Plaintext Application Metadata for Encrypted Data Awareness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Encrypted Internet data prevents effective identification of service types and content, leading to compromised service experiences, such as inadequate parental control filtering, as encryption renders service-aware systems ineffective.

Innovation Solution

A method where a server transmits application information in plaintext alongside encrypted service data to an awareness node, allowing the node to identify service information, thus enabling service-aware systems to function correctly without requiring additional encryption/decryption protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Internet data is encrypted using TLS protocol, then data security is improved, but service information identification capability deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidservice information identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the data transmission into two parts: encrypted service data for security and separate application information for service identification. The application information is transmitted in plaintext alongside the encrypted data, allowing service-aware systems to identify service types without decrypting the main data payload.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces application information as an intermediary element that carries service identification data between the server and awareness nodes. This intermediary contains service type identifiers and other metadata that enable service-aware processing without requiring decryption of the encrypted service data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If application information is transmitted in plaintext alongside encrypted data, then service awareness capability is improved, but system complexity increases

Engineering Contradiction:
Improveservice awareness capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The application information structure is designed to be universal and multi-functional, serving both service identification and traffic management purposes. The same plaintext information structure supports multiple service-aware applications including parental control, traffic prioritization, and content filtering without requiring application-specific modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If service data is encrypted, then user privacy protection is improved, but parental control filtering effectiveness deteriorates

Engineering Contradiction:
Improveuser privacy protectionVSAvoidparental control filtering effectiveness
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent applies different quality characteristics to different parts of the data transmission: the application information is kept in plaintext with high readability for filtering purposes, while the service data is encrypted with high security. This local differentiation allows parental control systems to effectively filter based on application information without compromising overall data security.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3413533B1Data transmission method and system
Publication Date: 2023.05.10 HUAWEI TECH CO LTD
  • EP3413533B1 patent drawingFigure 1~2
  • EP3413533B1 patent drawingFigure 3
  • EP3413533B1 patent drawingFigure 4

AI summary

Embodiments of the present invention disclose a data transmission method. In a process in which a server sends encrypted service data to a terminal device, the server transmits, to an awareness node, application information needed by the awareness node, so that the awareness node can learn of, based on the application information, service information of the encrypted service data transmitted between the terminal device and the server, and accordingly a service awareness system completes a service related to service content. The application information is transmitted in a plaintext manner, and the server does not need to additionally increase an encryption/decryption protocol stack. Data transmission is more convenient and system costs are lower while it is ensured that the service data between the terminal device and the server is encrypted.