Policy Node Filtering Encrypted Traffic Granularity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current content filtering solutions in 3GPP networks lack granularity, especially with encrypted traffic, and do not support dynamic updates or interactions between Network Service Providers (NSPs) and Application Service Providers (ASPs/OTTs for parental control, leading to inadequate control over content access by end users.
Innovation Solution
A method involving a policy node, application node, and storage node that exchanges application content information including adaptability and notification indicators to enable flexible content filtering, allowing NSPs and ASPs/OTTs to collaborate in controlling access to content based on user-defined categories and preferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If current content filtering solutions are used in 3GPP networks, then basic traffic filtering is possible, but filtering granularity is insufficient especially with encrypted traffic
Solution Approach 1:
The patent introduces an application node as an intermediary between the network and applications. This node receives application content information from applications and forwards it to the network, enabling the network to filter encrypted traffic without decrypting it. The intermediary facilitates cooperation between network operators and application providers to achieve fine-grained filtering of encrypted content.
Solution Approach 2:
The patent implements a feedback mechanism where application nodes send application content information (including content categories) back to the network. This feedback loop enables the network to make informed filtering decisions about encrypted traffic based on actual application content metadata, thereby improving filtering granularity while maintaining encrypted traffic handling capability.
2Adaptability or versatility
If traditional filtering mechanisms are used, then simple content blocking is achieved, but dynamic updates and NSP-ASP interaction are not supported
Solution Approach 1:
The patent segments the filtering system into distinct functional nodes: network service providers (NSPs), application service providers (ASPs), application nodes, and policy nodes. Each segment has specific responsibilities - ASPs provide content information, application nodes collect and forward this information, policy nodes process filtering rules, and NSPs enforce filtering. This segmentation enables dynamic updates and interactions while keeping each component relatively simple.
Solution Approach 2:
The application node serves multiple functions: it collects application content information, identifies applications, determines content categories, and communicates with both the network and applications. This multi-functional design enables dynamic updates and NSP-ASP interaction without requiring separate specialized components for each function, thereby managing complexity.
3Ease of operation
If parental control is implemented without application content information, then basic access restriction is possible, but adequate control over content access cannot be achieved
Solution Approach 1:
The patent implements preliminary action by collecting application content information (including content categories) before actual content delivery occurs. The application node receives this information from applications and stores it for later use in filtering decisions. This advance preparation enables adequate parental control over content access without losing important content category information.
Data Source
AI summary
Methods, a policy node, an application node, a storage node and an operator network for enabling filtering of traffic from an application hosted by the application node are disclosed. The policy node receives, from the application node, application content information relating to the filtering of the traffic and an identifier of the application to which the application content information applies, wherein the application content information comprises an indication relating to application content category of the traffic, and wherein the application content information comprises one or more of an adaptability indicator specifying whether the application is able to adapt the traffic to a given user content category, and a notification indicator specifying whether the application is able to notify, to the policy node, an application content category before providing requested traffic. The policy node further transmits, by the policy node to the storage node, the application content information.


