Encrypted Traffic Detection via PDU Session Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End-to-end encryption in wireless communication systems hinders mobile network operators' ability to accurately detect traffic types, making it difficult to apply service-specific policies, such as differential charging for video streaming traffic, as deep packet inspection methods are unreliable and increasingly challenged by stronger security protocols like TLS 1.3.

Innovation Solution

The method involves a user equipment (UE) and network functions that establish a PDU session, where the UE modifies data packets with encrypted traffic detection information, using unique signatures to identify applications and transmit this information to the network, enabling accurate detection of encrypted traffic flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If end-to-end encryption is implemented to protect communication privacy, then security and privacy are improved, but traffic type detection accuracy deteriorates

Engineering Contradiction:
Improvecommunication privacy protectionVSAvoidtraffic type detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by having the UE calculate and embed encrypted traffic detection information (ETDI) into data packets before transmission. The ETDI is prepared in advance using the UE's signature and application identifiers, allowing the network to detect traffic types without decrypting the actual payload. This resolves the contradiction by maintaining encryption while enabling detection through pre-prepared metadata.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism where the UE acts as a mediator between the encrypted traffic and the network detection system. The UE embeds ETDI that contains application identifiers and detection information, which the network can use to identify traffic types without accessing the encrypted payload. This intermediary approach allows both encryption to remain intact and detection to function accurately.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If deep packet inspection is used to detect encrypted traffic, then traffic type detection capability is improved, but reliability and accuracy deteriorate due to encryption protocols like TLS 1.3

Engineering Contradiction:
Improveencrypted traffic detection capabilityVSAvoiddetection accuracy
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent applies the extraction principle by separating detection information from the encrypted payload. Instead of attempting to inspect the encrypted data itself, the system extracts and uses ETDI that the UE embeds in the packets. This ETDI contains application identifiers and other detection-relevant information that is not encrypted, allowing reliable detection without compromising security or being blocked by strong encryption protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If service-specific policies are applied to encrypted traffic, then network operator control and charging accuracy are improved, but implementation difficulty increases due to inability to identify traffic types

Engineering Contradiction:
Improveservice-specific policy applicationVSAvoidpolicy implementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements feedback by having the UE provide ETDI back to the network with each data packet. The network uses this feedback information (application identifiers, detection information) to automatically apply appropriate service-specific policies and charging rules. This feedback mechanism simplifies policy implementation by providing the network with the information it needs to make automated decisions, reducing complexity despite increased adaptability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12010562B2PDU session for encrypted traffic detection
Publication Date: 2024.06.11 LENOVO (SINGAPORE) PTE LTD
  • US12010562B2 patent drawing
  • US12010562B2 patent drawing
  • US12010562B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for PDU Session Establishment for encrypted traffic detection. One apparatus includes a transceiver and a processor The processor transmits a request to establish a PDU session with a mobile communication network. Moreover, the processor receives a PDU session establishment response from the mobile communication network. Here, the response includes a list of one or more application identifiers for which detection information is to be provided. Accordingly, the processor calculates detection information for each application identifier. The processor modifies a data packet from first application associated with the start of an encrypted data flow to include the detection information of the first application. Additionally, the processor controls the transceiver to transmit the modified data packet to the mobile communication network.