User Equipment Selective Encryption Deactivation for QUIC Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for managing encrypted communications in 5G networks, particularly with the QUIC protocol, suffer from overhead and performance issues due to redundant encryption and encapsulation, which are not addressed by the MPTCP protocol and induce additional processing times and packet fragmentation.

Innovation Solution

A user equipment can selectively deactivate redundant encryption and encapsulation procedures during communications, optimizing performance by reducing overhead and processing times, while maintaining security and adhering to network policies through prior negotiation and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple encryption procedures are implemented for data routing in 5G networks, then security is improved, but overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies dynamics by making the encryption procedure selection adaptive rather than fixed. The user equipment dynamically selects which encryption procedure to deactivate based on real-time network conditions, available paths, and security requirements. This allows the system to optimize between security and processing time depending on the operational context, resolving the contradiction between maintaining security and reducing processing overhead.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of encryption procedure selection from a static configuration to a dynamic decision variable. By allowing the user equipment to modify which encryption procedures are active or deactivated based on current network state and available routing paths, the system optimizes the balance between security level and processing time without compromising either aspect excessively.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If redundant encryption and encapsulation procedures are used, then security coverage is improved, but packet fragmentation increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidpacket fragmentation
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and removes redundant encryption procedures from the data path. By identifying and deactivating unnecessary encryption layers that do not contribute to enhanced security, the system reduces encapsulation overhead and prevents packet fragmentation while maintaining adequate security coverage through selective encryption only where needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent discards redundant encryption procedures that provide no additional security benefit, thereby eliminating the harmful effect of packet fragmentation. The system recovers processing efficiency by removing unnecessary encryption/decryption operations while maintaining security through essential encryption procedures only.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If multiple communication paths are managed with redundant encryption, then connectivity reliability is improved, but resource usage increases

Engineering Contradiction:
Improveconnectivity reliabilityVSAvoidresource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by implementing encryption procedures only where necessary rather than universally. The user equipment selectively deactivates redundant encryption for certain paths or data types where it provides no additional security benefit, thereby reducing resource consumption while maintaining connectivity reliability through essential security measures.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The user equipment autonomously manages encryption procedure selection without requiring continuous network intervention. By making self-driven decisions about which encryption procedures to activate or deactivate based on local conditions, the system optimizes resource usage while maintaining reliable connectivity across multiple paths.

Inventive Principle:
Principle #25Self-service

4Loss of time

If encryption procedures are deactivated without network coordination, then processing time is reduced, but network security policies may be violated

Engineering Contradiction:
Improveprocessing timeVSAvoidnetwork security policy compliance
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the user equipment receives network information about available paths and security requirements, and adjusts encryption procedures accordingly. This feedback loop ensures that encryption deactivation decisions respect network security policies while still optimizing processing time based on actual network conditions and available alternatives.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12432565B2Methods for configuring a user apparatus, negotiating with a network entity, and managing a connection, and associated devices
Publication Date: 2025.09.30 ORANGE SA
  • US12432565B2 patent drawing
  • US12432565B2 patent drawing
  • US12432565B2 patent drawing

AI summary

A method for configuring a user apparatus and implemented by the user apparatus. The method including: deactivating, for at least one encrypted communication of the user apparatus with a remote device via a network, at least one encryption procedure selected by the user apparatus and implemented with a first entity of the network involved in routing data exchanged between the user apparatus and the remote device during the encrypted communication, the data being subject to at least one other encryption procedure separate from the at least one deactivated encryption procedure.