Handling of encrypted user data
The analytics entity in the cellular network identifies encrypted sessions and provides a list to the policy control entity, allowing differentiated traffic management for encrypted traffic, addressing the challenge of managing encrypted sessions in cellular networks.
Patent Information
- Application Number
- PCT/EP2024/060173
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-06
- Filing Date
- 2024-04-15
- Publication Date
- 2025-08-14
AI Technical Summary
Current cellular networks struggle to apply differentiated traffic management actions for encrypted traffic, such as charging and QoS, due to the inability to differentiate encrypted user data sessions, particularly in scenarios involving dual-proxy deployments like Apple's Private Relay and VPNs like Google's One VPN.
An analytics entity in the cellular network detects encrypted user data sessions and provides a list of applications generating such sessions to a policy control entity, enabling the generation of application-specific policies to manage traffic differently.
Enables network operators to apply differentiated traffic management actions like charging and QoS for encrypted traffic, preserving user privacy while enforcing operator policies and subscription terms, even in challenging encryption scenarios.
Smart Images

Figure EP2024060173_14082025_PF_FP_ABST
Abstract
Description
[0001] Handling of encrypted user data
[0002] Technical Field
[0003] The present application relates to a method carried out at an analytics entity of a cellular network, and to the corresponding analytics entity. Furthermore, a method carried out at a user plane entity handling user data sessions in the cellular network is provided and the corresponding user plane entity. In addition, a method carried out at a policy control entity is provided and the corresponding policy control entity. The application furthermore provides a system comprising at least 2 of the entities, a computer program comprising program code an a carrier is provided.
[0004] Background
[0005] Fig. 1 shows a 5G reference architecture as defined by 3 GPP. Service Based Interfaces are represented in the format Nxyz, such as Nsmf, and point to point interfaces in the format Nx, such as N4. The 5G core network part comprises a Unified Data Repository (UDR) 11 , a Network Exposure Function (NEF) 12, a Policy Control Function (PCF) 15, an Application Function (AF) 14, an Access and Mobility Management Function (AMF) 17, and a Session Management Function (SMF) 18. Furthermore a Network Data Analytics Function (NWDAF) 13 is provided. Having service based interfaces in the 5G Core Control Plane (CP), implies that the Network Functions (NFs) in the 5G Core CP provide services that are consumed by other NFs in the 5G Core CP. A User Equipment (UE) not shown is connected to the Radio Access Network (RAN) not shown, wherein a User Plane Function (UPF) 19 is provided to handle the user data.
[0006] In the following, some of the functions / nodes are explained in more detail.
[0007] NWDAF 13
[0008] NWDAF 13 represents operator managed network analytics logical function. The NWDAF is part of the 5GC architecture and uses the mechanisms and interfaces specified for 5GC and GAM.
[0009] The NWDAF interacts with different entities for different purposes: - Data collection based on event subscription, provided by AMF, SMF, PCF, UDM, AF (directly or via NEF), and OAM;
[0010] - Retrieval of information from data repositories (e.g. UDR via UDM for subscriber-related information);
[0011] - Retrieval of information about NFs (e.g. NRF for NF-related information, and NSSF for slice- related information);
[0012] - On demand provision of analytics to consumers.
[0013] - Storage in Analytics Data Repository Function (ADRF) for two types of data:
[0014] Collected Data (e.g., Event Exposure data)
[0015] Analytics reports.
[0016] UDR 11
[0017] The 5G System architecture allows the UDM, PCF and NEF to store data in the UDR, here especially subscription policy data to be used by PCF.
[0018] AMF 17
[0019] The Access and Mobility Management Function (AMF) supports different functionality, e.g. Termination of NAS (Non Access Stratum) signaling, NAS ciphering & integrity protection, registration management, connection management, mobility management, access authentication and authorization, security context management. Specifically, AMF will be used to convey information from / to UE through NAS signaling, including the UE Policies provided by PCF.
[0020] PCF 15
[0021] The Policy Control Function (PCF) supports unified policy framework to govern the network behavior. Specifically, PCF 15 provides UE Policies and PCC (Policy and Charging Control) rules to the SMF 18.
[0022] SMF 18
[0023] The Session Management function (SMF) supports different functionalities, e.g. SMF receives PCC rules from the PCF and configures the UPF accordingly.
[0024] UPF 19
[0025] The User Plane function (UPF) supports handling of user plane traffic based on the rules received from the SMF, e.g. packet inspection and different enforcement actions such as Sponsored Data or QoS handling.
[0026] UE Policies
[0027] 3GPP defines UE policies for the network and specifically the PCF to configure the UE with two types of operator policies: • Access Network Discovery and Selection Policy (ANDSP) for non-3GPP access, which includes information for what non-3GPP accesses that UE should prioritize and which is used by the UE e.g. for selecting non-3GPP accesses (e.g. Wi-Fi networks), and
[0028] • UE Route Selection Policy (URSP) related to applications and PDU sessions, which includes information mapping certain user data traffic (i.e. applications) to 5G PDU Session connectivity parameters. The user data traffic is defined in the URSP rule by a “traffic descriptor” parameter that can include e.g. IP filter parameters or Application Identity.
[0029] Traffic encryption and network management
[0030] Traffic encryption is growing significantly in mobile networks and at the same time, the encryption mechanisms are growing in complexity. In particular, most applications today are not based on HTTP cleartext, but instead they are based on HTTPS (using TLS (Transport Layer Security)). Additionally, a significant part of the traffic is based on QUID (Quick UDP Internet Connections) transport (e.g. YouTube, Facebook, etc), which has an encryption level higher than TLS. In the future, it is foreseen that most apps will be based on QUIC transport. Additionally, Apple's Private Relay and Google's One VPN are already deployed and represents the highest level of encryption.
[0031] Network operators today require application / service awareness in order to apply differentiated traffic management actions, e.g. Charging, QoS, etc.
