 by the UPF system 41 and then used by the UPF system 41 to classify the network traffic received from the user device 16 via the access point 19. Access point 19 may be a Wi-Fi access point, an ethemet access point, or a wireless 4G / 5G / 6G access point, for example. Other systems of the 5G core network 11 shown in Fig. 6 are the AMF system 61 and the UDM system 65.

[0079] In an alternative implementation, system 41 may be configured to be used in a different mobile communication network, e.g. a 4G network, or in a fixed access network, for example. In the case of a 4G network, the system 41 may be a P-GW system, as P-GW is the function which takes care of data plane traffic from the user to the internet in 4G networks. In the case of a fixed access network, the system 41 may be the network entity that is responsible for data plan traffic between users and the internet in the fixed access network.

[0080] A fourth embodiment of the system for routing network traffic or causing the network traffic to be routed to a next-hop network is shown in Fig. 7. In the embodiment of Fig. 7, the system 71 is configured to manage sessions in the mobile communication network. Specifically, the system 71 is a 5G SMF system. The system 71 comprises receiver 3, transmitter 4, a processor 75, and memory 7.

[0081] The processor 75 is configured to obtain privacy requirements which are associated with a user device 16, classify network traffic originating from the user device 16 as privacy sensitive or non-privacy sensitive based on the privacy requirements, cause the network traffic to be routed to a non-privacy -preserving next-hop network 13 if the network traffic is classified as non-privacy sensitive, and cause the network traffic to be routed to a privacy-preserving next-hop network 12 over a secure session if the network traffic is classified as privacy sensitive.

[0082] The processor 75 is configured to cause the network traffic to be routed to the privacy -preserving next-hop network 12 if the network traffic is classified as privacy sensitive by selecting a privacy -preserving gateway 31 for handling data plane connectivity of the user device 16, specifically a 5G UPF system, and causing the network traffic to be sent to the privacy -preserving gateway 31 for handling data plane connectivity of the user device 16. The privacy -preserving gateway 31 for handling data plane connectivity of the user device 16 routes the network traffic to the privacy -preserving next-hop network 12 over the secure session.

[0083] The processor 75 is configured to cause the network traffic to be routed to the non-privacy -preserving next-hop network 13 if the network traffic is classified as nonprivacy sensitive by selecting a non-privacy -preserving gateway 51 for handling data plane connectivity, specifically a 5G UPF system, and causing the network traffic to be sent to the non-privacy -preserving gateway 51 for handling data plane connectivity of the user device 16. The non-privacy -preserving gateway 51 for handling data plane connectivity of the user device 16 routes the network traffic to the non-privacy -preserving next-hop network 13.

[0084] In the embodiment of Fig. 7, the SMF system 71 influences the selection of the UPF system based on user policies stored in the PCF system 62. The SMF system 71 influences the selection of the UPF system by telling the user device 16 directly which UPF to use. This can be done using URSP rules or by some other mechanism. If the network traffic is classified as privacy sensitive, the SMF system 71 selects the UPF 31 that is connected to the privacy-preserving next hop network 12. If the network traffic is classified as non-privacy- sensitive, the SMF system 71 selects the UPF 51 that is connected directly to the non-privacy -preserving next-hop network 13. The user device 16 sends the network traffic to the selected UPF via the access point 19.

[0085] An embodiment of the user device is shown in Fig. 8. The user device 91 comprises a receiver 93, a transmitter 94, a processor 95, and a memory 97. The processor 95 is configured to obtain network traffic to be sent (e.g. from an application running on the user device 91), obtain privacy requirements, and send the network traffic and the privacy requirements to the system 21 of Fig. 3 to cause the system 21 to classify the network traffic as privacy sensitive or non-privacy sensitive based on the privacy requirements, route the network traffic or cause the network traffic to be routed to a non-privacy-preserving nexthop network 13 if the network traffic is classified as non-privacy sensitive and route the network traffic or cause the network traffic to be routed to a privacy-preserving next-hop network 12 over a secure session if the network traffic is classified as privacy sensitive.

[0086] A user may be able to use a mobile application on the user device 91 to indicate the privacy requirements, e.g. per application or per destination (e.g. IP address or website). The processor 95 may be configured to obtain the privacy requirements based on the network traffic. For example, outgoing traffic from the user may be analyzed to identify if it is privacy sensitive. The privacy requirements apply specifically to the network traffic. The privacy requirements may be specified in a privacy flag, for example. In an alternative embodiment, the processor 95 is configured to send the network traffic and the privacy requirements to the system 1 of Fig. 2 or the system 41 of Fig. 4.

