Tunnel Filtering System for Mobile Network Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile networks face challenges in managing communication resources during crisis situations, where security services require reliable communication while heavy traffic leads to resource exhaustion, making it difficult to prioritize and manage data transmission effectively.

Innovation Solution

A tunnel filtering system that allows for the prioritization and management of data transmission by using a set of filters shared between user devices and a VPN gateway, directing specific data types through designated VPN tunnels and EPS bearers, and dynamically rerouting data when initial connections become unavailable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple data types are transmitted through shared wireless media, then communication capacity is utilized efficiently, but resource exhaustion occurs during heavy traffic load

Engineering Contradiction:
Improvecommunication capacity utilizationVSAvoidconnection availability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments encrypted data traffic into multiple VPN tunnels, each carrying specific data types. This segmentation allows the system to manage and prioritize different data flows independently, preventing resource exhaustion from affecting all connections simultaneously while maintaining efficient utilization of available communication capacity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes routing parameters by modifying filter configurations to redirect specific data types between different VPN tunnels and EPS bearers. This parameter change capability enables adaptive resource allocation during heavy traffic conditions, maintaining reliability by rerouting critical data around congested paths.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If data transmission is limited during crisis situations, then congestion is reduced, but security services cannot identify data types due to encryption

Engineering Contradiction:
Improvecongestion controlVSAvoiddata type identification
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary routing decisions at the point of data generation, where the mobile application's routing function classifies and directs different data types into appropriate VPN tunnels before encryption occurs. This preliminary action enables congestion control based on data type while maintaining encryption, as the routing classification happens at the application layer rather than requiring decryption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary routing function that operates between the application layer and the encrypted transmission layer. This intermediary classifies data types and applies appropriate routing rules without requiring decryption, enabling congestion control while preserving security. The intermediary translates application-level data type information into network-level routing decisions.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secured connections are dropped to manage congestion, then resource exhaustion is prevented, but control over data transmission types is lost

Engineering Contradiction:
Improveresource managementVSAvoiddata transmission control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic filter configuration that can be modified in real-time based on network conditions and service requirements. When congestion occurs, the system dynamically adjusts which data types are routed through which VPN tunnels, allowing selective dropping or prioritization of specific data types while maintaining control. This dynamic adaptability enables resource management without losing data transmission control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The routing function serves multiple purposes: it classifies data types, applies routing rules, manages congestion, and maintains security policies all within a single unified mechanism. This multi-functionality allows the system to drop or prioritize connections based on data type while maintaining comprehensive control, rather than requiring separate mechanisms for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3729907B1Tunnel filtering system and method
Publication Date: 2025.04.16 RADIO IP SOFTWARE INC
  • EP3729907B1 patent drawingFigure 1
  • EP3729907B1 patent drawingFigure 2A
  • EP3729907B1 patent drawingFigure 2B

AI summary

A tunnel filtering system, method and process is provided for use in support of a mobile network. An EPS session comprising a default EPS bearer and a plurality of dedicated EPS bearers interconnects a mobile device/User Equipment (UE)and a network gateway via a wireless radio connection. The session comprises a default EPS bearer and a plurality of dedicated EPS bearers. A VPN client on the UE is interconnected with a VPN gateway connected to the public network using a plurality of VPN tunnels. Data transmission via one of the tunnels is supported by an associated one of the bearers. Filters shared between a first routing function in the UE and a second routing function in the VPN gateway are used by the routing functions to direct a particular data type to a specified one of the tunnels. The filters may be modified such that a particular data type uses a different specified one of the tunnels.