Encrypted Session Packet Capture for QUIC Stream Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communications networks, particularly in the context of vehicular data services like eCall, existing methods struggle to identify and process data streams from multiple applications securely multiplexed over protocols like QUIC, as they are encrypted and lack effective differentiation based on IP addresses, leading to challenges in billing and prioritization of data transmission.
Innovation Solution
A method and device for discriminating and processing data streams by adding attributes and markings to packets, utilizing secure stream multiplexing protocols like QUIC, allowing devices to identify and process packets based on application-specific markings, even in encrypted sessions, and enabling secure collaboration between terminal units and network devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is applied to data streams in protocols like QUIC, then security and confidentiality are improved, but the ability to identify and process specific data streams is worsened
Solution Approach 1:
The patent segments the data stream identification problem by introducing separate identification attributes (application identifier, service identifier) that are distinct from the encrypted payload. These attributes are extracted and processed separately, allowing stream identification without decrypting the main data flow, thus resolving the contradiction between security and identifiability.
Solution Approach 2:
The patent introduces intermediary attributes and markers that act as mediators between the encrypted data and the processing system. These intermediaries carry identification information that can be read without breaking encryption, enabling the network device to identify and prioritize streams while maintaining the security integrity of the encrypted payload.
2Productivity
If multiple data streams are multiplexed in a single connection, then bandwidth efficiency is improved, but the ability to differentiate and process specific streams is worsened
Solution Approach 1:
The patent applies local quality by assigning unique identification attributes to specific data streams within the multiplexed connection. Each stream carries its own application identifier and service identifier, enabling differentiated processing (such as prioritization or billing) for specific streams while maintaining the efficient multiplexed transport structure.
Solution Approach 2:
The patent adds new dimensions of identification (application layer identifiers, service identifiers) beyond the traditional network layer addressing. This dimensional expansion allows fine-grained stream differentiation within the existing multiplexed connection without requiring separate physical or network connections, thus maintaining bandwidth efficiency while enabling precise stream control.
3Ease of manufacture
If IP address-based differentiation is used to distinguish streams, then implementation simplicity is improved, but effectiveness is worsened when multiple applications use the same IP address
Solution Approach 1:
The patent segments the identification function by separating IP address (network layer) from application-specific identifiers (application layer). This segmentation allows the system to first use simple IP-based routing for basic traffic management, then overlay application-specific identifiers for precise stream differentiation, achieving both implementation simplicity and measurement precision.
Solution Approach 2:
The patent creates a universal identification framework where multiple types of identifiers (IP address, application identifier, service identifier) can work together or independently. This multi-functional approach allows the system to adapt to different scenarios: using simple IP addresses when sufficient, or combining with application-specific identifiers when needed, thus maintaining both simplicity and precision.
Data Source
AI summary
A method for counting data relating to an application transmitted by a terminal unit to a data server by a device, using an encrypted session between the terminal unit and the server. The method is implemented by the terminal unit and includes: transmitting a plurality of packets, each including a datum for determining a security key used for encrypting the packet; incrementing a counter of the application-related data; adding the incremented counter to a cooperation packet including the determining datum with a value distinct from a value of the data for determining the security keys of the other packets of the plurality of packets, the value corresponding to a security key used for encrypting packets of the plurality of packets exchanged between the terminal unit and the data server prior to sending the cooperation packet; and sending the cooperation packet including the added counter to the data server.


