Secure identification of applications in communication network
Techniques for securely identifying applications in a communication network are disclosed. For example, a method comprises receiving, at user equipment, a data item associated with an application program that is installed or being installed on the user equipment. The method further comprises storing, by the user equipment, the data item with an identifier of the application program. The method still further comprises utilizing, by the user equipment, the stored data item when deciding to apply a route selection rule for data traffic associated with the application program.
1 . A user equipment comprising:
at least one processor and at least one memory storing instructions that, when executed by the at least one processor, cause the user equipment to perform operations, the operations comprising:
receiving, from a communication network, via a secure channel established between the user equipment and the communication network, a data item associated with an application program that is installed or being installed on the user equipment, wherein the data item comprises a secret;
storing the data item in association with an identifier of the application program;
receiving, from the communication network, a route selection rule for data traffic associated with the application program, the route selection rule comprising another data item, wherein the another data item comprises another secret; and
applying the route selection rule for data traffic associated with the application program when the secret matches the another secret; or
rejecting the route selection rule for data traffic associated with the application program when the secret does not match the another secret.
2 . The user equipment of claim 1 , wherein the data item comprising the secret is generated by: (i) an application server associated with the application program; or (ii) a network entity of a communication network connecting the user equipment and the application server.
3 . The user equipment of claim 1 , wherein the secret comprises a security token, wherein the security token is static or dynamic, and wherein the another secret comprises another security token that is static or dynamic.
4 . The user equipment of claim 1 , wherein the secret comprises a trust-based value, and wherein the another secret comprises another trust-based value.
5 . The user equipment of claim 4 , wherein the trust-based value is useable to compute a security token or a one-time pad.
6 . A method comprising:
receiving, at user equipment from a communication network via a secure channel established between the user equipment and the communication network, a data item associated with an application program that is installed or being installed on the user equipment, wherein the data item comprises a secret;
storing, by the user equipment, the data item in association with an identifier of the application program; and
receiving, by the user equipment from the communication network, a route selection rule for data traffic associated with the application program, the route selection rule comprising another data item, the another data item comprising another secret; and
applying, by the user equipment, the route selection rule for data traffic associated with the application program when the secret matches the another secret; or
rejecting, by the user equipment, the route selection rule for data traffic associated with the application program when the secret does not match the another secret.
7 . The method of claim 6 , wherein the data item comprising the secret is generated by: (i) an application server associated with the application program; or (ii) a network entity of a communication network connecting the user equipment and the application server.
8 . The method of claim 6 , wherein the secret comprises a security token, wherein the security token is static or dynamic, and wherein the another secret comprises another security token that is static or dynamic.
9 . The method of claim 6 , wherein the secret comprises a trust-based value, and wherein the another secret comprises another trust-based value.
10 . The method of claim 9 , wherein the trust-based value is useable to compute a security token or a one-time pad.