Session Access Control for Application-Specific Network Flows

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunications networks lack the capability to provide application-specific access control and authentication for data transmission sessions, limiting the ability to differentiate and manage data flows based on individual applications rather than subscriber subscriptions.

Innovation Solution

Assigning application-specific identifier information to data packets and using a session access control function to mark and authorize application-specific downlink and uplink flows, enabling differentiated service deployment and access control on a per-application basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If application-specific identifier information is assigned and transported in data packets, then application-specific access control and traffic handling are enabled, but device complexity and protocol overhead increase

Engineering Contradiction:
Improveapplication-specific access control capabilityVSAvoidsession access control function complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the data transmission session into controllable units by assigning application-specific identifier information to individual data packets. This allows the session access control function to selectively authorize or reject specific application traffic flows based on the identifier information contained in each packet, enabling fine-grained control without requiring complete session re-establishment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The session access control function acts as an intermediary between the data transmission session and the core network. It intercepts data packets, extracts application-specific identifier information, and makes authorization decisions based on this information before forwarding packets to the core network, thereby enabling application-level control without modifying the underlying transmission protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If application-specific identifier information is transported in data packets, then differentiated service deployment is enabled, but loss of information and processing overhead increase

Engineering Contradiction:
Improvedifferentiated service capabilityVSAvoiddata packet overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent merges the application-specific identifier information with existing data packet structures by transporting the identifier information within the data packets themselves. This approach allows the identifier to be carried along with the payload data without requiring separate signaling channels or additional protocol layers, thereby minimizing information loss and processing overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Productivity

If session access control function marks and authorizes application-specific flows, then application-specific traffic handling is enabled, but device complexity and processing time increase

Engineering Contradiction:
Improveapplication-specific traffic handling efficiencyVSAvoidsession setup and control processing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The session access control function performs preliminary marking and authorization of application-specific identifier information during the data packet transmission process. By pre-configuring authorization rules and marking packets with application identifiers before core network transmission, the system enables efficient traffic handling without requiring time-consuming authorization decisions during actual data transfer.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4149138B1Method for operating a user equipment within or as part of a telecommunications network, user equipment, system or telecommunications network, session access control function or functionality, program and computer program product
Publication Date: 2026.03.18 DEUTSCHE TELEKOM AG
  • EP4149138B1 patent drawingFigure 1~3
  • EP4149138B1 patent drawingFigure 4~5

AI summary

The invention relates to a method for operating a user equipment within or as part of a telecommunications network, wherein the operation of the user equipment involves the operation of an application or an application layer functionality of the user equipment, wherein the telecommunications network comprises or is associated or assigned to an access network and to a core network, wherein the core network provides the user equipment with data connectivity towards a data network, wherein the operation of the application or of the application layer functionality of the user equipment requires at least one data transmission session to be established between the user equipment and the core network such that downlink data packets are able to be transmitted from or via the core network to the user equipment and uplink data packets are able to be transmitted from the user equipment to or via the core network, wherein, in order for downlink data packets, directed or related to the application or the application layer functionality, being able to form an application-specific downlink application flow, and uplink data packets, originating from the application or the application layer functionality, being able to form an application-specific uplink application flow, the method comprises the following steps: -- in a first step, at least one piece of application-specific identifier information is assigned to the application or the application layer functionality, -- in a second step, the application or the application layer functionality is operated using the at least one data transmission session, wherein both the downlink data packets and the uplink data packets comprise at least part of the at least one piece of application-specific identifier information.