[0032] Network operators today require application / service awareness in order to apply differentiated traffic management actions, e.g. Charging, QoS, etc, according to operator policies and subscription terms. It is currently not possible to apply differentiated traffic management actions for encrypted traffic, specifically Dual-proxy deployments (e.g. Apple's Private Relay) or VPN deployments (e.g. Google's One VPN).
[0033] Summary
[0034] Accordingly a need exists to overcome the above identified problems and to improve the handling of encrypted data in a cellular network. This need is met by the features of the independent claims. Further aspects are described in the dependent claims.
[0035] According to a first aspect a method is provided carried out by an analytics entity of the cellular network wherein the analytics entity triggers at user plane entity handling user data sessions in the cellular network, a detection of unencrypted user data session. Furthermore a notification is received from the user plane entity that a user data session has been detected where at least one part of the user data session is encrypted. The analytics entity determines based on the notification a list with at least one application which generates an encrypted user data session and provides the list with the at least one application to a policy control entity of the cellular network.
[0036] Furthermore, the corresponding analytics entity is provided configured to operate as discussed above or as discussed in further detail below. As the user plane entity cannot differentiate encrypted user data sessions, the notification can be used for the generation of a list with an application where encrypted user data will be used. By providing the list to the policy control entity, the latter can generate and distribute an application-specific policy in the cellular network.
[0037] In addition, a method is provided carried out by the user plane entity which handles the user data sessions in the network wherein the user plane entity receives a request to detect a user data session where at least a part of the user data session is encrypted. Based on this request it detects the user data session where at least a part of the user data session is encrypted and transmits a notification to an analytics entity of the cellular network, that a user data session has been detected where at least a part of the user data session is encrypted.
[0038] Furthermore, the corresponding user plane entity is provided. The operation of the user plane entity helps to detect the encrypted user data sessions and with the transmission of the notification to the data analytics entity the latter can initiate the generation of a session-specific policy rule by the policy control entity.
[0039] Additionally, a method carried out at the policy control entity in the cellular network is provided wherein the policy control entity subscribes to a service provided by the analytics entity of the cellular network by which a detection of a user data session is detected where at least one part of the will data session is encrypted. The policy control entity receives a notification from the analytics entity which includes the information that an encrypted user data session is detected for a user equipment with a list including at least one application which cannot be differentiated due to encryption. The policy control entity determines a policy rule for the corresponding user data session of the at least one application to be applied at a user plane entity which handles the corresponding user data session. Furthermore the determined policy rule is provided to the user plane entity. Furthermore the corresponding policy control entity is provided configured to operate as discussed above or as discussed in further detail below.
[0040] When the policy control entity subscribes to the service by which a detection of encrypted user data session is initiated, it is possible to generate a session specific policy rule to be applied by a user plane entity handling the corresponding user data session.
[0041] Furthermore a system is provided comprising at least two of the above discussed entities. Furthermore a computer program comprising program code is provided wherein execution of the program code causes the at least one processing unit of a policy control entity, the user plane entity or the analytics entity to carry out a method as discussed above or as discussed in further detail below.
[0042] Last but not least, a carrier is provided comprising the computer program, wherein the carrier is one of an electronic signal, optical signal, radio signal, or computer readable storage medium.
[0043] It is to be understood that the features mentioned above and features yet to be explained below can be used not only in the respective combinations indicated, but also in other combinations or in isolation without departing from the scope of the present invention. Features of the above- mentioned aspects and embodiments described below may be combined with each other in other embodiments unless explicitly mentioned otherwise.
[0044] Brief description of the drawings
[0045] The foregoing and additional features and effects of the application will become apparent from the following detailed description when read in conjunction with the accompanying drawings in which like reference numerals refer to like elements.
[0046] Fig. 1 shows a schematic architectural view of a 3 GPP environment in which the present application can be applied.
[0047] Figs. 2a and 2b show a schematic message exchange between the involved entities for improving the handling of encrypted data sessions. Fig. 3 shows an example flowchart of a method carried out by the analytics entity involved in Fig. 2.
[0048] Fig. 4 shows an example flowchart of a method carried out by a user plane entity in the situation shown in Fig. 2.
[0049] Fig. 5 shows an example flowchart of a method carried out by a policy control entity in a situation discussed in connection with Fig. 2.
[0050] Fig. 6 shows an example schematic representation of an analytics entity configured to operate as discussed in connection with Fig. 2 and 3.
[0051] Fig. 7 shows an example schematic representation of a user plane entity configured to operate as discussed in connection with Figs. 2 and 4.
[0052] Fig. 8 shows a schematic representation of a policy control entity configured to operate as discussed in connection with Figs. 2 and 5.
[0053] Detailed
[0054] In the following, embodiments of the invention will be described in detail with reference to the accompanying drawings. It is to be understood that the following description of embodiments is not to be taken in a limiting sense. The scope of the invention is not intended to be limited by the embodiments described hereinafter or by the drawings, which are to be illustrative only.
[0055] The drawings are to be regarded as being schematic representations, and elements illustrated in the drawings are not necessarily shown to scale. Rather, the various elements are represented such that their function and general purpose becomes apparent to a person skilled in the art. Any connection or coupling between functional blocks, devices, components of physical or functional units shown in the drawings and described hereinafter may also be implemented by an indirect connection or coupling. A coupling between components may be established over a wired or wireless connection. Functional blocks may be implemented in hardware, software, firmware, or a combination thereof. Within the context of the present application, the term “mobile entity” or “user equipment” (UE) refers to a device for instance used by a person (i.e. a user) for his or her personal communication. It can be a telephone type of device, for example a telephone or a Session Initiating Protocol (SIP) or Voice over IP (VoIP) phone, cellular telephone, a mobile station, cordless phone, or a personal digital assistant type of device like laptop, notebook, notepad, tablet equipped with a wireless data connection. The UE may also be associated with nonhumans like animals, plants, or machines. A UE may be equipped with a SIM (Subscriber Identity Module) or electronic-SIM comprising unique identities such as IMSI (International Mobile Subscriber Identity), TMSI (Temporary Mobile Subscriber Identity), or GUTI (Globally Unique Temporary UE Identity) associated with the user using the UE. The presence of a SIM within a UE customizes the UE uniquely with a subscription of the user.
