Encrypted Traffic Decryption via Intermediary Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods in mobile networks cannot simultaneously provide privacy and security for encrypted traffic while allowing operators to perform traffic management actions such as redirection and content enrichment, as encryption hinders visibility needed for these operations.

Innovation Solution

A method where a first node receives keys and indications from a second node, enabling decryption by a third node within the communications system, allowing traffic management operations to be performed on encrypted traffic between endpoints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic is encrypted between endpoints to provide privacy and security, then confidentiality of data is improved, but visibility of traffic is worsened making management operations impossible

Engineering Contradiction:
Improveprivacy and securityVSAvoidtraffic visibility
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a key management function as an intermediary between endpoints and network management nodes. This function enables controlled decryption of encrypted traffic at specific network points, allowing management operations to be performed on decrypted traffic while the original encrypted traffic continues to flow between endpoints. The intermediary maintains the security benefits of encryption while enabling necessary visibility for traffic management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If decryption is enabled at network nodes to allow traffic management operations, then operational control is improved, but security of encrypted traffic is worsened

Engineering Contradiction:
Improvetraffic management controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements local quality by enabling decryption only at specific network nodes where management operations are required, rather than system-wide decryption. The key management function distributes decryption capabilities selectively to authorized nodes, allowing each node to decrypt traffic only when and where management operations are needed, while other portions of the network maintain encrypted traffic flow for security.

Inventive Principle:
Principle #3Local quality

3Reliability

If encryption protocols are used between endpoints, then data confidentiality is improved, but compatibility with existing traffic management systems is worsened

Engineering Contradiction:
Improvedata confidentialityVSAvoidcompatibility with traffic management systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key management function serves as an intermediary layer between modern encrypted traffic and legacy traffic management systems. It receives encrypted traffic, decrypts it using keys obtained from the key management function, allows management operations to be performed on the decrypted traffic, and then re-encrypts it before forwarding. This intermediary approach maintains compatibility with existing traffic management infrastructure while preserving end-to-end encryption benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240073680A1First Node, Second Node, Third Node and Methods Performed Thereby, for Handling Encrypted Traffic in a Communications Network
Publication Date: 2024.02.29 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240073680A1 patent drawing
  • US20240073680A1 patent drawing
  • US20240073680A1 patent drawing

AI summary

A computer-implemented method, performed by a first node (111). The method is for handling encrypted traffic in a communications system (100). The first node (111) receives (304), from a second node (112) one or more keys to enable decryption by a third node (113) of traffic. The traffic is routed between two or more endpoints (130, 120) and is encrypted between the endpoints (130, 120) The first node (111) also receives (304) the one or more indications. The one or more indications indicate a respective protocol to be used with the one or more keys to enable decryption of the traffic. The first node (111) also initiates (305) sending the one or more keys and the one or more indications to the third node (113), thereby enabling decryption of the traffic. The first node (111) and the third node (113) are different from any of the two or more endpoints (130, 120).