Asymmetric 5G Traffic Encryption for Network Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems struggle to balance the need for privacy and security in encrypted traffic with the requirement for network operators to perform traffic management actions, as they lack visibility into encrypted traffic due to asymmetric encryption.
Innovation Solution
A mechanism where only public keys are exchanged among parties, allowing the network operator to decrypt and manage encrypted traffic using asymmetric encryption, applying actions like redirection and content enrichment without sharing private keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If asymmetric encryption is used to protect traffic privacy and security, then confidentiality and authentication are improved, but network operator's ability to perform traffic management actions deteriorates due to lack of traffic visibility
Solution Approach 1:
The encryption system is segmented into multiple key pairs with different purposes: one key pair for traffic encryption (providing confidentiality) and another key pair for traffic management (enabling operator visibility). This segmentation allows simultaneous achievement of both privacy protection and operator control capabilities.
Solution Approach 2:
A trusted intermediary (the network operator) is introduced that holds the private decryption key. This intermediary enables the operator to decrypt and manage traffic when needed, while applications maintain encryption capabilities. The intermediary resolves the conflict between encrypted traffic and operator visibility.
2Reliability
If traffic is encrypted using asymmetric encryption, then security is improved, but network operator's visibility into traffic for management actions worsens
Solution Approach 1:
Different quality attributes are applied to different parts of the encryption system: strong asymmetric encryption is used for traffic confidentiality, while a separate key mechanism provides localized access for the operator. This allows security to be maintained while enabling selective visibility where needed for management actions.
Solution Approach 2:
The system changes the cryptographic parameters by using multiple key pairs instead of a single encryption scheme. One key pair optimizes for security (asymmetric encryption), while another enables operator access. This parameter change allows both security and visibility requirements to be met simultaneously.
3Ease of operation
If private keys are shared with network operator for decryption, then traffic management capability is improved, but security and authentication deteriorate due to key exposure
Solution Approach 1:
The key management system is segmented into separate key pairs: one for authentication and confidentiality, another for traffic management access. This segmentation ensures that sharing one key pair does not compromise the security properties of the other, resolving the contradiction between operator capability and security.
Solution Approach 2:
The network operator acts as a trusted intermediary that holds the private key necessary for decryption and management actions. This intermediary relationship is established through secure key distribution mechanisms, allowing the operator to perform management functions without compromising the overall security architecture.
Data Source
AI summary
A network operator node (17) is provided. The network operator node (17) includes processing circuitry (42) configured to receive data traffic that is encrypted using one of an uplink and downlink public cryptographic key, decrypt the data traffic using one of an uplink and downlink private cryptographic key, apply at least a first traffic management action to the decrypted data traffic, after applying at least the first traffic management action, encrypt the data traffic using one of an application server, AS, public cryptographic key and an application client, AC, public cryptographic key where the AS public cryptographic key is associated with an AS private cryptographic key that remains unshared with the network operator node (17), and the AC public cryptographic key is associated with an AC private cryptographic key that remains unshared with the network operator node (17).