[0056] For the sake of clarity, it is noted that there is a difference but also a tight connection between a user and a subscriber. A user gets access to a network by acquiring a subscription to the network and by that becomes a subscriber within the network. The network then recognizes the subscriber (e.g. by IMSI, TMSI or GUTI or the like) and uses the associated subscription to identify related subscriber data. A user is the actual user of the UE, and the user may also be the one owning the subscription, but the user and the owner of the subscription may also be different. E.g. the subscription owner may be the parent, and the actual user of the UE could be a child of that parent.
[0057] The present application provides a mechanism which is based on the following idea. When traffic (for certain application / s and / or traffic type / s) is encrypted (e.g. through Apple's Private Relay and Google's One VPN) and cannot be differentiated by a UPF, the network (based on analytics) determines to install a recommendation such as URSP rule / s for certain application / s and / or traffic type / s, so that traffic goes through separate PDU session / s and differentiated traffic management actions (e.g. Charging, QoS, etc) can be applied by a mobile network operator (MNO). Accordingly, a mechanism is provided In summary, this invention proposes a mechanism which allows the network operator to apply differentiated traffic management actions (e.g. Charging, QoS, etc), when traffic is encrypted, by assisting PCF to determine the URSP rules for the session, based on Analytics (NWDAF).
[0058] A consumer (e.g. PCF) subscribes to NWDAF on Encrypted Traffic analytics (Analytic- ID=EncryptedTraffic), by triggering a subscription request such as a Nnwdaf_AnalyticsSubscription_Request message including the following parameters: - Analytic-ID= EncryptedTraffic
[0059] - Analytic-Target (LIE-ID, UE-Group-ID, anyllE). This indicates the UE / s which are the target for this analytic.
[0060] - Analytic-Filter (List of applications and / or traffic types, DNN, S-NSSAI, Area): this indicates filtering information (e.g. list of applications and / or traffic types, DNN, slice and / or area) for this analytic.
[0061] Based on the above analytic subscription, NWDAF triggers data collection from the following network functions:
[0062] UDR: to retrieve the subscriber policy data for LIE-ID (e.g. if the subscriber has active subscription / s to certain application / s or traffic type / s, e.g. a gaming subscription).
[0063] UPF: to retrieve user plane related information. It is possible to reuse and extend the “UserDatallsageMeasures” event defined in TS 23.502, v18.2.0 clause 5.2.26.2.
[0064] Based on the data collected above, NWDAF runs analytic processes, including e.g.:
[0065] If the subscriber has an active subscription to certain application / s and / or traffic type / s, and the UPF has not reported traffic (or the reported traffic has deviations with respect to the historic subscriber behavior) for all or some of those application / s and / or traffic type / s, and / or UPF has reported the detection of an encryption mechanism like Apple's Private Relay or Google's One VPN, NWDAF might determine some traffic cannot be differentiated by the UPF and consequently the need to differentiate that traffic via URSP rules. If so, a list of application / s and / or traffic type / s and the corresponding candidate URSP rule / s might be derived by NWDAF.
[0066] NWDAF provides a list of application / s and / or traffic type / s which cannot be differentiated by the UPF and recommendations to the consumer (e.g. PCF), by indicating which specific actions the consumer might take on a per global (any UE) or on a per UE-Group or on a per UE-ID basis, e.g. to assist PCF on which URSP rules (for certain application / s and / or traffic type / s) to install for the corresponding PDU sessions. NWDAF generates the analytic result, including inter alia: For each UE-ID, UE-Group-ID or anyUE:
[0067] - A list of application / s and / or traffic type / s which cannot be differentiated by the UPF due to encryption and the detected encryption mechanism.
[0068] List of Recommendations. This indicates which specific action / s the consumer might take e.g. to assist PCF on which URSP rules (for certain application / s and / or traffic type / s) to install for the corresponding PDU sessions. Based on the Analytic-Result, the Consumer (e.g. PCF) applies the corresponding actions, e.g:
[0069] In case the corresponding PDU session(s) is / are active, PCF to install / update the LIRSP rules for the session(s) based on NWDAF recommendations.
[0070] In case the corresponding PDU session(s) is / are not active, PCF to store in UDR (e.g. as subscriber policy data or as application data) the relevant information, so when the PDU session(s) is / are created later on, the PCF is able to install the URSP rules for those new sessions based on NWDAF recommendations.
[0071] Fig. 2a and 2b show a sequence diagram with the involved entities, such as an analytics entity 100 implemented as NWDAF, user plane entity 200 implemented as UPF, a policy control entity 300 implemented as PCF, a user equipment 50, a session management entity or SMF 60, a user data repository , UDR 70 and an application server 80. A possible implementation of the steps is indicated in parentheses after each step
[0072] Steps S11 (Consumer NF subscribes to NNWDAF Analytics) and S12: (Nndwdaf_AnalyticsSubscription_Subscribe request {Analytics-1 D=EncryptedTraffic, Analytic- Target (UE-ID, U-Group-ID, any UE), Analytic-Filter (List of applications and / or traffic types, DNN, S-NSSAI, Area): A consumer (e.g. PCF 300) subscribes to NWDAF 100 on Encrypted Traffic analytics (Analytic-ID= EncryptedTraffic), by triggering a Nnwdaf_AnalyticsSubscription_Subscribe request message including parameters such as:
[0073] - Analytic-ID= EncryptedTraffic
[0074] - Analytic-Target (UE-ID, UE-Group-ID, anyUE). This indicates the UE / s which are the target for this analytic.
