Blockchain-Based Encrypted Traffic Detection in Core Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication networks face challenges in reliably identifying and handling service traffic due to encryption, leading to inefficiencies and security vulnerabilities in the core network domain, as operators struggle to accurately detect service types and apply appropriate Quality of Service (QoS) and tariffs without compromising encrypted data.
Innovation Solution
Implementing a blockchain-based system that uses selective endorsement procedures to securely associate traffic detection information with traffic handling information, enabling trustful detection and handling of service traffic without decrypting encrypted data, thereby ensuring accurate QoS and tariff application while maintaining data security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If TLS decryption technology is used to detect service traffic, then service type identification accuracy is improved, but security and confidentiality are compromised
Solution Approach 1:
The patent extracts only the necessary traffic detection information (metadata) from the encrypted traffic flow, without decrypting the actual content. This allows service type identification while preserving the confidentiality and security of the encrypted payload, resolving the contradiction between detection accuracy and security.
Solution Approach 2:
The patent introduces an intermediary mechanism that works with encrypted traffic without requiring full decryption. The core network domain uses intermediate inspection methods to detect service types while the encrypted content remains protected, acting as a mediator between security requirements and detection needs.
2Ease of operation
If general service traffic characteristics are used for detection, then ease of operation is improved, but identification accuracy deteriorates
Solution Approach 1:
The patent applies preliminary action by having the service provider pre-configure and register accurate traffic detection information in the blockchain before service deployment. This pre-registration enables the core network domain to use precise detection rules without requiring complex real-time analysis, improving both accuracy and operational simplicity.
3Object-affected harmful factors
If traffic encryption is implemented, then data security is improved, but service traffic detection capability deteriorates
Solution Approach 1:
The patent extracts detection-relevant metadata from encrypted traffic without decrypting the content. The service provider registers this extracted information in the blockchain, enabling the core network domain to detect service types while the encrypted payload remains secure, thus maintaining both security and detection capability.
Solution Approach 2:
The patent creates a copy of the necessary detection information (traffic patterns, metadata) and stores it in the blockchain. This copy enables accurate detection without requiring access to or decryption of the actual encrypted traffic, preserving security while enabling detection.
4Reliability
If blockchain technology is used to store traffic handling information, then trust and reliability are improved, but device complexity increases
Solution Approach 1:
The patent implements a universal blockchain solution that serves multiple functions: storing traffic detection information, maintaining service level agreements, enabling trust among parties, and providing a tamper-proof record. This multi-functionality justifies the added complexity by consolidating multiple trust-related functions into a single reliable system.
Data Source
AI summary
A technique of configuring a core network domain of a wireless communication network for detection of service traffic that is to be trustfully handled in accordance with traffic handling information stored in a blockchain is provided. A method implementation of this technique comprises receiving, from a service provider, traffic detection information for service traffic that is to be handled in accordance with the traffic handling information. The method further comprises triggering an association, in the blockchain, of the received traffic detection information with the traffic handling information, and providing the traffic detection information to the core network domain for detecting the service traffic that is to be handled in accordance with the traffic handling information.


