CUPS Header Enrichment for HTTPS Without User Plane Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Control and User Plane Separation (CUPS) architectures in mobile communication technologies do not support header enrichment for Hypertext Transfer Protocol Secure (HTTPS), as the user plane function cannot decrypt Secure Sockets Layer (SSL)/Transport Layer Security (TLS) packets to insert mobile user information into HTTP headers.
Innovation Solution
Enhancements to the CP and UP functions in CUPS architectures to support header enrichment for HTTPS by providing specific instructions and information during PFCP session establishment, allowing the UP function to identify and insert headers into SSL/TLS packets using TLS/HTTPS indications and additional extensions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the user plane function attempts to insert mobile user information into HTTP headers, then header enrichment capability is improved, but the system cannot process SSL/TLS encrypted packets without decryption capability
Solution Approach 1:
The patent introduces a control plane function as an intermediary that extracts header enrichment information from SSL/TLS packets and forwards it to the user plane function. This mediator enables the user plane to enrich headers without needing to decrypt the encrypted traffic, resolving the contradiction between maintaining encryption reliability and achieving header enrichment capability.
Solution Approach 2:
The patent segments the packet processing function into two parts: the control plane handles decryption and extraction of header information from SSL/TLS packets, while the user plane handles the actual header enrichment based on information provided by the control plane. This segmentation allows each component to operate within its capability boundaries while achieving the overall goal.
2Adaptability or versatility
If SSL/TLS packets are decrypted to enable header insertion, then header enrichment is achieved, but security and confidentiality are compromised
Solution Approach 1:
The control plane function acts as a secure intermediary that temporarily handles decryption only when necessary, extracts the minimal required header information, and then discards the decrypted content. The user plane never receives or processes the actual encrypted payload, maintaining security while enabling header enrichment.
Solution Approach 2:
The patent performs header enrichment actions at the earliest possible point in the packet processing chain, before the encrypted data is fully decrypted or forwarded. This preliminary action allows header insertion to occur with minimal exposure of encrypted content, reducing security risks.
3Reliability
If the control plane processes all packet decryption and header extraction, then security is maintained, but processing speed and user plane efficiency decrease
Solution Approach 1:
The patent segments processing tasks by complexity: the control plane handles the computationally intensive decryption and header extraction only for control plane packets, while the user plane handles the simpler task of inserting headers into user data packets based on pre-processed information. This segmentation balances security requirements with processing efficiency.
Solution Approach 2:
The control plane performs preliminary processing of encryption/decryption operations and extracts header enrichment information in advance, storing this information for subsequent user plane operations. This preliminary action reduces the real-time processing burden on both planes, improving overall throughput.
Data Source
AI summary
Methods, apparatus, and systems for enhancing the CP Function and UP Function to support the header enrichment for HTTPS are disclosed. In one example aspect, the method includes transmitting, by a first communication component, to a second communication component, a session message instructing the second communication component to detect one or more messages from a user device based on a communication security protocol, wherein the session message includes detection information for the communication security protocol.