[0075] - Analytic-Filter (List of applications and / or traffic types, DNN, S-NSSAI, Area): this indicates filtering information (e.g. list of applications and / or traffic types, DNN, slice and / or area) for this analytic.
[0076] Step S13: (Response) NWDAF 100 answers the request message in Step S12 with a successful response (accepting the request).
[0077] Steps S14: (NNWDAF triggers data collection from UDR) and S15 (Nudr_Read {UE-ID}) NWDAF triggers data collection from UDR to retrieve the subscriber policy data for UE-ID (e.g. if the subscriber has active subscription / s to certain application / s or traffic type / s, e.g. a gaming subscription), e.g. by triggering a Nudr_Read message including as parameter the UE-ID. Step S16: UDR retrieves the subscriber policy data for LIE-ID.
[0078] Step S17: (Response, {subscriber policy data including the list of applications and / or traffic types which require differentiated traffic management}) UDR answers the message in step S15 including the subscriber policy data for UE-ID.
[0079] Steps S18 (NNWDAF triggers data collection from UPF) and S19: (Nsmf_EventExposure_Subscribe request {Event-ID=UserDataUsageMeasures, UE-ID, MeasurementType- ’Volume”, “Application_Related_lnformation”,
[0080] “ENCRYPTION_RELATED_INFORMATION, MeasurementTarget=”PER_SESSION”,
[0081] GranularityofMeasurement=”PER_FLOW”}) NWDAF 100 triggers data collection from UPF 200 (e.g. via SMF 60), specifically to retrieve information relative to user plane traffic detected by UPF for UE-ID. It is possible to reuse and extend the existing event “UserDataUsageMeasures” defined in TS 23.502 clause 5.2.26.2. To do this, NWDAF triggers (via SMF) a Nsmf_EventExposure_Subscribe request message including parameters such as:
[0082] • Event-ID=UserDataUsageMeasures
[0083] • UE-ID
[0084] • MeasurementType- 'VOLUME", "APPLICATION_RELATED_INFORMATION", "ENCRYPTION_RELATED_INFORMATION". This indicates the measurement types, which in this case it is set both to existing volume and to application related information, plus the encryption related information, which is to request if any encryption mechanism (e.g. Apple's Private Relay or Google's One VPN) has been detected in the PDU Session for the target traffic.
[0085] • MeasurementTarget="PER_SESSION". Indicates to retrieve user plane traffic data for the whole UE-ID's PDU session.
[0086] • GranularityOfMeasurement="PER_FLOW. This indicates the granularity of the measurement, which in this case it is per flow within UE-ID's PDU session.
[0087] Step S20: (Nupf_EventExposure_Subscribe request {Event-IID=UserDataUsageMeasures, UE-ID, Measurement Type=”Volume” “Application_Related_lnformation”, “ENCRYPTION-RELA TEDJNFORMA TION, MeasurementTarget=”Per_SESSION”,
[0088] GranularityofMeasurement="Per_Flow’}) SMF 60 triggers towards UPF a Nupf_EventExposure_Subscribe request message including the following parameters:
[0089] • Event-ID=UserDataUsageMeasures • UE-ID
[0090] • MeasurementType- 'VOLUME", "APPLICATION_RELATED_INFORMATION", "ENCRYPTION_RELATED_INFORMATION". This indicates the measurement types, which in this case it is set both to existing volume and to application related information, plus the encryption related information, which is to request if any encryption mechanism (e.g. Apple's Private Relay or Google's One VPN) has been detected in the PDU Session for the target traffic.
[0091] • MeasurementTarget="PER_SESSION". Indicates to retrieve user plane traffic data for the whole UE-ID's PDU session.
[0092] • GranularityOfMeasurement="PER_FLOW. This indicates the granularity of the measurement, which in this case it is per flow within UE-ID's PDU session.
[0093] Step S21 : (Response) UPF 200 answers the request message in Step S20 with a successful response (accepting the request).
[0094] Step S22: (Response, Application traffic (App-ID=example.com)) SMF 60 answers the request message in Step S19 with a successful response (accepting the request).
[0095] Steps S23: (UE starts an application example.com) and S24 (Application traffic) User starts application (App-ID=example.com).
[0096] Steps S25 (UPF, based on the requested event, stores data for each flow within application session.) and S26: (Application traffic, Event Reporting) UPF 200 runs PDR matching procedure and, based on the requested event (Event-ID=UserDataUsageMeasures), stores data for each flow within the application session, e.g:
[0097] For each detected flow matching the default PDR (match-all rule) (not an exhaustive list):
[0098] Timestamp (start and stop)
[0099] 5-tuple
[0100] Volume Measurement: measures of data volume exchanged (UL, DL and / or overall) and / or number of packets exchanged (UL, DL and / or overall).
[0101] URL / s and / or Domain name / s detected for that flow.
[0102] Encryption mechanism detected for that flow (e.g. Apple's Private Relay or Google's One VPN). Steps S27: (UPF reports Event-ID=UserDataUsageMeasures) and S28 (Nupf_EventExposure_Notify request {Event-ID=UserDataUsageMeasures, UE-ID, UserDataUsageMeasuresInfo}) UPF 200 continues gathering data for Event-ID= UserDatallsageMeasures and at some point (e.g. periodic reporting), UPF reports data for Event-ID= UserDataUsageMeasures. In order to do that, UPF notifies NWDAF by triggering Nupf_EventExposure_Notify request message including the following parameters:
[0103] Event-ID= UserDataUsageMeasures
[0104] - UE-ID
[0105] UserDataUsageMeasuresInfo. This includes the following information (stored from previous steps):
[0106] For each detected flow matching the PDR corresponding to the catch-all rule (not an exhaustive list):
[0107] Timestamp (start and stop)
[0108] 5-tuple
[0109] Volume Measurement: measures of data volume exchanged (UL, DL and / or overall) and / or number of packets exchanged (UL, DL and / or overall).
