Multi-Tunnel IPSec Packet Transmission for 5G User Plane Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing IPSec protocol is unable to meet the high-flow encryption and decryption processing capabilities required by 5G networks due to limited processing capacity of encryption chips and the use of a single security tunnel for user plane data, which results in difficulty in handling diverse service types.
Innovation Solution
Implementing a method that extends the IPSec standard protocol by using negotiation attribute information, such as DSCP, UE IP, or TEID, to establish multiple security tunnels based on service characteristics, allowing for differentiated packet handling and improved processing capacity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If user plane data are carried in the same IPSec security tunnel, then the network structure is simple and easy to manage, but the encryption chip processing capacity is insufficient to meet 5G high-flow service requirements
Solution Approach 1:
The patent segments user plane data into multiple IPSec security tunnels based on different service types and QoS requirements. By dividing the single tunnel into multiple tunnels with different security attributes (SA parameters), the system can distribute encryption processing across multiple channels, thereby increasing overall encryption processing capacity while maintaining manageable network structure through systematic organization.
Solution Approach 2:
The patent introduces a new dimension for tunnel selection by extending the traditional five-tuple matching to include negotiation attribute information. This dimensional expansion allows packets to be routed through different security tunnels based on service characteristics beyond basic addressing, enabling differentiated encryption processing without significantly complicating the underlying network structure.
2Ease of operation
If a single IPSec security tunnel is used for all user plane data, then the configuration is simple, but it cannot handle diverse service types with different encryption requirements
Solution Approach 1:
The patent creates multiple IPSec security tunnels, each configured with specific security attributes and negotiation parameters. These tunnels serve different service types with varying encryption requirements, allowing the system to universally handle diverse services through a standardized multi-tunnel framework. Each tunnel maintains its own configuration simplicity while the collective system achieves high service adaptability.
Solution Approach 2:
The patent applies local quality by configuring different security attributes and negotiation parameters for different tunnels based on their specific service requirements. Each tunnel is optimized locally for its intended service type, allowing differentiated handling of various service characteristics while maintaining overall system coherence through the extended five-tuple matching mechanism.
3Productivity
If multiple security tunnels are established based on negotiation attribute information, then the processing capacity for diverse services is improved, but the protocol complexity increases
Solution Approach 1:
The patent performs preliminary action by establishing multiple IPSec security tunnels with pre-configured security attributes and negotiation parameters before actual data transmission. The extended five-tuple matching rules are pre-defined, allowing packets to be quickly routed through appropriate tunnels without complex real-time decision-making, thereby maintaining high processing capacity while managing protocol complexity through advance preparation.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
Disclosed by the embodiments of the present invention are a transmission method and device and a message transmitting terminal and receiving terminal, said transmission method comprising: the message transmitting terminal using 5-tuple information and negotiation attribute information to negotiate with the message receiving terminal to determine an Internet protocol security (IPSec) security tunnel; said message transmitting terminal sending a message to the message receiving terminal by means of said IPSec security tunnel.