QUIC Secondary Encrypted Connections for Network Function Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The QUIC protocol lacks a mechanism for collaboration between terminals and network operators to enhance user experience through functions like anti-virus services and packet inspection without introducing additional latency or compromising security.
Innovation Solution
A method is introduced that establishes secondary encrypted connections between terminals and intermediate processing functions within the network, allowing for the invocation of processing functions like error correction and packet inspection without altering the primary connection's security, and enabling on-demand invocation and selection of functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network functions (anti-virus, packet inspection) are introduced to enhance user experience, then service quality improves, but connection establishment latency increases
Solution Approach 1:
The patent pre-establishes encrypted secondary connections between terminals and network functions before actual data transmission. This preliminary setup allows network functions to be ready to process traffic immediately when needed, avoiding the latency that would result from establishing connections on-demand during data transmission.
Solution Approach 2:
The patent introduces intermediate processing functions as mediators between terminals and the network. These intermediate functions act as proxies that can perform anti-virus scanning, packet inspection, and other processing tasks without requiring direct terminal involvement, thereby maintaining service quality while minimizing impact on connection establishment latency.
2Adaptability or versatility
If network functions modify addresses or port numbers, then network control improves, but QUIC connection stability deteriorates
Solution Approach 1:
The patent uses intermediate processing functions as intermediaries that handle address and port number modifications. These intermediaries maintain the encryption context and connection state, allowing network control functions to modify routing information without breaking the encrypted QUIC connection between terminals. The intermediaries translate and forward packets while preserving connection stability.
Solution Approach 2:
The patent segments the connection management into multiple independent encrypted connections: a primary connection for control and a secondary connection for data transmission through intermediaries. This segmentation allows address modifications in the secondary connection without affecting the primary connection's stability, enabling network control while maintaining connection integrity.
3Reliability
If all data is encrypted end-to-end, then security improves, but network function access to data deteriorates
Solution Approach 1:
The patent segments data transmission into multiple encrypted channels: a primary encrypted connection for sensitive control data and a secondary encrypted connection for data that may require network function access. This segmentation allows different security levels for different data types, maintaining end-to-end encryption where needed while enabling controlled access for network functions when required by policy.
Solution Approach 2:
The patent applies different encryption and access control policies to different portions of data traffic based on local requirements. Network functions can access and process specific data streams that require inspection (such as anti-virus scanning) while leaving other streams fully encrypted. This local quality approach maintains security for sensitive data while enabling necessary network function access for other data.
Data Source
AI summary
A method for communication in a network is disclosed, between a first and second terminal between which is established a first encrypted connection for transmitting data. The method comprises at the first terminal: storing, in association with the first connection, at least one second connection between the first terminal and the second terminal via an intermediate processing function intended to be applied between the first terminal and the second terminal to a part of the data referred to as eligible for the second connection, and a filter characterizing the data eligible for the second connection, the second connection being encrypted between the first terminal and the intermediate processing function, and sending, via the second connection, a message intended for the intermediate function and carrying data for the second terminal corresponding to the filter, the first message sent comprising information according to which the data are intended for the second terminal.


