Coordinated Encrypted Session Packet Delivery via Metadata Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service chaining and middle-box technologies are ineffective in handling encrypted traffic, limiting operators' ability to inspect and manage network traffic, which affects user experience and service plan creation due to the increasing use of SSL encryption.

Innovation Solution

A mechanism that enables coordinated policy enforcement between network operators and application service providers by negotiating a network and application-friendly policy, allowing the exchange of application flow metadata through a designated entity, such as RACS, to support middle-box functions and maintain user privacy, even for encrypted traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSL encryption is used to protect user data, then security and privacy are improved, but the ability to inspect and manage network traffic deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic inspection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the encrypted traffic handling into two parts: the encrypted data payload remains encrypted for security, while the metadata (flow identification information) is extracted and made available separately for inspection and management purposes

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a metadata exchange mechanism as an intermediary between the encrypted traffic flow and the network management functions, allowing middle-boxes to obtain flow identification information without decrypting the actual traffic content

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If deep packet inspection is used to analyze network traffic, then traffic management capability is improved, but compatibility with encrypted traffic deteriorates

Engineering Contradiction:
Improvetraffic management capabilityVSAvoidencrypted traffic compatibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent extracts flow identification information from encrypted traffic flows and makes it available to middle-boxes through a metadata exchange mechanism, allowing traffic management without requiring deep packet inspection of encrypted content

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical deep packet inspection approach with a metadata-based identification system that works with encrypted traffic by exchanging flow identification information through designated entities

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If service chaining is implemented to provide multiple middle-box functions, then network service capability is improved, but coordination between encrypted traffic and middle-boxes deteriorates

Engineering Contradiction:
Improvenetwork service capabilityVSAvoidcoordination between ASP and operator
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal metadata exchange mechanism that can be used across different middle-box functions and service chaining scenarios, providing a common interface for flow identification information exchange between operators and application service providers

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent establishes a feedback loop where flow identification information is exchanged between operators and ASPs, enabling coordinated policy enforcement and dynamic service plan creation based on actual traffic patterns

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3235168B1Coordinated packet delivery of encrypted session
Publication Date: 2020.07.01 NOKIA SOLUTIONS & NETWORKS OY
  • EP3235168B1 patent drawingFigure 1
  • EP3235168B1 patent drawingFigure 2
  • EP3235168B1 patent drawingFigure 3

AI summary

Various communication systems may benefit from appropriate handling of secure data. More specifically, certain packet-based communication systems may benefit from a mechanism to support coordinated packet delivery of one or more encrypted sessions. A method can include identifying metadata for an application flow, wherein the application flow is encrypted. The method can also include publishing the metadata in a core network, wherein the metadata is unencrypted when published.