UE Policy Provisioning Through User Plane for Encrypted QUIC Traffic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 3GPP systems lack an efficient mechanism for content providers to request and enforce policy rules for encrypted traffic, such as QUIC, due to the absence of direct communication channels and the reliance on complex Service Layer Agreements, leading to difficulties in network monitoring and optimization.

Innovation Solution

A method enabling User Equipment (UE) to directly send policy rules through a communication channel to a User Plane (UP) entity, allowing for the enforcement of these rules at the UP level, bypassing the need for extensive Control Plane signaling and supporting encrypted protocols like QUIC.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If policy rules are enforced through existing 3GPP Control Plane mechanisms, then policy management is standardized, but the process becomes complex and signaling-intensive

Engineering Contradiction:
Improvepolicy rule enforcementVSAvoidcontrol plane signaling
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Proxy Mobile Access Gateway (PMAG) as an intermediary node between the UE and the 5G core network. This PMAG acts as a mediator that receives policy rules from content providers and forwards them to the appropriate network functions, thereby simplifying the signaling path and reducing the complexity of direct Control Plane interactions while maintaining reliable policy enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the policy management function by separating the policy rule delivery mechanism from the traditional Control Plane signaling path. Policy rules are delivered through a dedicated data bearer established via the PMAG, independent from the control plane procedures, thus reducing signaling complexity while maintaining enforcement reliability

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If Service Layer Agreements are used for policy management, then content provider requirements are addressed, but the mechanism becomes inefficient and difficult to implement

Engineering Contradiction:
Improvecontent provider policy supportVSAvoidpolicy provisioning efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent enables content providers to directly provision policy rules through the PMAG without requiring complex Service Layer Agreement negotiations. The content provider's application server can autonomously send policy rules via HTTP requests to the PMAG, which then delivers them to the UE, creating a self-service mechanism that is both adaptable to content provider needs and efficient in implementation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The PMAG serves multiple functions: it acts as a proxy for encrypted traffic (including QUIC), a policy rule delivery point for content providers, and a signaling reduction mechanism. This multi-functionality allows a single node to address content provider requirements while improving overall system efficiency

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encrypted protocols like QUIC are used, then security and performance are improved, but network monitoring and policy enforcement become difficult

Engineering Contradiction:
Improveencrypted traffic securityVSAvoidnetwork monitoring
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The PMAG serves as a trusted intermediary that the UE explicitly contacts for encrypted traffic. Since the PMAG is part of the encryption handshake (via COPE mechanism), it can observe and classify traffic patterns, apply policies, and enable monitoring without breaking end-to-end encryption, thus maintaining security while enabling network visibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4173331B1Policy provisioning to a mobile communication system
Publication Date: 2025.08.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4173331B1 patent drawingFigure 1~2
  • EP4173331B1 patent drawingFigure 3
  • EP4173331B1 patent drawingFigure 4

AI summary

A method for providing a policy rule from a User Equipment to a mobile communication system. The method includes establishing a communication channel between the UE and a User Plane entity of the mobile communication system, sending the policy rule through the communication channel from the UE to the UP entity and receiving at the UE from the UP entity an indication of whether the policy rule is accepted or rejected. The UP entity may send the policy rule to a first Control Plane entity for authorization. In turn, the first CP entity may send the policy rule to a second Control Plane entity for authorization. The User Plane entity may be a User Plane Function including a Collaborative Performance Enhancement (COPE) entity.