[0087] In the embodiments shown in Figs. 2-4 and 6-7, the systems 1, 21, 41, and 71 comprise one processor 5, one processor 25, one processor 45, and one processor 75, respectively. In an alternative embodiment, one or more of the systems 1, 21, 41, and 71 comprise multiple processors. The processors 5, 25, and 45, and 75 may be general-purpose processors, e.g., ARM, AMD, or Intel processors, or application-specific processors. The processors 5, 25, 45, and 75 may run a Unix-based operating system or Windows as operating system, for example.

[0088] The receiver 3 and the transmitter 4 of the systems 1, 21, 41, and 71 may use one or more wired or wireless communication technologies such as Ethernet, Wi-Fi, LTE, and / or 5G New Radio to communicate with other devices. The receiver and the transmitter of a system may be combined in a transceiver. The systems 1, 21, 41, and 71 may comprise other components typical for a network system.

[0089] In the embodiment shown in Fig. 8, the user device 91 comprises one processor 95. In an alternative embodiment, the user device 91 comprises multiple processors. The processors 95 may be a general-purpose processors, e.g., ARM or Qualcomm processor, or application-specific processor.

[0090] The receiver 3 and the transmitter 4 may use one or more wireless communication technologies such as Wi-Fi, LTE, and / or 5G New Radio to communicate with base stations, for example. The receiver 3 and the transmitter 4 may be combined in a transceiver. The user device 91 may comprise other components typical for a user device, e.g., a battery and / or a power connector.

[0091] The user device is also referred to as a mobile device, a mobile station (MS), a subscriber station, a mobile unit, a subscriber unit, a wireless unit, a wireless terminal, a wireless device, a wireless communications device, a remote device, a mobile subscriber station, an access terminal (AT), a mobile terminal, a user equipment (UE), a remote terminal, a handset, a terminal, a user agent, a mobile client, a client, or some other suitable terminology.

[0092] Fig. 9 depicts a block diagram illustrating an exemplary data processing system that may perform the method as described with reference to Fig. 1.

[0093] As shown in Fig. 9, the data processing system 300 may include at least one processor 302 coupled to memory elements 304 through a system bus 306. As such, the data processing system may store program code within memory elements 304. Further, the processor 302 may execute the program code accessed from the memory elements 304 via a system bus 306. In one aspect, the data processing system may be implemented as a computer that is suitable for storing and / or executing program code. It should be appreciated, however, that the data processing system 300 may be implemented in the form of any system including a processor and a memory that is capable of performing the functions described within this specification.

[0094] The memory elements 304 may include one or more physical memory devices such as, for example, local memory 308 and one or more bulk storage devices 310. The local memory may refer to random access memory or other non-persistent memory device(s) generally used during actual execution of the program code. A bulk storage device may be implemented as a hard drive or other persistent data storage device. The processing system 300 may also include one or more cache memories (not shown) that provide temporary storage of at least some program code in order to reduce the number of times program code must be retrieved from the bulk storage device 310 during execution.

[0095] Input / output (I / O) devices depicted as an input device 312 and an output device 314 optionally can be coupled to the data processing system. Examples of input devices may include, but are not limited to, a keyboard, a pointing device such as a mouse, a camera, or the like. Examples of output devices may include, but are not limited to, a monitor or a display, speakers, or the like. Input and / or output devices may be coupled to the data processing system either directly or through intervening I / O controllers.

[0096] In an embodiment, the input and the output devices may be implemented as a combined input / output device (illustrated in Fig. 9 with a dashed line surrounding the input device 312 and the output device 314). An example of such a combined device is a touch sensitive display, also sometimes referred to as a “touch screen display” or simply “touch screen”. In such an embodiment, input to the device may be provided by a movement of a physical object, such as e.g. a stylus or a finger of a user, on or near the touch screen display.

[0097] A network adapter 316 may also be coupled to the data processing system to enable it to become coupled to other systems, computer systems, remote network devices, and / or remote storage devices through intervening private or public networks. The network adapter may comprise a data receiver for receiving data that is transmitted by said systems, devices and / or networks to the data processing system 300, and a data transmitter for transmitting data from the data processing system 300 to said systems, devices and / or networks. Modems, cable modems, and Ethernet cards are examples of different types of network adapter that may be used with the data processing system 300.

