Session Access Control for Application-Specific Network Flows
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing telecommunications networks lack the capability to provide application-specific access control and authentication for data transmission sessions, limiting the ability to differentiate and manage data flows based on individual applications rather than subscriber subscriptions.
Innovation Solution
Assigning application-specific identifier information to data packets and using a session access control function to mark and authorize application-specific downlink and uplink flows, enabling differentiated service deployment and access control on a per-application basis.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If application-specific identifier information is assigned and transported in data packets, then application-specific access control and traffic handling are enabled, but device complexity and protocol overhead increase
Solution Approach 1:
The patent segments the data transmission session into controllable units by assigning application-specific identifier information to individual data packets. This allows the session access control function to selectively authorize or reject specific application traffic flows based on the identifier information contained in each packet, enabling fine-grained control without requiring complete session re-establishment.
Solution Approach 2:
The session access control function acts as an intermediary between the data transmission session and the core network. It intercepts data packets, extracts application-specific identifier information, and makes authorization decisions based on this information before forwarding packets to the core network, thereby enabling application-level control without modifying the underlying transmission protocol.
2Adaptability or versatility
If application-specific identifier information is transported in data packets, then differentiated service deployment is enabled, but loss of information and processing overhead increase
Solution Approach 1:
The patent merges the application-specific identifier information with existing data packet structures by transporting the identifier information within the data packets themselves. This approach allows the identifier to be carried along with the payload data without requiring separate signaling channels or additional protocol layers, thereby minimizing information loss and processing overhead.
3Productivity
If session access control function marks and authorizes application-specific flows, then application-specific traffic handling is enabled, but device complexity and processing time increase
Solution Approach 1:
The session access control function performs preliminary marking and authorization of application-specific identifier information during the data packet transmission process. By pre-configuring authorization rules and marking packets with application identifiers before core network transmission, the system enables efficient traffic handling without requiring time-consuming authorization decisions during actual data transfer.
Data Source
Figure 1~3
Figure 4~5
AI summary
The invention relates to a method for operating a user equipment within or as part of a telecommunications network, wherein the operation of the user equipment involves the operation of an application or an application layer functionality of the user equipment, wherein the telecommunications network comprises or is associated or assigned to an access network and to a core network, wherein the core network provides the user equipment with data connectivity towards a data network, wherein the operation of the application or of the application layer functionality of the user equipment requires at least one data transmission session to be established between the user equipment and the core network such that downlink data packets are able to be transmitted from or via the core network to the user equipment and uplink data packets are able to be transmitted from the user equipment to or via the core network, wherein, in order for downlink data packets, directed or related to the application or the application layer functionality, being able to form an application-specific downlink application flow, and uplink data packets, originating from the application or the application layer functionality, being able to form an application-specific uplink application flow, the method comprises the following steps: -- in a first step, at least one piece of application-specific identifier information is assigned to the application or the application layer functionality, -- in a second step, the application or the application layer functionality is operated using the at least one data transmission session, wherein both the downlink data packets and the uplink data packets comprise at least part of the at least one piece of application-specific identifier information.