Policy Node Filtering Encrypted Traffic Granularity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content filtering solutions in 3GPP networks lack granularity, especially with encrypted traffic, and do not support dynamic updates or interactions between Network Service Providers (NSPs) and Application Service Providers (ASPs/OTTs for parental control, leading to inadequate control over content access by end users.

Innovation Solution

A method involving a policy node, application node, and storage node that exchanges application content information including adaptability and notification indicators to enable flexible content filtering, allowing NSPs and ASPs/OTTs to collaborate in controlling access to content based on user-defined categories and preferences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If current content filtering solutions are used in 3GPP networks, then basic traffic filtering is possible, but filtering granularity is insufficient especially with encrypted traffic

Engineering Contradiction:
Improvefiltering granularityVSAvoidencrypted traffic handling
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces an application node as an intermediary between the network and applications. This node receives application content information from applications and forwards it to the network, enabling the network to filter encrypted traffic without decrypting it. The intermediary facilitates cooperation between network operators and application providers to achieve fine-grained filtering of encrypted content.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where application nodes send application content information (including content categories) back to the network. This feedback loop enables the network to make informed filtering decisions about encrypted traffic based on actual application content metadata, thereby improving filtering granularity while maintaining encrypted traffic handling capability.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If traditional filtering mechanisms are used, then simple content blocking is achieved, but dynamic updates and NSP-ASP interaction are not supported

Engineering Contradiction:
Improvedynamic updates and interactionVSAvoidfiltering system architecture
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the filtering system into distinct functional nodes: network service providers (NSPs), application service providers (ASPs), application nodes, and policy nodes. Each segment has specific responsibilities - ASPs provide content information, application nodes collect and forward this information, policy nodes process filtering rules, and NSPs enforce filtering. This segmentation enables dynamic updates and interactions while keeping each component relatively simple.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The application node serves multiple functions: it collects application content information, identifies applications, determines content categories, and communicates with both the network and applications. This multi-functional design enables dynamic updates and NSP-ASP interaction without requiring separate specialized components for each function, thereby managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If parental control is implemented without application content information, then basic access restriction is possible, but adequate control over content access cannot be achieved

Engineering Contradiction:
Improvecontent access controlVSAvoidapplication content category information
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements preliminary action by collecting application content information (including content categories) before actual content delivery occurs. The application node receives this information from applications and stores it for later use in filtering decisions. This advance preparation enables adequate parental control over content access without losing important content category information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11463364B2Methods, nodes and operator network for enabling filtering of traffic from an application
Publication Date: 2022.10.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11463364B2 patent drawing
  • US11463364B2 patent drawing
  • US11463364B2 patent drawing

AI summary

Methods, a policy node, an application node, a storage node and an operator network for enabling filtering of traffic from an application hosted by the application node are disclosed. The policy node receives, from the application node, application content information relating to the filtering of the traffic and an identifier of the application to which the application content information applies, wherein the application content information comprises an indication relating to application content category of the traffic, and wherein the application content information comprises one or more of an adaptability indicator specifying whether the application is able to adapt the traffic to a given user content category, and a notification indicator specifying whether the application is able to notify, to the policy node, an application content category before providing requested traffic. The policy node further transmits, by the policy node to the storage node, the application content information.