Tagged Packet Identification for Encrypted Stream Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In communication networks, particularly with protocols like QUIC, identifying and processing specific data streams among multiplexed streams is challenging due to encryption and multiplexing, making it difficult for operators to differentiate and apply appropriate processing, such as billing, especially in scenarios like the eCall service where latency and priority are critical.

Innovation Solution

A method is introduced where a terminal equipment adds a specific attribute to information packets, applies a tag, and transmits them to a data server, allowing devices like routers or DPI equipment to identify and process messages based on attributes like the terminal origin, application type, or quality of service without decrypting the packets, using protocols like QUIC, HTTP2, or HTTP3, and modifying 'spin bit' or 'reserved bits' for differentiation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption mechanisms are applied to data streams for security, then confidentiality and authentication are improved, but the ability to identify and differentiate specific streams for processing is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidstream identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the identification problem by separating the encrypted data payload from the unencrypted identification fields. Stream identifiers, attributes, and tags are placed in packet headers or metadata fields that remain unencrypted, allowing routing equipment to identify and differentiate streams without needing to decrypt the actual data content.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary tagging mechanism where identification attributes are added to packets as metadata or headers. These tags act as intermediaries between the encrypted data streams and the routing equipment, enabling stream identification without compromising security. The tags include stream identifiers, application types, and quality of service attributes that facilitate differentiated processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple data streams are multiplexed in a single connection, then bandwidth efficiency is improved, but the complexity of identifying and processing individual streams is worsened

Engineering Contradiction:
Improvebandwidth efficiencyVSAvoidstream differentiation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning unique identification attributes and tags to specific packets or stream segments within the multiplexed connection. Each stream is marked with local identifiers (stream IDs, application types, QoS attributes) that enable routing equipment to differentiate and apply appropriate processing to individual streams while maintaining efficient multiplexing.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements preliminary action by pre-tagging packets with identification attributes before they enter the multiplexed stream. Stream identifiers, attributes, and tags are added during packet encapsulation, allowing routing equipment to perform efficient stream differentiation and processing decisions without complex real-time analysis of the multiplexed data flow.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If IP address-based stream differentiation is used, then implementation simplicity is improved, but effectiveness is worsened when multiple streams originate from or are routed to the same IP address

Engineering Contradiction:
Improveimplementation simplicityVSAvoidstream differentiation accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent changes the identification parameters from coarse-grained IP addresses to fine-grained packet-level attributes. Instead of relying solely on source and destination IP addresses, the system uses stream identifiers, application types, quality of service attributes, and custom tags that provide precise stream differentiation even when multiple streams share the same IP endpoints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20230262004A1Method for discriminating a message between a terminal and a data server
Publication Date: 2023.08.17 ORANGE SA
  • US20230262004A1 patent drawing
  • US20230262004A1 patent drawing
  • US20230262004A1 patent drawing

AI summary

A method for discriminating a first message concerning a first application from among a set of messages concerning a plurality of applications, transmitted by a terminal device to a data server via a routing device, able to apply a processing operation to an attribute in relation to the first message. The method is implemented by the terminal device and includes: adding an attribute in relation to the first message to an information packet, the packet grouping attributes to which the processing operation is applied; applying a tag to the information packet including the added attribute; and transmitting the information packet comprising the applied tag to the data server.