User Equipment Tethering Policy for Encrypted Traffic Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless carriers face challenges in completely identifying and controlling tethering traffic, especially when traffic is encrypted, as existing solutions fail to detect and manage tethering effectively at the network side.

Innovation Solution

A method for enforcing tethering policies at User Equipment (UE) involves receiving and applying tethering policies from a Control Plane entity, including actions such as blocking, marking, or reporting tethered device traffic, which are not possible at the network side, enabling detection and control of tethering traffic at the UE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network gateways use fingerprinting techniques to identify tethering traffic, then tethering detection capability is improved, but detection completeness deteriorates when traffic is encrypted

Engineering Contradiction:
Improvetethering detection capabilityVSAvoiddetection completeness
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

Instead of having the network detect tethering traffic from the network side, the patent inverts the detection approach by enabling the UE to detect its own tethering traffic locally. The UE applies policies to mark tethered device traffic with specific values in protocol headers, allowing the network to identify marked traffic without needing to decrypt or analyze encrypted traffic patterns.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces traffic marking as an intermediary mechanism. The UE marks tethering traffic with specific values in protocol headers (such as IP options, DSCP codes, or other header fields), creating an intermediate identifier that the network can use to recognize and control tethering traffic without needing to inspect the actual encrypted payload.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If network gateways apply policies to tethering traffic, then traffic control capability is improved, but control effectiveness deteriorates for encrypted traffic

Engineering Contradiction:
Improvetraffic control capabilityVSAvoidcontrol effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by having the UE mark the tethering traffic before it reaches the network gateways. The UE receives policy information from the network, identifies tethering traffic locally, and marks it with specific values in advance. This preliminary marking ensures that when the marked traffic reaches the network, the gateways can effectively control it without needing to decrypt or analyze the traffic content.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the network monitors all traffic for tethering detection, then detection accuracy is improved, but network processing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoidnetwork processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the detection function from the network side and places it at the UE side. Instead of the network monitoring and analyzing all traffic to detect tethering, the UE itself performs the detection and marking of its own tethering traffic. This extraction significantly reduces the processing complexity and resource requirements at the network side, as the network only needs to recognize pre-marked traffic rather than analyzing unmarked traffic patterns.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP4179748B1User equipment tethering policy
Publication Date: 2025.10.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4179748B1 patent drawingFigure 1~2
  • EP4179748B1 patent drawingFigure 3~4
  • EP4179748B1 patent drawingFigure 5~7

AI summary

A method for enabling the detection of tethering traffic and the application of tethering policies to such traffic at a User Equipment (UE). The method comprises receiving subscription information at a policy control entity from a subscriber data repository entity, the subscription information including an indication of actions to apply to the traffic of tethered devices at the UE, transmitting from the policy control entity to the UE a tethering policy including the received actions to apply to the traffic of tethered devices, and applying at the UE the tethering policy to the traffic of a tethered device. The policy control entity may be a PCF. The subscriber data repository entity may be a UDR. The tethering policy may include an indication to block the tethering traffic, to mark the tethering traffic or to report information or events related to the tethering traffic and tethering devices.