[0110] URL / s and / or Domain name / s detected for that flow.
[0111] Encryption mechanism detected for that flow (e.g. Apple's Private Relay or Google's One VPN).
[0112] Step S29: (Response) NWDAF answers the message in Step S28 with a successful response. Step S30 (N NWDAF produces analytics based on the data collected) NWDAF 100, based on the data collected from UDR and UPF, runs analytic processes, specifically:
[0113] If the subscriber has an active subscription to certain application / s and / or traffic type / s, and the UPF has not reported traffic (or the reported traffic has deviations with respect to the historic subscriber behavior) for all or some of those application / s and / or traffic type / s, and / or UPF has reported the detection of an encryption mechanism like Apple's Private Relay or Google's One VPN, NWDAF might determine some traffic cannot be differentiated by the UPF and consequently the need to differentiate that traffic via URSP rules. If so, a list of application / s and / or traffic type / s and the corresponding candidate URSP rule / s might be derived by NWDAF.
[0114] NWDAF 100 provides a list of application / s and / or traffic type / s which cannot be differentiated by the UPF and recommendations to the consumer (e.g. PCF), by indicating which specific actions the consumer might take on a per global (anyUE) or on a per UE-Group or on a per LIE-ID basis, e.g. to assist PCF on which URSP rules (for certain application / s and / or traffic type / s) to install for the corresponding PDU sessions.
[0115] NWDAF generates the analytic result, including (at least):
[0116] For each LIE-ID, UE-Group-ID or anyllE:
[0117] - A list of application / s and / or traffic type / s which cannot be differentiated by the UPF due to encryption and the detected encryption mechanism.
[0118] List of Recommendations. This indicates which specific action / s the consumer might take e.g. to assist PCF on which LIRSP rules (for certain application / s and / or traffic type / s) to install for the corresponding PDU sessions.
[0119] Step S31: (Nndwaf_AnalyticsSubscription_Notify request {Analytic- / D=EncryptedTraffic, AnalyticResult (including recommendations}) Based on the above, NWDAF 100 notifies the Consumer (e.g. PCF 300) by triggering a Nnwdaf_AnalyticsSubscription_Notify request message including the following parameters:
[0120] - Analytic-ID= EncryptedTraffic
[0121] - AnalyticResult. This includes (at least) the following information (stored in Step 20 above):
[0122] For each UE-ID, UE-Group-ID or anyUE:
[0123] - A list of application / s and / or traffic type / s which cannot be differentiated by the UPF due to encryption and the detected encryption mechanism.
[0124] List of Recommendations. This indicates which specific action / s the consumer might take e.g. to assist PCF on which URSP rules (for certain application / s and / or traffic type / s) to install for the corresponding PDU sessions.
[0125] Step S32: (Response) Consumer answers the message in Step S31 with a successful response.
[0126] Step S33: (Consumer applies the corresponding actions based on the AnalyticResult (specifically to install / update URSP rules and / or store the relevant data in UDR for subsequent PDU sessions)) Consumer (e.g. PCF 300) applies the corresponding actions based on the AnalyticResult, e.g:
[0127] In case the corresponding PDU session / s is / are active, PCF to install / update the URSP rules (for certain application / s and / or traffic type / s) for the session / s based on NWDAF recommendations. In case the corresponding PDU session / s is / are not active, PCF to store in UDR (e.g. as subscriber policy data or as application data) the relevant information, so when the PDU session / s is / are created later on, the PCF is able to install the URSP (for certain application / s and / or traffic type / s) rules for those new sessions based on NWDAF recommendations.
[0128] In a step not shown the PCF 300 provides the generated rules to the user plane entity or UE. For example, PCF 300 might provide the generated rules to UE as URSP rules, including the following information (based on the analytic result and recommendation received from NWDAF):
[0129] • Traffic descriptor: including the application / s and / or traffic type / s (which cannot be differentiated by the UPF due to encryption).
[0130] • Route selection descriptor: including S-NSSAI and / or DNN. For example, several slices (S-NSSAI / s) can be configured to allow for traffic differentiation.
[0131] UE stores the received URSP rules and routes application traffic through the corresponding PDU session. This allows UPF to differentiate the application / s and / or traffic type / s as they are carried into separate PDU sessions.
[0132] Fig. 3 summarizes some of the steps carried out by the analytics entity, the NWDAF 100 in the method discussed above in connection with Figs. 2a and 2b. In step S41 the analytics entity triggers the detection of the encrypted traffic at a user plane entity handling user data sessions in the network. This was discussed in more detail above in connection with step S19. Furthermore, in step S42 the analytics entity receives a notification from the user plane entity 200 that a user data session has been detected which is encrypted or where at least a part of the user data session is encrypted. This was discussed above in connection with Fig. 2 in step S28. In step S43 the analytics entity 100 determines based on the received notification a list with at least one application which generates the encrypted user data session as discussed above in connection with step S30 and in step S44 the list is finally provided with the at least one application to the policy control entity 300 of the cellular network. This was discussed above in connection with step S31.
[0133] Fig. 4 summarizes in more detail some of the steps carried out by the user plane entity in the method discussed above in connection with Fig. 2. In step S51 the user plane entity, the UPF 200 receives a request to detect a user data session where at least a part of the user data session is encrypted. This was discussed above in connection with step S20. The user plane entity then monitors the traffic and detects a user data session where at least a part of the was a data session is encrypted in step S52. This was discussed above in connection with step S27 and based on the detection in step S53 the user plane entity or UPF 200 transmits a notification to the analytics entity of the cellular network that a user data session has been detected where at least a part of the user data session is encrypted. This was discussed above in connection with Fig. 2 in step S28 in more detail.
