Proxy Node COPE for Encrypted Traffic QoS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication protocols face challenges in ensuring secure and efficient performance enhancement between client devices and servers, particularly in maintaining lightweight communication while preventing amplification attacks and ensuring proper congestion control, especially in 5G networks where ubiquitous encryption is prevalent.

Innovation Solution

The implementation of a Collaborative Performance Enhancement (COPE) node or function that uses a proxy node to receive encrypted traffic, perform services, and transmit encrypted information to the server, leveraging existing control channels and encryption keys to enhance Quality of Service (QoS) without adding complexity or delay, and ensuring that the proxy node is on-path for both uplink and downlink traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a proxy node is introduced to perform performance enhancement services, then QoS can be improved, but communication complexity and potential delay increase

Engineering Contradiction:
ImproveQoSVSAvoidcommunication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A proxy node is introduced as an intermediary between the client device and server to perform performance enhancement services. The proxy node receives encrypted traffic, performs services using existing encryption keys without decryption, and transmits results back, thereby improving QoS while maintaining security and minimizing complexity through lightweight operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If encryption keys are transmitted to the proxy node for service performance, then service capability is enhanced, but security risk increases

Engineering Contradiction:
Improveservice capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The proxy node acts as a mediator that receives encryption keys from the client device and uses them to perform services on encrypted traffic without decrypting it. This approach enhances service capability while maintaining security by avoiding full decryption and keeping key usage localized to the proxy node's service functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The encryption keys are used locally at the proxy node only for the specific service functions required, rather than being broadly distributed or stored. This localized key usage minimizes security risks by limiting the exposure and potential impact of key compromise to only the necessary service operations.

Inventive Principle:
Principle #3Local quality

3Productivity

If the proxy node processes encrypted traffic to provide services, then performance enhancement is achieved, but processing overhead increases

Engineering Contradiction:
Improveperformance enhancementVSAvoidprocessing overhead
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The proxy node performs only the specific partial services needed on the encrypted traffic rather than full processing or decryption. By applying services selectively to only the necessary portions of traffic and using existing encryption keys efficiently, the proxy node achieves performance enhancement while minimizing processing overhead and energy consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20230379150A1Methods and apparatuses for providing communication between a server and a client device via a proxy node
Publication Date: 2023.11.23 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230379150A1 patent drawing
  • US20230379150A1 patent drawing
  • US20230379150A1 patent drawing

AI summary

Embodiments described herein relate to methods and apparatuses for providing communication between a server and a client device via a proxy node. A method, in a proxy node, wherein the proxy node includes an intermediate node between a server and a client device includes receiving encrypted traffic transmitted between the client device and the server; receiving a key from the client device; performing a service in relation to the encrypted traffic to generate information; encrypting the information using the key to generate encrypted information; and transmitting the encrypted information to the server.