[0098] The network adapter 316 may allow the data processing system to connect to the Internet, e.g. via Wi-Fi or Ethernet, and / or directly to nearby devices, e.g. via Bluetooth, Wi-Fi-Direct or Ultrasound. Data may also be exchanged between other devices and the data processing system in another way, e.g. by enabling the data processing system to scan a QR code displayed on another device and / or by enabling the data processing system to display a QR code for scanning by another device.

[0099] As pictured in Fig. 9, the memory elements 304 may store an application 318. In various embodiments, the application 318 may be stored in the local memory 308, he one or more bulk storage devices 310, or separate from the local memory and the bulk storage devices. It should be appreciated that the data processing system 300 may further execute an operating system (not shown in Fig. 9) that can facilitate execution of the application 318. The application 318, being implemented in the form of executable program code, can be executed by the data processing system 300, e.g., by the processor 302. Responsive to executing the application, the data processing system 300 may be configured to perform one or more operations or method steps described herein.

[0100] Various embodiments of the invention may be implemented as a program product for use with a computer system, where the program(s) of the program product define functions of the embodiments (including the methods described herein). In one embodiment, the program(s) can be contained on a variety of non-transitory computer-readable storage media, where, as used herein, the expression “non-transitory computer readable storage media” comprises all computer-readable media, with the sole exception being a transitory, propagating signal. In another embodiment, the program(s) can be contained on a variety of transitory computer-readable storage media. Illustrative computer-readable storage media include, but are not limited to: (i) non-writable storage media (e.g., read-only memory devices within a computer such as CD-ROM disks readable by a CD-ROM drive, ROM chips or any type of solid-state non-volatile semiconductor memory) on which information is permanently stored; and (ii) writable storage media (e.g., flash memory, floppy disks within a diskette drive or hard-disk drive or any type of solid-state random-access semiconductor memory) on which alterable information is stored. The computer program may be run on the processor 302 described herein.

[0101] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the invention. As used herein, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms "comprises" and / or "comprising," when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof.

[0102] The corresponding structures, materials, acts, and equivalents of all means or step plus function elements in the claims below are intended to include any structure, material, or act for performing the function in combination with other claimed elements as specifically claimed. The description of embodiments of the present invention has been presented for purposes of illustration, but is not intended to be exhaustive or limited to the implementations in the form disclosed. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope of the present invention. The embodiments were chosen and described in order to best explain the principles and some practical applications of the present invention, and to enable others of ordinary skill in the art to understand the present invention for various embodiments with various modifications as are suited to the particular use contemplated.

Claims

CLAIMS:

1. A system ( 1,21,41,71) for routing network traffic or causing the network traffic to be routed to a next-hop network, the system (1,21,41,71) comprising at least one processor (5,25,45,75) configured to:- obtain privacy requirements, the privacy requirements being received from a user device (16,91) or being associated with the user device (16,91),- classify network traffic originating from the user device (16,91) as privacy sensitive or non-privacy sensitive based on the privacy requirements,- route the network traffic or cause the network traffic to be routed to a nonprivacy-preserving next-hop network (13) if the network traffic is classified as non-privacy sensitive, and- route the network traffic or cause the network traffic to be routed to a privacy -preserving next-hop network (12) over a secure session if the network traffic is classified as privacy sensitive.

2. A system (1,21,41) as claimed in claim 1, wherein the at least one processor (5,25,45) is configured to receive the network traffic from the user device (16,91).

3. A system (1,21,41,71) as claimed in claim 1 or 2, wherein the at least one processor (5,25,45,75) is configured to cause the network traffic to be routed to the privacypreserving next-hop network (12) if the network traffic is classified as privacy sensitive by selecting a privacy-preserving gateway (31,81) and sending the network traffic to the privacy-preserving gateway (31) or causing the network traffic to be sent to the privacypreserving gateway (31,81), the privacy-preserving gateway (31,81) routing the network traffic to the privacy -preserving next-hop network (12) over the secure session.

4. A system (1,21,41,71) as claimed in any one of claims 1 to 3, wherein the at least one processor (5,25,45,75) is configured to cause the network traffic to be routed to the non-privacy -preserving next-hop network (13) if the network traffic is classified as non- privacy sensitive by selecting a non-privacy-preserving gateway (51,82) and sending the network traffic to the non-privacy-preserving gateway (51,82) or causing the network traffic to be sent to the non-privacy-preserving gateway (51,82), the non-privacy-preservinggateway (51,82) routing the network traffic to the non-privacy-preserving next-hop network (13).

