Content Token Embedding for Encrypted IP Flow Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity of networking architectures in mobile wireless environments, particularly the challenge of identifying Internet Protocol (IP) flows due to encryption, hinders mobile service providers and developers from applying appropriate charging and packet treatment for subscribed services.
Innovation Solution
A system and method that generates a content token based on a trust relationship between application services and mobile service providers, embedding it in unencrypted packet headers, allowing data-plane packet processing nodes to identify IP flows and perform operations like charging and policy application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IP packet content is encrypted to protect user privacy and security, then communication security is improved, but the ability to identify IP flows for charging and packet treatment deteriorates
Solution Approach 1:
The patent segments the packet identification problem by separating encrypted payload content from unencrypted header information. Instead of attempting to identify flows through encrypted content, the system uses unencrypted packet headers containing token information that can be detected without decryption, thus resolving the contradiction between maintaining encryption security and enabling flow identification.
Solution Approach 2:
The patent introduces an intermediary token mechanism where application services generate tokens that are embedded in unencrypted packet headers. These tokens serve as mediators that allow network elements to identify and classify IP flows without needing to decrypt the encrypted payload, thus enabling flow identification while preserving communication security.
2Measurement precision
If deep packet inspection is used to identify encrypted IP flows, then flow identification accuracy is improved, but network processing complexity and computational burden increase
Solution Approach 1:
The patent extracts the identification information from the encrypted payload and places it in the unencrypted packet header as a token. This extraction eliminates the need for computationally intensive deep packet inspection of encrypted content, allowing network elements to identify flows by examining only the unencrypted header portion, thus reducing processing complexity while maintaining identification accuracy.
Solution Approach 2:
The patent replaces the mechanical process of deep packet inspection (which requires decrypting and analyzing packet content) with a simpler information retrieval process where network elements directly read token information from unencrypted packet headers. This substitution dramatically reduces computational burden and network processing complexity.
3Manufacturing precision
If centralized flow identification is implemented to ensure accurate charging, then charging accuracy is improved, but network scalability and distributed processing capability deteriorate
Solution Approach 1:
The patent creates a universal token-based identification mechanism that can be implemented by any network element along the data path. The same token embedded in packet headers can be used by multiple network functions (charging, policing, routing, etc.) without requiring centralized coordination, enabling both accurate charging and distributed processing simultaneously.
Solution Approach 2:
The patent performs preliminary action by embedding the identification token in packet headers at the source (application service) before packets traverse the network. This upfront placement of identification information eliminates the need for centralized flow identification later in the network, enabling distributed elements to independently perform accurate charging and other processing functions.
Data Source
AI summary
An example method is provided in one example embodiment and may include generating a content token, wherein the content token is generated for a particular content type of a particular application service based on a trust relationship established between the particular application service and a mobile service provider; and embedding the content token in one or more packets of a plurality of packets sent to a user equipment (UE) for one or more Internet Protocol (IP) flows associated with the particular content type, wherein the content token is embedded in an unencrypted portion of each packet that is separate from an encrypted data payload portion of each packet.


