Authenticated Traffic Header Encryption for Cross-Domain QoS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for traffic differentiation, such as DPI/DFI/SPI and signaling-based solutions, are inadequate for managing traffic characteristics in encrypted and multiplexed traffic, particularly across network domains, leading to limited QoS treatment effectiveness.
Innovation Solution
A method where nodes exchange traffic characteristic semantics and a common key for encrypting traffic characteristics values, which are included in the transport header of packets, allowing domain-specific QoS handling and authentication to ensure proper treatment across network domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If packet markings are used for traffic differentiation, then QoS treatment can be applied, but packet markings may be easily modified across network domains leading to limited single-domain agreements
Solution Approach 1:
The patent embeds multiple layers of protection within the packet structure: the traffic characteristic value is first encrypted using domain-specific keys, then authenticated using cryptographic authentication. This nested approach allows each domain to apply QoS treatment while maintaining security across domain boundaries, resolving the contradiction between reliable QoS treatment and cross-domain versatility.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that validates traffic characteristic values across domain boundaries. Instead of relying solely on trust between domains, the authentication system acts as an intermediary that verifies the integrity and origin of traffic markings, enabling cross-domain QoS agreements while maintaining reliability.
2Ease of operation
If traffic characteristics are sent in clear text, then network nodes can read and apply QoS treatment, but traffic characteristics may be tampered with or modified by intermediate nodes
Solution Approach 1:
The patent applies authentication and encryption to traffic characteristic values before they are transmitted through the network. By preprocessing the traffic characteristics with security measures, the system ensures that nodes can easily read and apply QoS treatment while the pre-applied authentication prevents tampering, resolving the contradiction between ease of operation and reliability.
3Reliability
If all traffic is encrypted for privacy, then communication security is improved, but network nodes cannot inspect traffic characteristics for QoS differentiation
Solution Approach 1:
The patent segments the packet into different parts with different security treatments: the payload remains fully encrypted for privacy, while the transport layer header contains authenticated and encrypted traffic characteristic values that network nodes can inspect. This segmentation allows simultaneous achievement of communication security and traffic characteristic inspection capability.
Solution Approach 2:
The patent applies different security qualities to different parts of the data structure: the payload receives strong encryption for privacy, while the traffic characteristic values receive authenticated encryption that balances security with inspectability. This local quality approach resolves the contradiction by optimizing security and inspectability for their respective purposes.
4Adaptability or versatility
If signaling protocols are used for resource reservation, then QoS requirements can be communicated, but deployment problems prevent widespread adoption
Solution Approach 1:
The patent enables endpoints to self-mark their own traffic with authenticated traffic characteristic values without requiring complex signaling protocols. This self-service approach eliminates the need for extensive signaling infrastructure and deployment coordination, while still providing versatile QoS capability across different domains and applications.
Data Source
AI summary
Methods and a first node, a second node and a network node for managing traffic characteristics of one or more packets on a connection are disclosed. The first node exchanges, with the network node, traffic characteristic semantics and a common key for encryption of a traffic characteristic value to be applied for the one or more packets on the connection, wherein the traffic characteristic semantics include the traffic characteristic value and an associated characteristic for the one or more packets. Moreover, the first node sends the traffic characteristic value and the common key to the second node. The network node checks and applies the traffic characteristics value according to service policies of the network node. Next, the first node exchanges, with the second node, payload which includes one or more packets over the connection. Information about the traffic characteristic value is included in a transport header of each packet carrying the payload.


