Tagged Packet Identification for Encrypted Stream Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In communication networks, particularly with protocols like QUIC, identifying and processing specific data streams among multiplexed streams is challenging due to encryption and multiplexing, making it difficult for operators to differentiate and apply appropriate processing, such as billing, especially in scenarios like the eCall service where latency and priority are critical.
Innovation Solution
A method is introduced where a terminal equipment adds a specific attribute to information packets, applies a tag, and transmits them to a data server, allowing devices like routers or DPI equipment to identify and process messages based on attributes like the terminal origin, application type, or quality of service without decrypting the packets, using protocols like QUIC, HTTP2, or HTTP3, and modifying 'spin bit' or 'reserved bits' for differentiation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption mechanisms are applied to data streams for security, then confidentiality and authentication are improved, but the ability to identify and differentiate specific streams for processing is worsened
Solution Approach 1:
The patent segments the identification problem by separating the encrypted data payload from the unencrypted identification fields. Stream identifiers, attributes, and tags are placed in packet headers or metadata fields that remain unencrypted, allowing routing equipment to identify and differentiate streams without needing to decrypt the actual data content.
Solution Approach 2:
The patent introduces an intermediary tagging mechanism where identification attributes are added to packets as metadata or headers. These tags act as intermediaries between the encrypted data streams and the routing equipment, enabling stream identification without compromising security. The tags include stream identifiers, application types, and quality of service attributes that facilitate differentiated processing.
2Productivity
If multiple data streams are multiplexed in a single connection, then bandwidth efficiency is improved, but the complexity of identifying and processing individual streams is worsened
Solution Approach 1:
The patent applies local quality by assigning unique identification attributes and tags to specific packets or stream segments within the multiplexed connection. Each stream is marked with local identifiers (stream IDs, application types, QoS attributes) that enable routing equipment to differentiate and apply appropriate processing to individual streams while maintaining efficient multiplexing.
Solution Approach 2:
The patent implements preliminary action by pre-tagging packets with identification attributes before they enter the multiplexed stream. Stream identifiers, attributes, and tags are added during packet encapsulation, allowing routing equipment to perform efficient stream differentiation and processing decisions without complex real-time analysis of the multiplexed data flow.
3Ease of manufacture
If IP address-based stream differentiation is used, then implementation simplicity is improved, but effectiveness is worsened when multiple streams originate from or are routed to the same IP address
Solution Approach 1:
The patent changes the identification parameters from coarse-grained IP addresses to fine-grained packet-level attributes. Instead of relying solely on source and destination IP addresses, the system uses stream identifiers, application types, quality of service attributes, and custom tags that provide precise stream differentiation even when multiple streams share the same IP endpoints.
Data Source
AI summary
A method for discriminating a first message concerning a first application from among a set of messages concerning a plurality of applications, transmitted by a terminal device to a data server via a routing device, able to apply a processing operation to an attribute in relation to the first message. The method is implemented by the terminal device and includes: adding an attribute in relation to the first message to an information packet, the packet grouping attributes to which the processing operation is applied; applying a tag to the information packet including the added attribute; and transmitting the information packet comprising the applied tag to the data server.


