Encrypting Application Metadata in 5G Transport Packets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems in next-generation networks face challenges in securely conveying application metadata to on-path network elements, which is essential for ensuring security and privacy in 5G mobile networks.
Innovation Solution
The proposed solution involves establishing an application session between user equipment (UE) and an application service through an Application Function (AF) of a 5G core network. Pre-shared keying material is distributed to on-path network elements, allowing them to encrypt and decrypt application metadata within transport protocol packets, such as UDP packets, ensuring secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application metadata is transmitted in clear text to on-path network elements, then the network elements can access and process the metadata, but the security and privacy of the application session is compromised
Solution Approach 1:
The patent introduces an intermediary encryption mechanism using pre-shared keying material distributed to on-path network elements. This intermediary layer (encryption/decryption process) enables secure transmission by transforming clear text metadata into encrypted form, allowing only authorized network elements with the correct keying material to access the metadata, thus resolving the contradiction between security and accessibility
Solution Approach 2:
The patent applies local quality by distributing keying material selectively to specific on-path network elements that require access to application metadata. Each network element receives the necessary cryptographic credentials locally, enabling them to decrypt and process metadata while maintaining security for elements that do not require access
2Reliability
If encryption is implemented for application metadata, then security is enhanced, but the complexity of the communication system increases
Solution Approach 1:
The patent applies preliminary action by distributing pre-shared keying material to on-path network elements in advance, before actual application metadata transmission occurs. This preliminary setup of cryptographic credentials simplifies the ongoing encryption/decryption process, as the keying material is already in place and does not need to be dynamically negotiated for each metadata exchange
Solution Approach 2:
The encryption mechanism is designed to be self-service, where each on-path network element independently possesses the necessary keying material to decrypt metadata without requiring real-time interaction with the transmitting entity. This self-service approach reduces system complexity by eliminating the need for complex key management infrastructure and real-time cryptographic negotiations
Data Source
AI summary
Systems and methods of sending application metadata to on-path network elements. In an embodiment, a method comprises establishing an application session between an application client (1006) running on user equipment (106) and an application service (1010), identifying application metadata (1810) associated with the application session, formatting a transport protocol packet (1802) with the application metadata, deriving an encryption key (1816) based on keying material (1812), encrypting the application metadata in the transport protocol packet using the encryption key, and sending the transport protocol packet over a user plane network path (1024) comprising one or more on-path network elements (1104).


