Multi-Tunnel IPSec Packet Transmission for 5G User Plane Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IPSec protocol is unable to meet the high-flow encryption and decryption processing capabilities required by 5G networks due to limited processing capacity of encryption chips and the use of a single security tunnel for user plane data, which results in difficulty in handling diverse service types.

Innovation Solution

Implementing a method that extends the IPSec standard protocol by using negotiation attribute information, such as DSCP, UE IP, or TEID, to establish multiple security tunnels based on service characteristics, allowing for differentiated packet handling and improved processing capacity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If user plane data are carried in the same IPSec security tunnel, then the network structure is simple and easy to manage, but the encryption chip processing capacity is insufficient to meet 5G high-flow service requirements

Engineering Contradiction:
Improvenetwork structure complexityVSAvoidencryption processing capacity
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent segments user plane data into multiple IPSec security tunnels based on different service types and QoS requirements. By dividing the single tunnel into multiple tunnels with different security attributes (SA parameters), the system can distribute encryption processing across multiple channels, thereby increasing overall encryption processing capacity while maintaining manageable network structure through systematic organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension for tunnel selection by extending the traditional five-tuple matching to include negotiation attribute information. This dimensional expansion allows packets to be routed through different security tunnels based on service characteristics beyond basic addressing, enabling differentiated encryption processing without significantly complicating the underlying network structure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If a single IPSec security tunnel is used for all user plane data, then the configuration is simple, but it cannot handle diverse service types with different encryption requirements

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidservice type adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates multiple IPSec security tunnels, each configured with specific security attributes and negotiation parameters. These tunnels serve different service types with varying encryption requirements, allowing the system to universally handle diverse services through a standardized multi-tunnel framework. Each tunnel maintains its own configuration simplicity while the collective system achieves high service adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent applies local quality by configuring different security attributes and negotiation parameters for different tunnels based on their specific service requirements. Each tunnel is optimized locally for its intended service type, allowing differentiated handling of various service characteristics while maintaining overall system coherence through the extended five-tuple matching mechanism.

Inventive Principle:
Principle #3Local quality

3Productivity

If multiple security tunnels are established based on negotiation attribute information, then the processing capacity for diverse services is improved, but the protocol complexity increases

Engineering Contradiction:
Improvepacket processing capacityVSAvoidprotocol complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent performs preliminary action by establishing multiple IPSec security tunnels with pre-configured security attributes and negotiation parameters before actual data transmission. The extended five-tuple matching rules are pre-defined, allowing packets to be quickly routed through appropriate tunnels without complex real-time decision-making, thereby maintaining high processing capacity while managing protocol complexity through advance preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3866427B1Transmission method and device, packet transmitting terminal and receiving terminal
Publication Date: 2026.01.28 ZTE CORP
  • EP3866427B1 patent drawingFigure 1~2
  • EP3866427B1 patent drawingFigure 3
  • EP3866427B1 patent drawingFigure 4~5

AI summary

Disclosed by the embodiments of the present invention are a transmission method and device and a message transmitting terminal and receiving terminal, said transmission method comprising: the message transmitting terminal using 5-tuple information and negotiation attribute information to negotiate with the message receiving terminal to determine an Internet protocol security (IPSec) security tunnel; said message transmitting terminal sending a message to the message receiving terminal by means of said IPSec security tunnel.