5. A system (1,21,41,71) as claimed in any one of the preceding claims, wherein the at least one processor (5,25,45,75) is configured to route the network traffic or cause the network traffic to be routed to a non-privacy -preserving network (13) via the privacypreserving next-hop network (12) over the secure session if the network traffic is classified as privacy sensitive.

6. A system (1,21,41,71) as claimed in any one of the preceding claims, wherein the at least one processor (5,25,45,75) is configured to route the network traffic or cause the network traffic to be routed to the privacy -preserving next-hop network (12) over the secure session by routing the network traffic or causing the network traffic to be routed through a secure tunnel between a network (11) in which the system is located and the privacypreserving next-hop network (12).

7. A system (1,21,41) as claimed in any one of the preceding claims, wherein the at least one processor (5,25,45,75) is configured to receive information indicative of the privacy requirements from the user device (16,91).

8. A system (1,21,41,71) as claimed in any one of the preceding claims, wherein the system (1,21,41,71) is configured to be used in a mobile communication network.

9. A system (1,21,41,71) as claimed in claim 8, wherein the at least one processor is configured to obtain the privacy requirements from another system (62) in the mobile communication network.

10. A system (1,21,41) as claimed in claim 8 or 9, wherein the system (1,21,41) is a gateway for handling data plane connectivity of the user device (16,91).

11. A system (71) as claimed in claim 8 or 9, wherein the system (71) is configured to manage sessions in the mobile communication network and the at least one processor (75) is configured to:- cause the network traffic to be routed to the privacy-preserving next-hop network (12) if the network traffic is classified as privacy sensitive by selecting a privacypreserving gateway (81) for handling data plane connectivity of the user device (16) andcausing the network traffic to be sent to the privacy -preserving gateway (81) for handling data plane connectivity of the user device (16), the privacy-preserving gateway (81) for handling data plane connectivity of the user device (16) routing the network traffic to the privacy -preserving next-hop network (12) over the secure session, and- cause the network traffic to be routed to the non-privacy-preserving nexthop network (13) if the network traffic is classified as non-privacy sensitive by selecting a non-privacy-preserving gateway (82) for handling data plane connectivity and causing the network traffic to be sent to the non-privacy-preserving gateway (82) for handling data plane connectivity of the user device (16), the non-privacy -pre serving gateway (82) for handling data plane connectivity of the user device (16) routing the network traffic to the non-privacypreserving next-hop network (13).

12. A user device (91) for use with the system (21,41,61) of claim 1, the user device (91) comprising at least one processor (95) configured to:- obtain network traffic to be sent,- obtain privacy requirements, and- send the network traffic and the privacy requirements to the system (21,41,61) to cause the system to classify the network traffic as privacy sensitive or non- privacy sensitive based on the privacy requirements, route the network traffic or cause the network traffic to be routed to a non-privacy -preserving next-hop network (13) if the network traffic is classified as non-privacy sensitive, and route the network traffic or cause the network traffic to be routed to a privacy -preserving next-hop network (12) over a secure session if the network traffic is classified as privacy sensitive.

13. A user device (91) as claimed in claim 12, wherein the at least one processor (95) is configured to obtain the privacy requirements based on the network traffic, the privacy requirements applying specifically to the network traffic.

14. A method of routing network traffic or causing the network traffic to be routed to a next-hop network, the method comprising:- obtaining (101) privacy requirements, the privacy requirements being received from a user device or being associated with the user device;- classifying (103) network traffic originating from the user device as privacy sensitive or non-privacy sensitive based on the privacy requirements;- routing (105) the network traffic or causing the network traffic to be routed to a non-privacy-preserving next-hop network if the network traffic is classified as nonprivacy sensitive; and- routing (107) the network traffic or causing the network traffic to be routed to a privacy-preserving next-hop network over a secure session if the network traffic is classified as privacy sensitive.

15. A computer program or suite of computer programs comprising at least one software code portion or a computer program product storing at least one software code portion, the software code portion, when run on a computer system, being configured for performing the method of claim 14.

Citation Information

Patent Citations

  • Method and apparatus for anonymous access and control of a service node

    US20170279775A1