Encryption Segment Identifiers for Encrypted Traffic Flow Handling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks lack effective mechanisms to securely identify and manage encrypted traffic flows, leading to inefficiencies in encryption and decryption processes.

Innovation Solution

The implementation of encryption segments with unique identifiers (SIDs) within communication networks to identify and manage encrypted traffic flows, utilizing encryption algorithms and keys, enabling secure communication protocols like IEEE 802.1AE for Layer 2.5 and Layer 3 traffic flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption segments with unique identifiers are implemented to identify encrypted traffic flows, then network security is improved and redundant encryption is prevented, but device complexity increases due to the need to manage and process encryption segment identifiers across network nodes

Engineering Contradiction:
Improvenetwork securityVSAvoidencryption segment management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides encrypted traffic flows into distinct encryption segments, each identified by a unique encryption segment identifier (ESI). This segmentation allows network nodes to independently identify and process specific encrypted flows without requiring complex global state management, thereby improving security while controlling complexity through modular identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption segment identifier acts as an intermediary element between the encrypted payload and network node processing logic. Rather than requiring nodes to directly interpret complex encryption states, the ESI provides a simplified interface that enables secure flow identification and prevents redundant encryption through straightforward matching operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If encryption segment identifiers are used to uniquely identify encrypted traffic flows, then processing efficiency is improved by preventing double encryption, but the packet structure complexity increases due to additional header fields

Engineering Contradiction:
Improveencryption processing efficiencyVSAvoidpacket structure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts the identification function from the encrypted payload itself by placing an encryption segment identifier in a dedicated field within the packet structure. This separation allows network nodes to identify and process encrypted flows efficiently without requiring complex decryption and re-encryption operations, thereby improving productivity while managing structure complexity through functional separation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The encryption segment identifier is embedded in the packet structure before the packet traverses the network. This preliminary identification enables intermediate nodes to quickly determine whether a packet requires decryption and re-encryption operations, preventing double encryption and improving processing efficiency without requiring complex runtime analysis of packet contents.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If encryption resources are managed per encryption segment, then security is enhanced through precise control of encryption algorithms and keys, but the amount of state information that must be programmed and maintained increases

Engineering Contradiction:
Improveencryption security controlVSAvoidstate information volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent associates encryption resources (algorithms, keys, parameters) with specific encryption segments identified by unique ESIs. This segmentation allows each encrypted traffic flow to be managed independently with its own security parameters, enhancing security control while reducing the overall state information volume by avoiding global state management and enabling independent processing of each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each encryption segment is equipped with its own identifier that enables self-identification and self-management of encryption resources. Network nodes can autonomously determine the appropriate encryption resources to use by matching the ESI with stored segment information, reducing the need for extensive external programming and state maintenance while maintaining precise security control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP4175228B1Encryption segments for security in communication networks
Publication Date: 2026.05.13 NOKIA SOLUTIONS & NETWORKS OY
  • EP4175228B1 patent drawingFigure 1
  • EP4175228B1 patent drawingFigure 2
  • EP4175228B1 patent drawingFigure 3

AI summary

Various example embodiments for supporting security for communications are presented. Various example embodiments for supporting security for communications may be configured to support security for communications within a network based on use of an encryption segment configured to encrypt a traffic flow to form an encrypted traffic flow and an associated encryption segment identifier (SID) configured to uniquely identify various aspects of the encrypted traffic flow within the network. (e.g., identification of the encrypted traffic flow within the network, identification of the encrypting node which encrypts the traffic flow to form the encrypted traffic flow, identification of the encryption segment on the encrypting node which encrypts the traffic flow to form the encrypted traffic flow, identification of encryption resources used by the encryption segment to encrypt the traffic flow to form the encrypted traffic flow (e.g., an encryption algorithm, an encryption key, a security association, or the like), or the like, as well as various combinations thereof).