Multiplexing Multiple Protocol Streams Over Single TLS Session

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems face challenges in securely transmitting data streams across various communication protocol layers, particularly in negotiating and multiplexing protocols efficiently over a single session layer protocol, which affects the reliability and security of data transmission.

Innovation Solution

The implementation of a communication device with a processor and memory configured to support secure communications using a session layer protocol, specifically the Transport Layer Security (TLS) protocol, which enables negotiation and multiplexing of communication protocols across different layers, including data link, network, transport, and application layers, through TLS handshake messages and multiprotocol records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate sessions are used to transmit different data streams across various communication protocol layers, then each data stream can be securely transmitted, but the device complexity and number of sessions required increases

Engineering Contradiction:
Improvesecure transmission of data streamsVSAvoidnumber of sessions
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple separate session layer protocols into a single unified session layer protocol that can handle multiple data streams from different communication protocol layers. This allows secure transmission of multiple data streams (e.g., voice, video, data) over a single session establishment, eliminating the need for multiple separate sessions and reducing device complexity while maintaining security for each stream

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The session layer protocol is designed with universality to support multiple communication protocol layers simultaneously. The protocol can identify and securely transmit different types of data streams (voice, video, data) by examining packet headers, making a single session capable of handling diverse communication needs that previously required multiple specialized sessions

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If protocol negotiation is performed for each data stream separately, then compatibility is ensured, but the time required for setup increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidsetup time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent performs protocol negotiation and capability exchange as a preliminary action during the initial session establishment. Communication devices exchange information about supported communication protocol layers and capabilities before actual data transmission begins. This preliminary negotiation ensures compatibility for multiple data streams while avoiding the need for repeated negotiation for each individual stream, thereby reducing overall setup time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms where communication devices provide information about their supported protocols and capabilities during session setup. This feedback allows the devices to agree on a unified set of protocols for the session, ensuring compatibility across all data streams while establishing the communication path efficiently in one negotiation process rather than multiple separate ones

Inventive Principle:
Principle #23Feedback

3Device complexity

If a single session layer protocol is used to multiplex multiple data streams, then device complexity is reduced, but the difficulty of detecting and measuring different protocol layers increases

Engineering Contradiction:
Improvenumber of sessionsVSAvoidprotocol layer identification
Core Design Contradiction:
Device complexityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies local quality by examining specific local characteristics of data packets to identify their protocol layer. Each packet includes header information with distinctive features that indicate its protocol layer (e.g., voice packets have different header formats than video or data packets). By analyzing these local packet characteristics, the system can reliably identify and route different protocol layers through the unified session without requiring complex global analysis

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses packet header fields as analogs of color changes to distinguish between different protocol layers. Different protocol layers are marked with distinctive header patterns or identifiers that can be easily detected by the session layer protocol. This allows the single session layer protocol to visually distinguish (detect) between voice, video, and data streams through their unique header signatures, making protocol layer identification straightforward despite the multiplexed nature of the session

Inventive Principle:
Principle #32Color changes

Data Source

PatentEP3937457A1Secure communications using secure sessions
Publication Date: 2022.01.12 NOKIA SOLUTIONS & NETWORKS OY
  • EP3937457A1 patent drawingFigure 1
  • EP3937457A1 patent drawingFigure 2
  • EP3937457A1 patent drawingFigure 3

AI summary

Various example embodiments for supporting secure communications via secure sessions in communication systems are presented. Various example embodiments for supporting secure communications via secure sessions in communication systems may be configured to support mechanisms in a session layer protocol which enable communications of any communication protocol at any communication protocol layer to be transported over a session layer session (e.g., tunneling any data link protocol, any network layer protocol, any transport layer protocol, and/or any application layer protocol transparently over the session layer protocol), which enable multiple communications of one or more communication protocols of one or more communication protocol layers to be transported over a single session layer session (e.g., multiplexing two or more data streams of any data link protocol, any network layer protocol, any transport layer protocol, and/or any application layer protocol transparently over the session layer protocol), and so forth.