Cellular Core Routing With Token DNNs for Encrypted App Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G network routing methods fail to optimize data traffic routing due to lack of precise identification of application origin and type, leading to suboptimal user experience, as operating systems obscure this information for privacy reasons, and packet inspection is not feasible for encrypted data.

Innovation Solution

A method utilizing a network operator platform to configure application clients and core networks with token DNNs, enabling precise identification and customized handling of data traffic by generating configuration information for application clients and core networks, allowing the network operator to allocate optimized network slices and routes based on application and UE identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If packet inspection is used to identify data traffic origin and type, then routing precision is improved, but it becomes infeasible for encrypted data

Engineering Contradiction:
Improverouting precisionVSAvoidencryption interference
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing the routing configuration before data transmission begins. The network operator platform pre-configures the application client with token DNN mappings and routing rules, so that when encrypted data traffic flows through the network, the routing decisions are already determined based on pre-established associations between token DNNs, application identifiers, and network slices, eliminating the need for real-time inspection of encrypted data

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism through the network operator platform and token DNN system. Instead of directly inspecting encrypted data packets, the system uses token DNNs as intermediaries that carry routing information. The platform mediates between the application client and the core network, translating application-specific routing requirements into network-configurable parameters that guide encrypted traffic through appropriate network slices without requiring decryption

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If operating systems obscure application identification information for privacy reasons, then user privacy is protected, but data traffic identification precision deteriorates

Engineering Contradiction:
Improveprivacy protectionVSAvoiddata traffic identification precision
Core Design Contradiction:
Loss of informationVSMeasurement precision

Solution Approach 1:

The patent applies segmentation by separating the identification function from the data payload. Instead of relying on the operating system to provide complete application identification, the system segments the identification process into multiple components: token DNNs for routing identification, application identifiers for service identification, and network slice selections for traffic type identification. This segmentation allows precise traffic identification while maintaining privacy protection, as each segment provides only the specific information needed for its function

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces another dimension by moving the identification mechanism from the operating system layer to the network configuration layer. Instead of relying on the OS to expose application information, the system creates a parallel identification dimension through token DNN mappings that are configured independently of OS privacy settings. This dimensional shift allows routing identification to occur at the network level without compromising OS-level privacy protections

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If network slicing is implemented to optimize routing, then network characteristics are improved, but device complexity increases

Engineering Contradiction:
Improvenetwork characteristicsVSAvoidrouting configuration complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the network operator platform to automatically generate and distribute routing configurations. The platform autonomously creates token DNN mappings, generates URSP rules, and pushes configurations to application clients without requiring manual intervention. This automation reduces the perceived complexity for users while maintaining optimized network slicing, as the system serves itself by generating and managing its own routing intelligence

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12587942B2Method for routing data from an application client to an application server via a core network of a cellular network
Publication Date: 2026.03.24 VODAFONE GROUP SERVICES LTD
  • US12587942B2 patent drawing
  • US12587942B2 patent drawing
  • US12587942B2 patent drawing

AI summary

A method for routing data through a cellular network from an application client at a user equipment (UE) to an application server via the core network. The method comprises use of a network operator platform to configure the application client and the core network. The application client is configured to address a request for a communication session between the application client and the application server to a token Data Network Name (DNN). The core network is configured to route data addressed to the token DNN to a specified DNN. By providing the network operator with information on the origin and type of data traffic received from a UE (signalled by use of the token DNN, which may be specific to a given application session), the network operator can implement specific, customised handling and treatment of the data traffic as it passes through the cellular network.