Encrypted Session Packet Capture for QUIC Stream Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communications networks, particularly in the context of vehicular data services like eCall, existing methods struggle to identify and process data streams from multiple applications securely multiplexed over protocols like QUIC, as they are encrypted and lack effective differentiation based on IP addresses, leading to challenges in billing and prioritization of data transmission.

Innovation Solution

A method and device for discriminating and processing data streams by adding attributes and markings to packets, utilizing secure stream multiplexing protocols like QUIC, allowing devices to identify and process packets based on application-specific markings, even in encrypted sessions, and enabling secure collaboration between terminal units and network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is applied to data streams in protocols like QUIC, then security and confidentiality are improved, but the ability to identify and process specific data streams is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddata stream identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the data stream identification problem by introducing separate identification attributes (application identifier, service identifier) that are distinct from the encrypted payload. These attributes are extracted and processed separately, allowing stream identification without decrypting the main data flow, thus resolving the contradiction between security and identifiability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary attributes and markers that act as mediators between the encrypted data and the processing system. These intermediaries carry identification information that can be read without breaking encryption, enabling the network device to identify and prioritize streams while maintaining the security integrity of the encrypted payload.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple data streams are multiplexed in a single connection, then bandwidth efficiency is improved, but the ability to differentiate and process specific streams is worsened

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidstream differentiation
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies local quality by assigning unique identification attributes to specific data streams within the multiplexed connection. Each stream carries its own application identifier and service identifier, enabling differentiated processing (such as prioritization or billing) for specific streams while maintaining the efficient multiplexed transport structure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent adds new dimensions of identification (application layer identifiers, service identifiers) beyond the traditional network layer addressing. This dimensional expansion allows fine-grained stream differentiation within the existing multiplexed connection without requiring separate physical or network connections, thus maintaining bandwidth efficiency while enabling precise stream control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of manufacture

If IP address-based differentiation is used to distinguish streams, then implementation simplicity is improved, but effectiveness is worsened when multiple applications use the same IP address

Engineering Contradiction:
Improveimplementation simplicityVSAvoidstream distinction accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent segments the identification function by separating IP address (network layer) from application-specific identifiers (application layer). This segmentation allows the system to first use simple IP-based routing for basic traffic management, then overlay application-specific identifiers for precise stream differentiation, achieving both implementation simplicity and measurement precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal identification framework where multiple types of identifiers (IP address, application identifier, service identifier) can work together or independently. This multi-functional approach allows the system to adapt to different scenarios: using simple IP addresses when sufficient, or combining with application-specific identifiers when needed, thus maintaining both simplicity and precision.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250240279A1Method For Capturing A Packet From An Encrypted Session
Publication Date: 2025.07.24 ORANGE SA
  • US20250240279A1 patent drawing
  • US20250240279A1 patent drawing
  • US20250240279A1 patent drawing

AI summary

A method for counting data relating to an application transmitted by a terminal unit to a data server by a device, using an encrypted session between the terminal unit and the server. The method is implemented by the terminal unit and includes: transmitting a plurality of packets, each including a datum for determining a security key used for encrypting the packet; incrementing a counter of the application-related data; adding the incremented counter to a cooperation packet including the determining datum with a value distinct from a value of the data for determining the security keys of the other packets of the plurality of packets, the value corresponding to a security key used for encrypting packets of the plurality of packets exchanged between the terminal unit and the data server prior to sending the cooperation packet; and sending the cooperation packet including the added counter to the data server.