IPsec QoS Flow Handling with DSCP-Based SLA Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems lack the ability to authorize user equipment (UE)-initiated quality of service (QoS) modifications when accessing a stand-alone non-public network (SNPN) via a public land mobile network (PLMN), as the requested QoS rules are not supported by a service level agreement (SLA), leading to uncertainty in resource allocation.

Innovation Solution

Introduce a differentiated services code point (DSCP) value on the IPsec SA to facilitate authorization based on a SLA, ensuring that QoS requests from UE are validated and resources are allocated accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If UE initiates QoS modification in SNPN via PLMN, then QoS customization is enabled, but authorization capability is lost due to lack of SLA support

Engineering Contradiction:
ImproveQoS customization capabilityVSAvoidAuthorization capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces DSCP (Differentiated Services Code Point) as an intermediary mechanism that bridges the UE's QoS requests with the PLMN's SLA framework. The DSCP value acts as a mediator that carries QoS information through the IPsec SA, enabling both UE-initiated customization and PLMN authorization without requiring direct SLA modification in the SNPN.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter space by introducing DSCP marking in the IPsec SA header. This parameter change enables the PLMN to recognize and process UE QoS requests using existing SLA frameworks, transforming the authorization mechanism from unavailable to functional while maintaining UE-initiated customization capability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dedicated IPsec SA is created for QoS flow, then QoS support is enabled, but network complexity increases

Engineering Contradiction:
ImproveQoS supportVSAvoidNetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the IPsec SA multi-functional by using it not only for security but also for QoS differentiation through DSCP marking. This universal approach allows the same IPsec SA to serve both security and QoS purposes, avoiding the need for separate QoS handling mechanisms and reducing overall network complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the QoS differentiation function with the existing IPsec SA structure. By combining security association and QoS flow handling into a single IPsec SA with DSCP marking, the patent eliminates the need for separate QoS processing mechanisms, thereby reducing network complexity while maintaining reliable QoS support.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12538184B2Communication device initiated quality of service with service level agreement for supporting quality of service modification
Publication Date: 2026.01.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12538184B2 patent drawing
  • US12538184B2 patent drawing
  • US12538184B2 patent drawing

AI summary

A method performed by a first network node in a first network is provided for support in a second network of a quality of service, QoS, of the first network for a communication device initiated QoS modification. The method includes checking a QoS profile for a QoS flow of the first network based on a service level agreement, SLA, between the first network and the second network to determine whether the QoS flow is supported by the second network. The method further includes creating a dedicated internet protocol security, IPsec, security association, SA, for handling the QoS flow; and setting a differentiated services code point, DSCP, value of the dedicated IPsec SA according to the SLA. Methods performed by a second network node and by a communication device are also provided.