Network Traffic Segmentation for Shared Security Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic management systems, particularly in 5G transport networks, face inefficiencies due to the resource-intensive requirements of security and encryption protocols like MACsec and IPsec, which are not optimally allocated and can lead to bottlenecks, increased latency, and unnecessary hardware costs, especially in fronthaul links where most traffic does not require such protocols.

Innovation Solution

A mechanism for detecting and separating protocol data units requiring different processing power, such as security-sensitive frames, and transmitting them over different links, while using placeholder frames to maintain synchronization and reduce unnecessary encryption, allowing shared resource allocation across multiple links.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security protocols (MACsec/IPsec) are applied to all traffic in 5G transport networks, then security protection is improved, but processing resource consumption and latency increase significantly

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments traffic into two categories: protected traffic (control plane, management, sensitive user information) and unprotected traffic (data plane). By applying security protocols only to the protected subset rather than all traffic, the system maintains security where needed while significantly reducing processing resource consumption and latency for the majority of data plane traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the traffic flow. Control plane and management traffic receive full MACsec/IPsec protection, while data plane traffic is transmitted without encryption. This localized application of security protocols optimizes the balance between security and performance by matching protection levels to traffic sensitivity requirements.

Inventive Principle:
Principle #3Local quality

2Use of energy by moving object

If security protocols are applied to a subset of traffic, then processing resources are saved, but packet synchronization and ordering between protected and unprotected traffic becomes complex

Engineering Contradiction:
Improveprocessing resource consumptionVSAvoidpacket synchronization complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

The patent introduces a traffic classification and marking mechanism as an intermediary layer between the data plane and security processing. By marking packets with security requirements before transmission, the system enables simple router forwarding decisions without complex real-time synchronization logic, reducing device complexity while maintaining resource efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dedicated MACsec hardware is deployed on each trunk port, then security processing capability is improved, but hardware costs and device complexity increase

Engineering Contradiction:
Improvesecurity processing capabilityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables security processing resources to serve multiple functions and multiple traffic flows. Instead of dedicating MACsec hardware to each trunk port, the system uses centralized or shared security processing units that can dynamically handle security requirements across multiple ports and traffic types, reducing hardware costs and device complexity while maintaining security processing capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If MACsec is applied to fronthaul links, then security protection is improved, but latency increases and synchronization protocol performance is degraded

Engineering Contradiction:
Improvesecurity protectionVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments fronthaul traffic to identify and protect only the small portion containing sensitive control information, while allowing the majority of data plane traffic to flow without encryption. This segmentation maintains security protection for critical fronthaul control signals while minimizing latency impact on the overall fronthaul performance.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12363077B2Network traffic management
Publication Date: 2025.07.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12363077B2 patent drawing
  • US12363077B2 patent drawing
  • US12363077B2 patent drawing

AI summary

There is provided a method comprising: detecting (310) a subset of protocol data units in an original stream of protocol data units to be transmitted over the network, wherein the original stream is associated with a first source port; generating (320) an updated transmitting-side stream of protocol data units based on the original stream, wherein the updated transmitting-side stream excludes the detected subset; merging (330) the subset of protocol data units with a subset of protocol data units associated with a second source port to form a merged stream; transmitting (340) the merged stream, as a first stream, over a first link of the network; transmitting (350) the updated transmitting-side stream associated with the first source port, as a second stream, over a second link; and transmitting (360) an updated transmitting-side stream associated with the second source port, as a third stream, over a third link.