NWDAF DNS-Based Application Detection for Encrypted 5G Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The encryption of user traffic in 5G networks, including DNS traffic, prevents the UPF from identifying application traffic, hindering proper network operation and classification.

Innovation Solution

NWDAF-assisted application detection methods that utilize data from DNS resolvers to derive packet flow descriptions (PFDs) by mapping FQDNs to server IP addresses, enabling classification of encrypted traffic without requiring ASPs to maintain PFDs in NEF repositories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DNS traffic is encrypted to enhance security, then security is improved, but application detection capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidapplication detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary mechanism where the network retrieves FQDN information from DNS resolver logs as intermediate data. This intermediary approach allows the system to obtain application identification information without decrypting the actual DNS traffic, thus maintaining security while enabling detection through a third-party data source.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts only the necessary FQDN information from DNS resolver logs rather than processing or decrypting the entire encrypted DNS traffic. By taking out only the specific data element (FQDN) needed for application detection, the system achieves detection capability while preserving the encryption and security of the original DNS communications.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If FQDN-based detection is implemented instead of IP address-based PFDs, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent creates a simplified copy of the detection mechanism by using FQDN information from DNS logs instead of complex IP address-based PFDs. This copying approach replaces the need for ASPs to maintain complex PFD repositories with a simpler system that leverages existing DNS resolver data, reducing operational complexity while maintaining detection effectiveness.

Inventive Principle:
Principle #26Copying

3Measurement precision

If ASPs maintain PFDs in NEF repositories, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improvemeasurement precisionVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent enables the network to serve itself by automatically retrieving FQDN information from DNS resolver logs without requiring external ASP intervention. This self-service mechanism eliminates the need for ASPs to maintain PFDs in NEF repositories, reducing device complexity while the system maintains measurement precision through automated FQDN-based application identification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260075030A1Nwdaf-assisted application detection based on domain name service (DNS)
Publication Date: 2026.03.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20260075030A1 patent drawing
  • US20260075030A1 patent drawing
  • US20260075030A1 patent drawing

AI summary

Embodiments include methods for a network data analytics function (NWDAF) configured to assist with application detection in a communication network. Such methods include receiving, from a consumer network function (cNF) of the communication network, an analytic request related to assisted application detection and based on the analytic request, sending to a first DNS resolver associated with the communication network an exposure request for events related to fully qualified domain name (FQDN)-to-address mapping for application servers associated with applications. Such methods also include receiving from the first DNS resolver a first FQDN associated with a first application, in accordance with the exposure request, and based on the first FQDN, determining one or more packet flow descriptions (PFDs) associated with the first application. Such methods also include sending to the cNF an analytic result comprising the one or more PFDs, in accordance with the analytic request.