Encrypted Path Selection With Intermediate Function Discovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing end-to-end encryption systems restrict the activation of functions hosted in intermediate equipment, limiting cooperation between communication endpoints and intermediate nodes, particularly in the context of diverse application needs and evolving Web services protocols like QUIC, which do not allow data insertion or header enrichment by intermediate devices.

Innovation Solution

A method for discovering and selecting transmission functions hosted in intermediate nodes by intercepting signaling messages and adding parameters representing these functions to the messages, allowing intermediate nodes to provide information about their capabilities without accessing the content, thus enabling secure cooperation between communication endpoints and intermediate nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end encryption is implemented to secure data transmission, then security is improved, but intermediate equipment cannot access or process encrypted data

Engineering Contradiction:
ImprovesecurityVSAvoidintermediate equipment functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces signaling messages as an intermediary mechanism that enables intermediate equipment to discover and activate transmission functions without compromising end-to-end encryption. The signaling messages carry function information between endpoints and intermediate nodes, allowing secure cooperation while maintaining encryption integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary discovery of transmission functions through signaling messages before actual data transmission occurs. This allows intermediate equipment to prepare and activate required functions in advance, ensuring both security and functionality are established prior to encrypted data flow.

Inventive Principle:
Principle #10Preliminary action

2Speed

If QUIC protocol is used to improve transmission speed, then speed is improved, but intermediate equipment cannot insert or enrich data

Engineering Contradiction:
Improvetransmission speedVSAvoidintermediate equipment data insertion capability
Core Design Contradiction:
SpeedVSAdaptability or versatility

Solution Approach 1:

The patent adds a new dimension to QUIC protocol by introducing signaling messages that operate alongside the encrypted data channel. This allows intermediate equipment to inject function information without interfering with the high-speed encrypted data transmission, effectively separating control plane (signaling) from data plane (encrypted traffic).

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Loss of information

If signaling messages are intercepted and modified to add function parameters, then intermediate node capability information is transmitted, but message integrity may be compromised

Engineering Contradiction:
Improvefunction information transmissionVSAvoidmessage integrity
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where endpoints verify the authenticity of signaling messages received from intermediate equipment. This allows function information to be transmitted while maintaining message integrity through verification protocols that detect unauthorized modifications.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3811578B1Method of discovering intermediate functions and selecting a path between two communication devices
Publication Date: 2025.09.17 ORANGE SA
  • EP3811578B1 patent drawingFigure 1A~1B
  • EP3811578B1 patent drawingFigure 2
  • EP3811578B1 patent drawingFigure 3~4

AI summary

The invention relates to a method for carrying out transmission functions hosted by intermediate devices of a path between two communication devices. The end-to-end encryption devices are designed to resist any attempts at surveillance or tampering, since third parties can neither decrypt nor modify the communicated data. A solution is known which, depending on the requests from applications to open connections, makes it possible to select and assemble the transport protocols necessary for the application to function. However, this is a local method: the protocol stack is assembled only at the communication equipment making up the endpoints of the connections. Therefore, the requests emitted by these applications are not transmitted to the intermediate devices hosting the desired functions. The invention makes it possible to restore cooperation between communication devices, constituting the endpoints of a connection, and intermediate nodes hosting transmission functions.