Asymmetric 5G Traffic Encryption for Network Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to balance the need for privacy and security in encrypted traffic with the requirement for network operators to perform traffic management actions, as they lack visibility into encrypted traffic due to asymmetric encryption.

Innovation Solution

A mechanism where only public keys are exchanged among parties, allowing the network operator to decrypt and manage encrypted traffic using asymmetric encryption, applying actions like redirection and content enrichment without sharing private keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric encryption is used to protect traffic privacy and security, then confidentiality and authentication are improved, but network operator's ability to perform traffic management actions deteriorates due to lack of traffic visibility

Engineering Contradiction:
Improvetraffic confidentialityVSAvoidtraffic management capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The encryption system is segmented into multiple key pairs with different purposes: one key pair for traffic encryption (providing confidentiality) and another key pair for traffic management (enabling operator visibility). This segmentation allows simultaneous achievement of both privacy protection and operator control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted intermediary (the network operator) is introduced that holds the private decryption key. This intermediary enables the operator to decrypt and manage traffic when needed, while applications maintain encryption capabilities. The intermediary resolves the conflict between encrypted traffic and operator visibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traffic is encrypted using asymmetric encryption, then security is improved, but network operator's visibility into traffic for management actions worsens

Engineering Contradiction:
Improvetraffic securityVSAvoidtraffic visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Different quality attributes are applied to different parts of the encryption system: strong asymmetric encryption is used for traffic confidentiality, while a separate key mechanism provides localized access for the operator. This allows security to be maintained while enabling selective visibility where needed for management actions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the cryptographic parameters by using multiple key pairs instead of a single encryption scheme. One key pair optimizes for security (asymmetric encryption), while another enables operator access. This parameter change allows both security and visibility requirements to be met simultaneously.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If private keys are shared with network operator for decryption, then traffic management capability is improved, but security and authentication deteriorate due to key exposure

Engineering Contradiction:
Improvetraffic management capabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The key management system is segmented into separate key pairs: one for authentication and confidentiality, another for traffic management access. This segmentation ensures that sharing one key pair does not compromise the security properties of the other, resolving the contradiction between operator capability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network operator acts as a trusted intermediary that holds the private key necessary for decryption and management actions. This intermediary relationship is established through secure key distribution mechanisms, allowing the operator to perform management functions without compromising the overall security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12388803B2Traffic management with asymmetric traffic encryption in 5G networks
Publication Date: 2025.08.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12388803B2 patent drawing
  • US12388803B2 patent drawing
  • US12388803B2 patent drawing

AI summary

A network operator node (17) is provided. The network operator node (17) includes processing circuitry (42) configured to receive data traffic that is encrypted using one of an uplink and downlink public cryptographic key, decrypt the data traffic using one of an uplink and downlink private cryptographic key, apply at least a first traffic management action to the decrypted data traffic, after applying at least the first traffic management action, encrypt the data traffic using one of an application server, AS, public cryptographic key and an application client, AC, public cryptographic key where the AS public cryptographic key is associated with an AS private cryptographic key that remains unshared with the network operator node (17), and the AC public cryptographic key is associated with an AC private cryptographic key that remains unshared with the network operator node (17).