Service Communication Proxy Decrypting IP Traffic for Core Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional deep packet inspection (DPI) methods struggle to detect intruders or unwanted entities in encrypted IP traffic within core networks, such as 5G or 6G mobile core networks, as encryption hides malicious activities.

Innovation Solution

A system and method that utilize a service communication proxy (SCP) to decrypt at least one layer of IP traffic and perform a security inspection, which can include intrusion detection, malware detection, and anomaly detection, using artificial intelligence algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep packet inspection is performed on encrypted IP traffic, then network security inspection capability is maintained, but detection precision deteriorates because encryption hides malicious activities

Engineering Contradiction:
Improvedetection precisionVSAvoidencryption hiding malicious activities
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service communication proxy as an intermediary component positioned between network functions. This proxy intercepts IP traffic, decrypts it using its private key, performs deep packet inspection on the decrypted data, and then re-encrypts the traffic before forwarding it. By placing the proxy in this intermediary position with access to both encrypted and decrypted traffic, the system enables security inspection of encrypted communications without requiring the entire network to operate in unencrypted mode, thus resolving the contradiction between maintaining security inspection capability and overcoming encryption obfuscation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IP traffic is decrypted for security inspection, then intruder detection capability is improved, but network complexity increases due to additional decryption and re-encryption operations

Engineering Contradiction:
Improveintruder detection capabilityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The service communication proxy is designed to perform multiple functions within a single network element: it acts as a traffic interceptor, a decryption engine using its private key, a deep packet inspection system, and a re-encryption module. By consolidating these multiple functions into one universal proxy component rather than distributing separate systems for each function, the patent reduces overall network complexity while maintaining enhanced intruder detection capability through comprehensive security inspection of decrypted traffic.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If all communications between network functions go through service communication proxies, then security inspection coverage is improved, but processing time increases due to additional decryption and inspection steps

Engineering Contradiction:
Improvesecurity inspection coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by having the service communication proxy perform decryption and security inspection before the traffic reaches its final destination. The proxy decrypts the traffic using its private key, inspects the decrypted packets for malicious activities, and only after verification does it re-encrypt and forward the traffic. This preliminary inspection approach ensures comprehensive security coverage while minimizing time loss by performing inspections in advance rather than requiring continuous monitoring throughout the entire communication path.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250080500A1System and method for security inspection of IP traffic in a core network
Publication Date: 2025.03.06 ROHDE & SCHWARZ GMBH & CO KG
  • US20250080500A1 patent drawing
  • US20250080500A1 patent drawing
  • US20250080500A1 patent drawing

AI summary

The present disclosure relates to a system and a method for security inspection of IP traffic in a core network. The system comprises at least one service communication proxy which comprises at least one interface and a processor; wherein the interface is configured to receive the IP traffic; wherein the processor is configured to decrypt at least one layer of communication of the received IP traffic; and wherein the processor is further configured to perform a security inspection on the at least one decrypted layer.