Proxy Node Service Optimization via Decryption Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Proxy nodes cannot provide service optimization for user equipment due to their inability to decrypt ciphertexts, as they do not possess the encryption keys used by user equipment and network servers.

Innovation Solution

A proxy node sets up encrypted connections with user equipment and network servers, obtaining an encryption context to generate a first key, which it uses to decrypt ciphertexts sent by the user equipment, allowing it to process and forward service information to the network server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a proxy node is disposed between user equipment and network server to enable service optimization, then service optimization capability is improved, but the proxy node cannot decrypt ciphertext because it does not have the encryption keys

Engineering Contradiction:
Improveservice optimization capabilityVSAvoidinability to decrypt ciphertext
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a key distribution mechanism where the encryption context is shared between the user equipment and the proxy node. The proxy node acts as an intermediary that can generate the first key from the encryption context, enabling it to decrypt ciphertext while maintaining the security architecture. This resolves the contradiction by allowing the proxy node to function as both a service optimization point and a decryption-capable entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the key generation process into two parts: the user equipment generates the second key and encryption context, while the proxy node independently generates the first key from the same encryption context. This segmentation allows both parties to have decryption capabilities without sharing private keys directly, enabling the proxy to decrypt and optimize services while maintaining end-to-end encryption security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If end-to-end encryption is used between user equipment and network server, then security is improved, but proxy nodes cannot access or optimize the communication content

Engineering Contradiction:
Improveencryption securityVSAvoidservice optimization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The encryption context serves as a mediator that enables the proxy node to decrypt and optimize communications without compromising the end-to-end encryption security model. The proxy node uses this context to generate the first key, allowing it to act as a trusted intermediary that can inspect and optimize traffic while maintaining the security guarantees of encrypted communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of key generation by allowing multiple parties (user equipment and proxy node) to independently derive keys from the same encryption context using different key generation functions. This parameter change enables the proxy to access encrypted content for optimization purposes while the original end-to-end encryption security model remains intact.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3324571B1Service processing method and apparatus
Publication Date: 2020.08.19 HUAWEI TECH CO LTD
  • EP3324571B1 patent drawingFigure 1
  • EP3324571B1 patent drawingFigure 2
  • EP3324571B1 patent drawingFigure 3A

AI summary

The present invention relates to the communications field, and discloses a service processing method and apparatus. The method includes: setting up, by a proxy node, in place of a network server, a first encrypted connection to UE, and setting up a second encrypted connection to the network server; obtaining, by the proxy node from the UE, an encryption context generated in the process of setting up the first encrypted connection, and generating a first key according to the encryption context; and receiving, by the proxy node, a ciphertext sent by the UE, decrypting the ciphertext by using the first key, processing obtained service information, and sending the processed service information to the network server by using the second encrypted connection, where the ciphertext is obtained by the UE by encrypting the service information by using a second key, the first key corresponds to the second key, and the second key is generated by the UE according to the encryption context. According to the present invention, a problem that a proxy node cannot provide service optimization for UE because the proxy node cannot decrypt a ciphertext is resolved, and an effect of expanding a usage scope of service optimization is achieved.