[0134] Fig. 5 describes in more detail some of the steps carried out by the policy control entity in the situation discussed in connection with Fig. 2. The policy control entity 300 subscribes to a service provided by the analytics entity by which the policy control entity asks to be informed when a user data session is detected where at least a part of the session is encrypted (S61). This was discussed above in step S12. The policy control entity then receives in step S62 the notification from the analytics entity that encrypted user data traffic is detected wherein the notification includes a list with at least one application which cannot be differentiated due to encryption. This was discussed in connection with Fig. 2 in step S31. In step S63 the policy control entity determines a policy rule for the corresponding user data session which is to be applied at a user plane entity handling the corresponding session. This was discussed in step S33 in connection with Fig. 2. The determined policy rule is furthermore provided in step S64 to the user plane entity.
[0135] Fig. 6 shows a schematic architectural view of one possible implementation of the analytics entity 100 which may be implemented as NWDAF in the network. The analytics entity comprises an interface 110 provided for transmitting user data or control messages to other entities and provided for receiving user data or control messages from other entities wherein in the present situation exchange with the user plane entity 200 and the policy control entity 300 can be considered. The analytics entity 100 furthermore comprises a processing unit 120 which is responsible for the operation of entity 100. The processing unit 120 comprises one or more processors and carry out instructions stored on a memory 130, wherein the memory may include a read-only memory, a random access memory, a mass storage, a hard disk or the like. The memory can furthermore include a suitable program code to be executed by the processing unit 120 so as to implement the above described functionalities in which the analytics entity is involved. The analytics entity may be implemented in a single hardware element or may be distributed over several locations in a cloud implementation. Fig. 7 shows a schematic architectural view of a user plane entity 200 which handles user plane sessions in the situation discussed in connection with Fig. 2. The user plane entity 200 comprises an interface 220 for receiving user data and control messages from other entities and for transmitting user data and control messages to other entities. The interface 210 handles the user data packets and can receive the information from the analytics entity and transmit the corresponding notifications to the analytics entity. The user plane entity 200 furthermore comprises a processing unit 220 which is responsible for the operation of the user plane entity 200. The processing unit 220 can comprise one or more processors and can carry out instructions stored on a memory 230, wherein the memory may include a read-only memory, a random access memory, a mass storage, a hard disk or the like. The memory 230 can furthermore include suitable program code to be executed by the processing unit 220 so as to implement the above-described functionalities in which the user plane entity is involved. The entity 200 can be implemented in a single node or may be distributed over several nodes or locations in a cloud implementation.
[0136] Fig. 8 shows a further schematic architectural view of a policy control entity 300 which generates policy voice as discussed in connection with Fig. 2. The policy control entity 300 comprises an interface 310 provided for the exchange of data and control messages with other entities. The interface can inter alia receive the notification from the analytics entity without the encrypted user data traffic and can provide the determined policy to the user plane entity. The policy control entity furthermore comprises a processing unit 320 which is responsible for the operation of the policy control entity 300. The processing unit 320 comprises one or more processors and can carry out instructions stored on a memory 330, wherein the memory may include a read-only memory, a random access memory, a mass storage, a hard disk or the like. The memory furthermore includes suitable program code to be executed by the processing unit 320 so as to implement the above-described functionalities in which the policy control entity is involved. The policy control entity may be implemented in a single node in the network or may be distributed over several nodes or locations in a cloud implementation.
[0137] From the above said some general conclusions can be drawn for the different entities involved. As far as the analytics entity 100 is concerned when the list is determined as discussed above in connection with step S30 the list can include for each of the at least one application a traffic rule recommendation indicating how the encrypted at least one part of the user data session should be transmitted through the network. With this recommendation it is then possible to handle this traffic in a separate way and to apply separate rules to this traffic.
[0138] The traffic rule recommendation can indicate that the encrypted at least one part of the user data session should be transmitted as a separate encrypted user data session through the network. With this recommendation it is possible to have a separate policy for this encrypted user data session.
[0139] The traffic rule recommendation may include a traffic descriptor and a route selection descriptor indicating that a user equipment from which the encrypted at least one part of the user data session is transmitted through the network indicates a path of the encrypted at least one part of the user data session through the network.
[0140] Furthermore it is possible that the policy control entity is a consumer of a service provided by the analytics entity to which the consumer had subscribed and by which the analytics entity informs the consumer when at least a part of the user data session is encrypted by providing a list with the at least one application which generates an encrypted data session.
[0141] The analytics entity can furthermore receive a subscription request from the policy control entity by which the policy control entity subscribes to the service provided by the analytics entity. This subscription request can comprise at least one parameter of interest for the user data session, wherein the entity analytics entity informs the policy control entity when a user data session meeting the at least one parameter of interest is detected, wherein the triggering and providing is carried out in response to the subscription request.
[0142] The at least one parameter of interest can include items such as a list of application with encrypted user data sessions, a list of traffic types, identifier of a user equipment or group of user equipments involved in the user data session.
[0143] The triggering of the detection at the user plane entity can include the transmission of a request to a session management entity of the cellular network by which the session management entity is requested to trigger the detection of the encrypted user data traffic at the user plane entity. Accordingly here the analytics entity informs the user plane entity via the session management entity. The received notification from the user plane entity can include a volume of the user data session where at least a part is encrypted, it can include a source and a destination address of the user data session, a URL and / or a domain name involved in the user data session, or a used encryption mechanism.
[0144] For determining the list the analytics entity may carry out the steps of identifying the encrypted at least one part of the user data session based on a subscription to an application or a type of traffic by a subscriber of the cellular network which the encrypted user data session is related.
[0145] Furthermore it is possible that the list provided to the policy control entity includes a recommendation for the policy control entity that, for the encrypted user data session a user equipment involved in the encrypted user data session should select the route of the encrypted user data session through the cellular network.
[0146] As far as the user plane entity is concerned, the transmitted notification transmitted to the analytics entity can include a volume of the user data session where at least a part of the session is encrypted, the source and destination address of the user data session, the URL and / or domain name involved in the user data session and a used encryption mechanism.
