Token-Based Session Correlation in NAT Policy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Policy and Charging Control (PCC) architectures in telecommunications systems, which employ Network Address Translators (NATs) for Deep Packet Inspection (DPI), face challenges in properly controlling IP-CAN sessions due to the absence of the User Equipment (UE) IP address, leading to limitations in policy evaluation and enforcement, especially in managing QoS and session correlations.

Innovation Solution

A token-based mechanism is introduced to uniquely identify IP sessions, allowing the Policy Server (PS) to associate service control sessions between the Access Gateway (AG) and the Deep Packet Inspection (DPI) node, enabling effective policy rule enforcement and session management by replacing the UE IP address with a translated IP address and distributing tokens among network elements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If a NAT is used to enable DPI for both outgoing and incoming packets, then packet inspection capability is improved, but the ability to correlate service control sessions and enforce policies is worsened due to loss of UE IP address information

Engineering Contradiction:
Improvepacket inspection capabilityVSAvoidUE IP address information
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of information

Solution Approach 1:

The patent introduces a token as an intermediary element that carries UE IP address information through the NAT boundary. The token is inserted into packets at the AG before NAT translation, allowing the DPI node to access UE IP information without compromising the NAT functionality. This mediator approach resolves the contradiction by enabling both packet inspection and policy correlation simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the packet structure by separating the UE IP address information from the main packet payload. The token contains the UE IP address information as a distinct segment that can be independently transmitted through the NAT. This segmentation allows the NAT to translate IP addresses for inspection purposes while the token preserves the original UE IP information for policy correlation.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If DPI is performed on all packets, then inspection thoroughness is improved, but processing time and network resources are worsened

Engineering Contradiction:
Improveinspection thoroughnessVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies local quality by differentiating the treatment of packets based on their characteristics. Packets are marked with tokens that indicate whether they require full DPI inspection or can be processed with simpler rules. This allows the system to maintain high inspection thoroughness for critical packets while reducing processing time for less critical traffic, optimizing the balance between measurement precision and time loss.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9106541B2Token-based correlation of control sessions for policy and charging control of a data session through a NAT
Publication Date: 2015.08.11 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9106541B2 patent drawing
  • US9106541B2 patent drawing
  • US9106541B2 patent drawing

AI summary

A method of handling packets sent across a packet switched network comprising a policy server acting as a policy and charging rules function. The method comprises providing a first set of policy rules at said policy server, and installing these from the policy server into an access gateway over a first service control session. These policy rules cause packets belonging to a given IP session to be diverted by the access gateway to a network address translator. At the network address translator, an IP source address of said packets is translated into a translated IP source address identifying a deep packet inspection node. The network address translator forwards the packets to the deep packet inspection node configured to perform deep packet inspection of IP packets.