Prioritizing Encrypted Traffic via Packet Size Criteria

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Standard access points in communications networks, such as those used in UMA and 3GPP specifications, lack quality-of-service (QoS) mechanisms to differentiate and prioritize encrypted traffic types like voice, signaling, and GPRS data, as they can only rely on information in the unencrypted outer IP header, which may be unreliable.

Innovation Solution

Prioritizing encrypted packets based on size criteria, where packets shorter than a specific length are given higher priority, allowing intermediate nodes to differentiate and prioritize voice traffic without relying on potentially unreliable DiffServ/TC/ToS bits, and enabling dynamic detection of packet size for further prioritization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard APs are used with IPsec encryption, then security is improved, but QoS differentiation capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidQoS differentiation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the packet header into two parts: the encrypted inner header (containing payload information) and the unencrypted outer header (containing QoS marking fields). This segmentation allows the outer header to carry visible QoS markings while the inner header remains encrypted for security, resolving the contradiction between security and QoS differentiation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The outer IP header acts as an intermediary that carries QoS markings (DiffServ, TC, or ToS bits) visible to the AP, while the actual payload remains encrypted in the inner header. This intermediary structure enables QoS differentiation without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If DiffServ/TC/ToS bits are used for prioritization, then traffic differentiation is improved, but reliability deteriorates due to potential modification or non-recognition

Engineering Contradiction:
Improvetraffic differentiationVSAvoidprioritization accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies QoS markings (DiffServ/TC/ToS bits) in the outer header at the source (UNC/GANC) before encryption, establishing a preliminary classification that the AP can reliably use for prioritization without needing to trust or interpret potentially modified inner header information.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the location of QoS markings from the inner header to the outer header, making them visible and reliable for AP-based prioritization while maintaining security through encryption of the inner header.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If AP performs deep packet inspection to identify traffic types, then QoS prioritization is improved, but device complexity increases

Engineering Contradiction:
ImproveQoS prioritization accuracyVSAvoidAP processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the QoS marking information from the encrypted inner header and places it in the unencrypted outer header, allowing the AP to perform simple header-based prioritization without complex deep packet inspection or decryption capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7506156B2Method and apparatus for prioritizing encrypted traffic at an intermediate node in a communications network
Publication Date: 2009.03.17 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7506156B2 patent drawing
  • US7506156B2 patent drawing
  • US7506156B2 patent drawing

AI summary

The present invention provides a method and apparatus for prioritizing encrypted traffic at an intermediate node within a communications network. The present invention provides a method and an intermediate node that prioritizes the processing of a packet based on one or more size-based criteria, the packet comprising one or more headers and an encrypted payload. The one or more size-based criteria are satisfied whenever a size of the received packet is equal to a packet size limit, the size of the received packet is less than or equal to the packet size limit, the size of the received packet is less than the packet size limit, or the size of the received packet is within a range of the packet size limit.