Service Communication Proxy Decrypting IP Traffic for Core Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional deep packet inspection (DPI) methods struggle to detect intruders or unwanted entities in encrypted IP traffic within core networks, such as 5G or 6G mobile core networks, as encryption hides malicious activities.
Innovation Solution
A system and method that utilize a service communication proxy (SCP) to decrypt at least one layer of IP traffic and perform a security inspection, which can include intrusion detection, malware detection, and anomaly detection, using artificial intelligence algorithms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If deep packet inspection is performed on encrypted IP traffic, then network security inspection capability is maintained, but detection precision deteriorates because encryption hides malicious activities
Solution Approach 1:
The patent introduces a service communication proxy as an intermediary component positioned between network functions. This proxy intercepts IP traffic, decrypts it using its private key, performs deep packet inspection on the decrypted data, and then re-encrypts the traffic before forwarding it. By placing the proxy in this intermediary position with access to both encrypted and decrypted traffic, the system enables security inspection of encrypted communications without requiring the entire network to operate in unencrypted mode, thus resolving the contradiction between maintaining security inspection capability and overcoming encryption obfuscation.
2Reliability
If IP traffic is decrypted for security inspection, then intruder detection capability is improved, but network complexity increases due to additional decryption and re-encryption operations
Solution Approach 1:
The service communication proxy is designed to perform multiple functions within a single network element: it acts as a traffic interceptor, a decryption engine using its private key, a deep packet inspection system, and a re-encryption module. By consolidating these multiple functions into one universal proxy component rather than distributing separate systems for each function, the patent reduces overall network complexity while maintaining enhanced intruder detection capability through comprehensive security inspection of decrypted traffic.
3Reliability
If all communications between network functions go through service communication proxies, then security inspection coverage is improved, but processing time increases due to additional decryption and inspection steps
Solution Approach 1:
The patent implements preliminary action by having the service communication proxy perform decryption and security inspection before the traffic reaches its final destination. The proxy decrypts the traffic using its private key, inspects the decrypted packets for malicious activities, and only after verification does it re-encrypt and forward the traffic. This preliminary inspection approach ensures comprehensive security coverage while minimizing time loss by performing inspections in advance rather than requiring continuous monitoring throughout the entire communication path.
Data Source
AI summary
The present disclosure relates to a system and a method for security inspection of IP traffic in a core network. The system comprises at least one service communication proxy which comprises at least one interface and a processor; wherein the interface is configured to receive the IP traffic; wherein the processor is configured to decrypt at least one layer of communication of the received IP traffic; and wherein the processor is further configured to perform a security inspection on the at least one decrypted layer.


