Encrypted Traffic Detection via PDU Session Signaling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
End-to-end encryption in wireless communication systems hinders mobile network operators' ability to accurately detect traffic types, making it difficult to apply service-specific policies, such as differential charging for video streaming traffic, as deep packet inspection methods are unreliable and increasingly challenged by stronger security protocols like TLS 1.3.
Innovation Solution
The method involves a user equipment (UE) and network functions that establish a PDU session, where the UE modifies data packets with encrypted traffic detection information, using unique signatures to identify applications and transmit this information to the network, enabling accurate detection of encrypted traffic flows.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If end-to-end encryption is implemented to protect communication privacy, then security and privacy are improved, but traffic type detection accuracy deteriorates
Solution Approach 1:
The patent applies preliminary action by having the UE calculate and embed encrypted traffic detection information (ETDI) into data packets before transmission. The ETDI is prepared in advance using the UE's signature and application identifiers, allowing the network to detect traffic types without decrypting the actual payload. This resolves the contradiction by maintaining encryption while enabling detection through pre-prepared metadata.
Solution Approach 2:
The patent introduces an intermediary mechanism where the UE acts as a mediator between the encrypted traffic and the network detection system. The UE embeds ETDI that contains application identifiers and detection information, which the network can use to identify traffic types without accessing the encrypted payload. This intermediary approach allows both encryption to remain intact and detection to function accurately.
2Difficulty of detecting and measuring
If deep packet inspection is used to detect encrypted traffic, then traffic type detection capability is improved, but reliability and accuracy deteriorate due to encryption protocols like TLS 1.3
Solution Approach 1:
The patent applies the extraction principle by separating detection information from the encrypted payload. Instead of attempting to inspect the encrypted data itself, the system extracts and uses ETDI that the UE embeds in the packets. This ETDI contains application identifiers and other detection-relevant information that is not encrypted, allowing reliable detection without compromising security or being blocked by strong encryption protocols.
3Adaptability or versatility
If service-specific policies are applied to encrypted traffic, then network operator control and charging accuracy are improved, but implementation difficulty increases due to inability to identify traffic types
Solution Approach 1:
The patent implements feedback by having the UE provide ETDI back to the network with each data packet. The network uses this feedback information (application identifiers, detection information) to automatically apply appropriate service-specific policies and charging rules. This feedback mechanism simplifies policy implementation by providing the network with the information it needs to make automated decisions, reducing complexity despite increased adaptability.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for PDU Session Establishment for encrypted traffic detection. One apparatus includes a transceiver and a processor The processor transmits a request to establish a PDU session with a mobile communication network. Moreover, the processor receives a PDU session establishment response from the mobile communication network. Here, the response includes a list of one or more application identifiers for which detection information is to be provided. Accordingly, the processor calculates detection information for each application identifier. The processor modifies a data packet from first application associated with the start of an encrypted data flow to include the detection information of the first application. Additionally, the processor controls the transceiver to transmit the modified data packet to the mobile communication network.