[0147] The received request received by the user plane entity can request the determination of an encryption mechanism used for the encrypted at least one part of the user data session. For each of the user data session where at least one part is encrypted the used encryption mechanism can be determined and transmitted in the notification.
[0148] As far as the policy control entity is concerned the subscription with the analytics entity can include a parameter of interest for the user data session and this parameter can include a list of applications with encrypted user data sessions, a list of traffic types, or an identifier for a user equipment or a group of user equipments involved in the user data session.
[0149] The policy rule which is provided to the user plane entity can include an indication that a user equipment involved in the encrypted user data session should select the route of the encrypted user data session through the cellular network. Preferably the policy rule can include a UE route selection policy, URSP which is generated based on the notification received from the analytics entity. The above discussed solution has several advantages. By way of example, it allows the network operator to apply differentiating traffic management actions such as charging or quality of service when traffic is encrypted in a simple and efficient way even when challenging encryption scenarios with a dual-proxy and VPN deployments are used. Furthermore the user privacy is preserved and at the same time the operator policies and subscription terms can be enforced. The use of LIRSP rules allows the moving of a certain traffic into a different slice with specific traffic handling such as the maximum bit rate or the guaranteed bit rate.
Claims
Claims1. A method carried out by an analytics entity (100) of a cellular network, the method comprising:- triggering, (S19, S41) at a user plane entity (200) handling user data sessions in the cellular network, a detection of an encrypted user data session,- receiving (S28, S42) a notification from the user plane entity (200) that a user data session has been detected where at least one part of the user data session is encrypted,- determining (S30, S43), based on the notification, a list with at least one application which generates the encrypted user data session,- providing (S31 , S44) the list with the at least one application to a policy control entity (300) of the cellular network.
2. The method of claim 1 , wherein the determined list includes, for each of the at least one application a traffic rule recommendation indicating how the encrypted at least one part of the user data session should be transmitted through the cellular network.
3. The method of claim 2, wherein the traffic rule recommendation indicates that the encrypted at least one part of the user data session should be transmitted as a separate encrypted user data session through the cellular network.
4. The method of claim 2 or 3, wherein the traffic rule recommendation includes a traffic descriptor and a route selection descriptor indicating that a user equipment from which the encrypted at least one part of the user data session is transmitted through the cellular network indicates a path of the encrypted at least one part of the user data session through the cellular network.
5. The method of any preceding claim, wherein the policy control entity is a consumer of a service provided by the analytics entity to which the consumer had subscribed and by which the analytics entity informs the consumer when at least a part of the user data session is encrypted by providing the list with at least one application which generates an encrypted user data session.
6. The method of any preceding claim, further receiving a subscription request from the policy control entity by which the policy control entity subscribes to a service providedby the analytics entity, the subscription request comprising at least one parameter of interest for the user data session, wherein the analytics entity informs the policy control entity when a user data session meeting the at least one parameter of interest is detected, wherein the triggering and providing is carried out in response to the subscription request.
7. The method of claim 6 wherein the at least one parameter of interest includes at least one of the following;- a list of application with encrypted user data sessions,- a list of traffic types- an identifier for a user equipment or a group of user equipment involved in the user data session.
8. The method of any preceding claim, wherein triggering the detection comprises transmitting a request to a session management entity of the cellular network by which the session management entity is requested to trigger the detection of the encrypted user data session at the user plane entity.
9. The method of any preceding claim, wherein the received notification comprises at least one of the following:- a volume of the user data session where the at least one part is encrypted,- a source and destination address of the user data session,- a URL and / or domain name involved in the user data session,- a used encryption mechanism.
10. The method of any preceding claim, wherein determining the list comprises identifying the encrypted at least one part of the user data session based on a subscription to an application or type of traffic by a subscriber of the cellular network to which the encrypted user data session is related.
11. The method of any preceding claim, wherein the list provided to the policy control entity comprises a recommendation for the policy control entity, that for the encrypted user data session a user equipment involved in the encrypted user data session should select the route of the encrypted user data session through the cellular network.
12. A method carried out at a user plane entity handling user data sessions in a cellular network, the method comprising:- receiving (S51, S20) a request to detect a user data session where at least one part of the user data session is encrypted,- detecting (S52, S27) the user data session where at least one part of the user data session is encrypted,- transmitting (S53, S28) a notification to an analytics entity of the cellular network that a user data session has been detected where at least a part of the user data session is encrypted.
13. The method of claim 12, wherein the transmitted notification comprises at least one of the following:- a volume of the user data session where the at least one part is encrypted,- a source and destination address of the user data session,- a URL and / or domain name involved in the user data session,- a used encryption mechanism.
14. The method of claim 12 or 13, wherein the received request requests to determine a encryption mechanism used for the encrypted at least one part of the user data session, wherein for each user data session where at least one part is encrypted the used encryption mechanism is determined and transmitted in the notification.
15. A method carried out at a policy control entity of a cellular network, the method comprising:- subscribing (S61, S12)to a service provided by an analytics entity of a cellular network by which a detection of an user data session is detected where at least one part of the user data session is encrypted,- receiving (S62, S31) a notification from the analytics entity including information that an encrypted user data session is detected for a user equipment with a list including at least one application which cannot be differentiated due to encryption,- determining (S63, S33)a policy rule for the corresponding user data session of the at least one application to be applied at a user plane entity handling the corresponding user data session,- providing (S64) the determined policy rule to at least one of the user plane entity and a user equipment, UE, involved in the user data session.
16. The method of claim 15, wherein the subscription comprising at least one parameter of interest for the user data session, wherein the at least one parameter of interest includes at least one of the following;- a list of application with encrypted user data sessions,- a list of traffic types- an identifier for the user equipment or a group of user equipments involved in the user data session.
17. The method of claim 15 or 16, wherein the policy rule includes an indication that a user equipment involved in the encrypted user data session should select the route of the encrypted user data session through the cellular network.
18. The method of claim 17, wherein the policy rule includes a UE route selection policy, LIRSP, generated based on the notification received from the analytics entity.
