Dummy Packets for QoS Control in Encrypted Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for supporting connections between communication devices and destination devices over intermediate network nodes in IP-based communication, such as those using IPSec tunnels, face challenges in controlling or influencing intermediate network nodes for enhancing network performance or Quality of Service (QoS) without complex and inefficient signaling procedures.

Innovation Solution

The method involves sending dummy packets with encoded information in the packet headers through the tunnel, allowing intermediate network nodes to detect and perform predefined actions, thereby influencing network behavior without a separate control channel, using fields like TTL, Total length, or IP addresses that are readable despite payload encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec tunnels are used for encryption, then security is improved, but the ability to control intermediate network nodes for QoS enhancement deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcontrol of intermediate network nodes
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces dummy packets as an intermediary mechanism to convey control information through the encrypted tunnel. These packets contain encoded QoS commands in their headers that intermediate network nodes can detect and act upon, enabling control without breaking encryption. The dummy packets serve as a mediator between the encryption requirement and the control requirement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter being used for control from the encrypted payload to the unencrypted packet header fields. By encoding QoS information in header parameters (such as TTL, total length, or IP addresses) rather than in the encrypted payload, the system maintains security while enabling intermediate nodes to read and act on control information.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If dedicated signaling procedures are used for QoS control, then control capability is improved, but system complexity deteriorates

Engineering Contradiction:
Improvecontrol capabilityVSAvoidsignaling procedures
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges the control signaling function with the existing data transmission tunnel. Instead of creating separate dedicated signaling procedures or control channels, the system combines QoS control information with the encrypted data packets by embedding it in the packet headers. This eliminates the need for additional signaling infrastructure and procedures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The encrypted data tunnel is given a dual function: it continues to provide secure data transmission while simultaneously serving as a carrier for QoS control information through the dummy packets with encoded headers. This multi-functionality eliminates the need for separate control channels and reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If separate control channels are established, then control precision is improved, but network overhead deteriorates

Engineering Contradiction:
Improvecontrol precisionVSAvoidnetwork overhead
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent combines control information transmission with existing data packets by using the packet headers of the encrypted tunnel. This merging approach allows control commands to be conveyed without requiring separate control channels, thereby maintaining control precision while avoiding additional network overhead from duplicate communication paths.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9084234B2Method and base station for supporting a connection between a communication device and a destination device in a target network
Publication Date: 2015.07.14 NEC CORP
  • US9084234B2 patent drawing
  • US9084234B2 patent drawing
  • US9084234B2 patent drawing

AI summary

A method for supporting a connection between a communication device and a destination device in a target network over intermediate network nodes, in particular in the context of Internet Protocol based communication, wherein data between the communication device and the destination device is transmitted via a tunnel established between the communication device or a base station connected to the communication device, as a first tunnel endpoint and a gateway in the target network as a second tunnel endpoint. One or more dummy packets are sent via the tunnel from the first tunnel endpoint towards the second tunnel endpoint, information is encoded in the packet headers of the one or more dummy packets, and at least one of the intermediate network nodes, upon receiving the one or more dummy packets, performs the steps of detecting and/or decoding the encoded information and performing a predefined action dependent on the encoded information.