Content Token Embedding for Encrypted IP Flow Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing complexity of networking architectures in mobile wireless environments, particularly the challenge of identifying Internet Protocol (IP) flows due to encryption, hinders mobile service providers and developers from applying appropriate charging and packet treatment for subscribed services.

Innovation Solution

A system and method that generates a content token based on a trust relationship between application services and mobile service providers, embedding it in unencrypted packet headers, allowing data-plane packet processing nodes to identify IP flows and perform operations like charging and policy application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IP packet content is encrypted to protect user privacy and security, then communication security is improved, but the ability to identify IP flows for charging and packet treatment deteriorates

Engineering Contradiction:
Improvecommunication securityVSAvoidIP flow identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the packet identification problem by separating encrypted payload content from unencrypted header information. Instead of attempting to identify flows through encrypted content, the system uses unencrypted packet headers containing token information that can be detected without decryption, thus resolving the contradiction between maintaining encryption security and enabling flow identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary token mechanism where application services generate tokens that are embedded in unencrypted packet headers. These tokens serve as mediators that allow network elements to identify and classify IP flows without needing to decrypt the encrypted payload, thus enabling flow identification while preserving communication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If deep packet inspection is used to identify encrypted IP flows, then flow identification accuracy is improved, but network processing complexity and computational burden increase

Engineering Contradiction:
Improveflow identification accuracyVSAvoidnetwork processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the identification information from the encrypted payload and places it in the unencrypted packet header as a token. This extraction eliminates the need for computationally intensive deep packet inspection of encrypted content, allowing network elements to identify flows by examining only the unencrypted header portion, thus reducing processing complexity while maintaining identification accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical process of deep packet inspection (which requires decrypting and analyzing packet content) with a simpler information retrieval process where network elements directly read token information from unencrypted packet headers. This substitution dramatically reduces computational burden and network processing complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Manufacturing precision

If centralized flow identification is implemented to ensure accurate charging, then charging accuracy is improved, but network scalability and distributed processing capability deteriorate

Engineering Contradiction:
Improvecharging accuracyVSAvoidnetwork scalability
Core Design Contradiction:
Manufacturing precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal token-based identification mechanism that can be implemented by any network element along the data path. The same token embedded in packet headers can be used by multiple network functions (charging, policing, routing, etc.) without requiring centralized coordination, enabling both accurate charging and distributed processing simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary action by embedding the identification token in packet headers at the source (application service) before packets traverse the network. This upfront placement of identification information eliminates the need for centralized flow identification later in the network, enabling distributed elements to independently perform accurate charging and other processing functions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10341126B2System and method to facilitate flow identification in a network environment
Publication Date: 2019.07.02 CISCO TECHNOLOGY INC
  • US10341126B2 patent drawing
  • US10341126B2 patent drawing
  • US10341126B2 patent drawing

AI summary

An example method is provided in one example embodiment and may include generating a content token, wherein the content token is generated for a particular content type of a particular application service based on a trust relationship established between the particular application service and a mobile service provider; and embedding the content token in one or more packets of a plurality of packets sent to a user equipment (UE) for one or more Internet Protocol (IP) flows associated with the particular content type, wherein the content token is embedded in an unencrypted portion of each packet that is separate from an encrypted data payload portion of each packet.