19. An analytics entity of a cellular network, configured to :- trigger, by a user plane entity (200) handling user data sessions in the cellular network, a detection of an encrypted user data session,- receive a notification from the user plane entity (200) that a user data session has been detected where at least one part of the user data session is encrypted,- determine, based on the notification, a list with at least one application which generates an encrypted user data session,- provide the list with the at least one application to a policy control entity (300) of the cellular network.
20. The analytics entity of claim 19, wherein the determined list includes, for each of the at least one application a traffic rule recommendation indicating how the encrypted at least one part of the user data session should be transmitted through the cellular network.
21. The analytics entity of claim 19 or 20, wherein the traffic rule recommendation indicates that the encrypted at least one part of the user data session should be transmitted as a separate encrypted user data session through the cellular network.
22. The analytics entity of claim 20 or 21 , wherein the traffic rule recommendation includes a traffic descriptor and a route selection descriptor indicating that a user equipment from which the encrypted at least one part of the user data session is transmitted through the cellular network indicates a path of the encrypted at least one part of the user data session through the cellular network.
23. The analytics entity of any of claims 19 to 22, wherein the policy control entity is a consumer of a service provided by the analytics entity to which the consumer had subscribed, wherein the analytics entity is configured to inform the consumer when at least a part of the user data session is encrypted and to provide a list with at least one application which generates an encrypted data session.
24. The analytics entity of any of claims 19 to 23, further being configured to- receive a subscription request from the policy control entity by which the policy control entity subscribes to a service provided by the analytics entity, the subscription request comprising at least one parameter of interest for the user data session, and- inform the policy control entity when a user data session meeting the at least one parameter of interest is detected, wherein the triggering and providing is carried out in response to the subscription request.
25. The analytics entity of claim 24, wherein the at least one parameter of interest includes at least one of the following;- a list of application with encrypted user data sessions,- a list of traffic types- an identifier for a user equipment or a group of user equipments involved in the user data session.
26. The analytics entity of any of claims 19 to 25, further being configured, for triggering the detection, to transmit a request to a session management entity of the cellular network by which the session management entity is requested to trigger the detection of the encrypted user data session at the user plane entity.
27. The analytics entity of any of claims 19 to 26, wherein the received notification comprises at least one of the following:- a volume of the user data session where the at least one part is encrypted,- a source and destination address of the user data session,- a URL and / or domain name involved in the user data session,- a used encryption mechanism.
28. The analytics entity of any of claims 19 to 27, further being configured, for determining the list, to identify the encrypted at least one part of the user data session based on a subscription to an application or type of traffic by a subscriber of the cellular network to which the encrypted user data session is related.
29. The analytics entity of any of claims 19 to 28, wherein the list provided to the policy control entity comprises a recommendation for the policy control entity, that for the encrypted user data session a user equipment involved in the encrypted user data session should select the route of the encrypted user data session through the cellular network.
30. A user plane entity handling user data sessions in a cellular network, configured to- receive a request to detect user data session where at least one part of the user data session is encrypted,- detect the user data session where at least one part of the user data session is encrypted,- transmit a notification to an analytics entity of the cellular network that a user data session has been detected where at least a part of the user data session is encrypted.31 . The user plane entity of claim 30, wherein the transmitted notification comprises at least one of the following:- a volume of the user data session where the at least one part is encrypted,- a source and destination address of the user data session,- a URL and / or domain name involved in the user data session,- a used encryption mechanism.
32. The user plane entity of claim 30 or 31 , wherein the received request requests to determine a encryption mechanism used for the encrypted at least one part of the user data session, the user plane entity being configured, for each user data session where at least one part is encrypted the used, to determine the encryption mechanism and to transmit the encryption mechanism in the notification.
33. A policy control entity configured to- subscribe to a service provided by an analytics entity of a cellular network by which a detection of an user data session is detected where at least one part of the user data session is encrypted,- receive a notification from the analytics entity including information that an encrypted user data traffic is detected for a user equipment with a list including at least one application which can not be differentiated due to encryption,- determine a policy rule for the corresponding user data session of the at least one application to be applied at a user plane entity handling the corresponding user data session,- provide the determined policy rule to the user plane entity.
34. The policy control entity of claim 33, wherein the subscription comprising at least one parameter of interest for the user data session, wherein the at least one parameter of interest includes at least one of the following;- a list of application with encrypted user data sessions,- a list of traffic types- an identifier for a user equipment or a group of user entities involved in the user data session.
35. The policy control entity of claim 33 or 34, wherein the policy rule includes an indication that a user equipment involved in the encrypted user data session should select the route of the encrypted user data session through the cellular network.
36. The policy control entity of claim 35, wherein the policy rule includes a UE route selection policy, LIRSP, generated based on the notification received from the analytics entity.
37. A system comprising at least 2 entities of the following group of entities including an analytics entity as claimed in any of claims 19 to 29, a user plane entity as mentioned in any of claims 30 to 32, and a policy control entity as mentioned in any of claims 33 and 36.
38. A computer program comprising program code to be executed by at least one processing unit of an analytics entity wherein execution of the program code causes the at least one processing unit to carry out a method as mentioned in any of claims 1 to 11 .
39. A computer program comprising program code to be executed by at least one processing unit of an user plane entity wherein execution of the program code causes the at least one processing unit to carry out a method as mentioned in any of claims 12 to 14.
40. A computer program comprising program code to be executed by at least one processing unit of an user plane entity wherein execution of the program code causes the at least one processing unit to carry out a method as mentioned in any of claims 15 to 18.
41. A carrier comprising the computer program of any of claims 38 to 40, wherein the carrier is one of an electronic signal, optical signal, radio signal, and computer readable storage medium.
Citation Information
Patent Citations
PDU session for encrypted traffic detection
EP3777066B1
Fraudulent traffic detection based on analytics
WO2022156918A1