Application Layer Proxy for Encrypted Traffic Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication systems face challenges in correlating exposure information with encrypted user data traffic, particularly with protocols like QUIC, making it difficult for network operators and content providers to classify and enforce policies.

Innovation Solution

Implementing an application layer proxy within the mobile communication system that decrypts encrypted traffic, allowing for the exchange of supplemental information such as application identifiers, enabling accurate classification and policy enforcement even with encrypted traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic encryption is implemented to secure communication, then security and privacy are improved, but the ability to detect and classify traffic is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary component (proxy server or network function) that acts as a mediator between the encrypted traffic flow and the detection/classification systems. This intermediary has the capability to decrypt or inspect encrypted traffic while maintaining the security benefits, allowing classification systems to access traffic metadata without compromising end-to-end encryption for all traffic.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network architecture into distinct functional components: one handling encrypted traffic transmission and another handling traffic detection and classification. This segmentation allows each component to be optimized for its specific function while working together within the CUPS framework, enabling both security and detectability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If Deep Packet Inspection (DPI) functionality is used to monitor traffic, then traffic classification accuracy is improved, but processing complexity and overhead are worsened

Engineering Contradiction:
Improvetraffic classification accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the DPI functionality into separate network plane functions rather than embedding it throughout the entire data path. By segmenting the inspection function into specific network nodes (such as UPF or dedicated inspection functions), the processing complexity is localized and managed more efficiently while maintaining high classification accuracy where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary network functions that handle the complex DPI processing, acting as mediators between the high-speed data plane and the detailed inspection requirements. These intermediaries perform the computationally intensive classification tasks, allowing the main data path to remain efficient while still achieving accurate traffic monitoring.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If Control and User Plane Separation (CUPS) architecture is implemented to separate control and user planes, then network flexibility and scalability are improved, but coordination complexity between planes is worsened

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidcoordination complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universal interfaces and standardized protocols between the control plane and user plane components, allowing the same interface mechanisms to handle multiple types of coordination tasks. This multi-functionality reduces the overall coordination complexity despite the separated architecture, as the same framework handles diverse communication and control requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent establishes feedback mechanisms between the control plane and user plane that enable dynamic coordination. The control plane receives feedback from the user plane about traffic conditions and enforcement needs, and adjusts control policies accordingly, creating a coordinated system that manages complexity through continuous information exchange and adaptive control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4233335B1Technique for enabling exposure of information related to encrypted communication
Publication Date: 2025.11.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4233335B1 patent drawingFigure 1
  • EP4233335B1 patent drawingFigure 2a~2d
  • EP4233335B1 patent drawingFigure 3

AI summary

A technique for enabling exposure of information related to encrypted communication between a User Equipment, UE, and an application server in a mobile communication system is disclosed. A method implementation of the technique is performed by the UE and comprises establishing (S302) a communication channel with a network node of the mobile communication system, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in the communication between the UE and the application server, and sending (S304) encrypted traffic through the communication channel to the network node for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node.