TCLAS Element Filtering 5G QoS Traffic Over IPsec SAs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to provide effective Quality-of-Service (QoS) differentiation for 5G traffic carried over IPsec security associations (SAs) within Wi-Fi access, necessitating a solution to ensure end-to-end QoS in 5G networks.

Innovation Solution

A TCLAS element is extended to include a frame classifier field with specific parameters such as SPI, destination IP address, and IPsec protocol to identify and filter 5G QoS traffic flows over IPsec SAs, ensuring QoS differentiation by establishing IPsec SA filtering based on these parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPsec encryption is used for secure communication over Wi-Fi, then security is improved, but QoS differentiation for 5G traffic is lost

Engineering Contradiction:
ImprovesecurityVSAvoidQoS differentiation
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encrypted IPsec payload into individual bytes and extracts specific bytes containing TCI (Traffic Classification Information) and QoS parameters. This segmentation allows the system to access QoS differentiation data without decrypting the entire payload, thus maintaining security while enabling traffic classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism that operates on the encrypted IPsec payload without requiring full decryption. By extracting QoS parameters from specific byte positions within the encrypted data, the system acts as a mediator between security requirements and QoS differentiation needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traffic filtering is implemented for QoS differentiation, then QoS is improved, but complexity of traffic classification increases

Engineering Contradiction:
ImproveQoS differentiationVSAvoidtraffic classification complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter representation by extracting QoS information from specific byte positions within the encrypted payload rather than requiring full decryption. This parameter change approach simplifies the classification process by directly accessing predefined byte locations containing TCI and QoS parameters.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies partial action by extracting only the specific bytes needed for QoS classification (TCI bytes and QoS parameter bytes) from the encrypted payload, rather than processing or decrypting the entire packet. This reduces classification complexity while maintaining effective QoS differentiation.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If IPsec SA parameters are extracted from encrypted payload, then QoS filtering capability is improved, but processing overhead increases

Engineering Contradiction:
ImproveQoS filtering capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent extracts only the minimal necessary bytes (TCI bytes and QoS parameter bytes) from the encrypted IPsec payload without performing full decryption. This partial action approach reduces processing overhead and time loss while maintaining improved QoS filtering capability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The QoS parameters are embedded in predetermined byte positions within the encrypted payload during packet generation. This preliminary action allows the receiving end to directly extract QoS information without decryption, minimizing processing overhead and time loss.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4190023B1Tclas element for filtering ipsec traffic
Publication Date: 2025.09.10 INTEL CORP
  • EP4190023B1 patent drawingFigure 1
  • EP4190023B1 patent drawingFigure 2
  • EP4190023B1 patent drawingFigure 3A~3B

AI summary

To carry a 5G QoS traffic flow over an IPsec security association (SA) within the WLAN network, a STA is configured to encode a frame to include a traffic classification (TCLAS) element comprising a frame classifier field. The frame classifier field may include a classifier type subfield and a classifier parameters subfield. To identify and filter the 5G QoS traffic flow carried over the IPsec SA, the STA may set the classifier type subfield to a predetermine value (e.g., 11) to indicate that IPsec SA parameters are included in the classifier parameters subfield and include a Security Parameter Index (SPI), a destination IP address, and a IPsec protocol within the classifier parameters subfield.