Toll-Free Traffic Identification via Encrypted Campaign Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems face challenges in identifying and differentiating traffic associated with multiple toll-free data service campaigns from the same IP address and port, leading to incorrect charging and increased processing delays.
Innovation Solution
The implementation of a key-based authentication and encryption system, where content providers use a content public key and enforcement public/private key pairs to validate and encrypt session information, allowing network operators to accurately identify and charge for data usage associated with specific campaigns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional IP address and port-based traffic identification is used, then traffic routing is simple, but traffic identification accuracy deteriorates when multiple campaigns share the same IP and port
Solution Approach 1:
The patent segments traffic identification from traditional IP/port-based methods to application-layer authentication using App IDs and campaign-specific credentials. Each campaign receives unique authentication credentials, enabling precise traffic differentiation even when multiple campaigns share the same network infrastructure (IP address and port).
Solution Approach 2:
The patent introduces an intermediary authentication system that mediates between the application layer and network layer. The system uses session tokens and encrypted credentials as intermediaries to verify campaign affiliation, allowing accurate traffic identification without modifying underlying network routing infrastructure.
2Productivity
If manual traffic verification processes are used, then system complexity is low, but processing delays increase
Solution Approach 1:
The patent implements preliminary authentication where applications register App IDs and receive encryption keys before actual data transfer. Session tokens are pre-generated and validated, allowing rapid traffic verification during data transfer without real-time manual intervention or complex runtime verification processes.
Solution Approach 2:
The patent replaces manual mechanical verification processes with automated cryptographic validation. Encryption/decryption operations and token validation algorithms automatically verify campaign affiliation, eliminating human intervention and significantly reducing processing delays while maintaining security.
3Reliability
If basic traffic classification is used, then processing overhead is low, but charging accuracy deteriorates
Solution Approach 1:
The patent uses encrypted session tokens and authentication credentials as unique identifiers for different campaigns, analogous to using distinct colors to differentiate objects. Each campaign's traffic is tagged with cryptographic credentials that enable precise identification and accurate charging, replacing basic classification with cryptographically-secured identification.
Data Source
AI summary
A device may receive, from a mobile device, first encrypted information, encrypted by a content provider device using a first private key, and at least one unencrypted identifier. The device may decrypt, using a first public key, the first encrypted information to obtain first information that may include second encrypted information, encrypted using a second public key. The device may decrypt, using a second private key, the second encrypted information to obtain second information that may include at least one first identifier and at least one second identifier corresponding to a toll-free data service campaign that may be provided by a content provider. The device may allow toll-free data service traffic, for the mobile device, based on whether the at least one first identifier corresponds to the at least one unencrypted identifier and the traffic includes at least one third identifier that corresponds to the at least one second identifier.


