Cellular Core Routing With Token DNNs for Encrypted App Traffic
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G network routing methods fail to optimize data traffic routing due to lack of precise identification of application origin and type, leading to suboptimal user experience, as operating systems obscure this information for privacy reasons, and packet inspection is not feasible for encrypted data.
Innovation Solution
A method utilizing a network operator platform to configure application clients and core networks with token DNNs, enabling precise identification and customized handling of data traffic by generating configuration information for application clients and core networks, allowing the network operator to allocate optimized network slices and routes based on application and UE identity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If packet inspection is used to identify data traffic origin and type, then routing precision is improved, but it becomes infeasible for encrypted data
Solution Approach 1:
The patent applies preliminary action by establishing the routing configuration before data transmission begins. The network operator platform pre-configures the application client with token DNN mappings and routing rules, so that when encrypted data traffic flows through the network, the routing decisions are already determined based on pre-established associations between token DNNs, application identifiers, and network slices, eliminating the need for real-time inspection of encrypted data
Solution Approach 2:
The patent introduces an intermediary mechanism through the network operator platform and token DNN system. Instead of directly inspecting encrypted data packets, the system uses token DNNs as intermediaries that carry routing information. The platform mediates between the application client and the core network, translating application-specific routing requirements into network-configurable parameters that guide encrypted traffic through appropriate network slices without requiring decryption
2Loss of information
If operating systems obscure application identification information for privacy reasons, then user privacy is protected, but data traffic identification precision deteriorates
Solution Approach 1:
The patent applies segmentation by separating the identification function from the data payload. Instead of relying on the operating system to provide complete application identification, the system segments the identification process into multiple components: token DNNs for routing identification, application identifiers for service identification, and network slice selections for traffic type identification. This segmentation allows precise traffic identification while maintaining privacy protection, as each segment provides only the specific information needed for its function
Solution Approach 2:
The patent introduces another dimension by moving the identification mechanism from the operating system layer to the network configuration layer. Instead of relying on the OS to expose application information, the system creates a parallel identification dimension through token DNN mappings that are configured independently of OS privacy settings. This dimensional shift allows routing identification to occur at the network level without compromising OS-level privacy protections
3Productivity
If network slicing is implemented to optimize routing, then network characteristics are improved, but device complexity increases
Solution Approach 1:
The patent applies self-service by enabling the network operator platform to automatically generate and distribute routing configurations. The platform autonomously creates token DNN mappings, generates URSP rules, and pushes configurations to application clients without requiring manual intervention. This automation reduces the perceived complexity for users while maintaining optimized network slicing, as the system serves itself by generating and managing its own routing intelligence
Data Source
AI summary
A method for routing data through a cellular network from an application client at a user equipment (UE) to an application server via the core network. The method comprises use of a network operator platform to configure the application client and the core network. The application client is configured to address a request for a communication session between the application client and the application server to a token Data Network Name (DNN). The core network is configured to route data addressed to the token DNN to a specified DNN. By providing the network operator with information on the origin and type of data traffic received from a UE (signalled by use of the token DNN, which may be specific to a given application session), the network operator can implement specific, customised handling and treatment of the data traffic as it passes through the cellular network.


