IP Library Granted Patent US 12,432,254
Granted Patent B2
US 12,432,254 · App. 18/154,298 · Granted Sep 30, 2025

Header enrichment for hypertext transfer protocol secure

Inventors: Zhijun Li (Shenzhen, CN); Yuanjun Sun (Shenzhen, CN)
Assignee: ZTE Corporation
H04L63/168H04L67/02H04L69/22H04L63/0236H04L63/166
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,254
App. No.
18/154,298
Granted
Sep 30, 2025
Kind
B2
Abstract

Methods, apparatus, and systems for enhancing the CP Function and UP Function to support the header enrichment for HTTPS are disclosed. In one example aspect, the method includes transmitting, by a first communication component, to a second communication component, a session message instructing the second communication component to detect one or more messages from a user device based on a communication security protocol, wherein the session message includes detection information for the communication security protocol.

Claims (38)

1. A data communication method, comprising:

transmitting, by a first communication component, to a second communication component, a session message instructing the second communication component to perform operations comprising:

detecting a handshake message from a user device based on a communication security protocol, wherein the communication security protocol comprising at least one of secure sockets layer (SSL), transport layer security (TLS), or hypertext transfer protocol secure (HTTPS);

identifying, based on the session message, at least one header field name and a corresponding value;

inserting, into the handshake message, the at least one header field name and a corresponding value as an additional extension for the communication security protocol; and

forwarding, to a server, a modified handshake message that includes the additional extension,

wherein the session message includes detection information indicating use of the communication security protocol and header enrichment information including the at least one header field name and the corresponding value.

2. The method of claim 1 , wherein the detection information includes an indication for at least one of transport layer security (TLS) or hypertext transfer protocol secure (HTTPS) in at least one of a packet detection rule or a service data flow filter.

3. The method of claim 1 , wherein the detection information includes at least one of a well-known port for an SSL or TLS protocol in a service data flow filter, or a pre-configured port for SSL or TLS protocol in the service data flow filter known by the first and second communication components.

4. The method of claim 1 , wherein the header enrichment information includes a header type of a header enrichment information element set to a value corresponding to at least one of TLS, SSL/TLS, or HTTPS.

5. The method of claim 1 , wherein the header enrichment information includes header field names and values to be inserted into the handshake message from the user device.

6. The method of claim 1 , further comprising:

receiving, by the first communication component, a trigger entity of a packet data network connection establish request or a packet data unit session establishment request; and

transmitting, by the first communication component, a packet data network connection establishment response or a packet data unit session establishment response.

7. A data communication method, comprising:

receiving, by a second communication component, from a first communication component, a session message including detection information indicating use of a communication security protocol that includes at least one of secure sockets layer (SSL), transport layer security (TLS), or hypertext transfer protocol secure (HTTPS), and header enrichment information including at least one header field name and a corresponding value;

detecting, by the second communication component, a handshake message from a user device based on the communication security protocol;

identifying, from the session message, the at least one header field name and the corresponding value;

inserting, by the second communication component, into the handshake message, the at least one header field name and the corresponding value as an additional extension for the communication security protocol; and

forwarding, to a server, a modified handshake message that includes the additional extension.

8. The method of claim 7 , wherein the detection information includes an indication for at least one of transport layer security (TLS) or hypertext transfer protocol secure (HTTPS) in at least one of a packet detection rule or a service data flow filter.

9. The method of claim 7 , wherein the detection information includes at least one of a well-known port for an SSL or TLS protocol in a service data flow filter, or a pre-configured port for SSL or TLS protocol in the service data flow filter known by the first and second communication components.

10. The method of claim 7 , wherein the detecting the handshake message from a user device based on the detection information includes:

determining whether a destination port matches a well-known port for secure sockets layer (SSL) or transport layer security (TLS) protocol; and

determining, upon determination that the destination port matches the well-known port for the SSL or TLS protocol, that a current service data flow uses the SSL or TLS protocol.

11. The method of claim 7 , wherein the detection information includes a header type of a header enrichment information element set to a value corresponding to at least one of TLS, SSL/TLS, or HTTPS.

12. The method of claim 7 , further comprising parsing encapsulated SSL or TLS packets of the handshake message.

13. The method of claim 7 , further comprising, upon receiving a packet forwarding control protocol (PFCP) session establishment request from the first communication component, installing, by the second communication component, at least one of packet detection rule (PDR), QoS enforcement rule (QER), forwarding action rule (FAR), or usage reporting rule (URR).

14. A data communication method, comprising:

receiving, by a second communication component, from a first communication component, a session message that includes header enrichment information including at least one header field name and a corresponding value;

detecting, by the second communication component, a handshake message from a user device based on a communication security protocol that includes at least one of secure sockets layer (SSL), transport layer security (TLS), or hypertext transfer protocol secure (HTTPS);

inserting, by the second communication component, into the handshake message, the at least one header field name and the corresponding value as an additional extension for the communication security protocol; and

forwarding, to a server, a modified handshake message that includes the additional extension.

15. The method of claim 14 , wherein the header enrichment information includes a header type of a header enrichment information element set to a value corresponding to at least one of TLS, SSL/TLS, or HTTPS.

16. The method of claim 14 , wherein the header enrichment information includes one or more header field names and values to be inserted into the message.

17. The method of claim 14 , wherein the inserting the at least one header field name and a corresponding value into the handshake message comprises:

detecting one or more uplink IP packets from the user device are secure sockets layer (SSL) or transport layer security (TLS) packets carrying an SSL or TLS handshake message; and

inserting an additional SSL or TLS extension to the SSL or TLS handshake message while placing the one or more header field names and values indicated by the header enrichment information in the inserted additional SSL or TLS extension.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 13, 2023
From: LI, ZHIJUN; SUN, YUANJUN
To: ZTE CORPORATION
Reel/Frame 062371/0382 →
Continuity (2)
Continuation PCTCN2020102908 · Jul 20, 2020
Related Publication 20230164186A1 · May 25, 2023
References Cited (30)
US 7743245B2 · Khosravi · 2010 [cited by examiner]
US 8982893B2 · Akhtar · 2015 [cited by examiner]
US 10171548B2 · Kant · 2019 [cited by examiner]
US 10425446B2 · Kasbekar · 2019 [cited by examiner]
US 10554718B2 · Uppili et al. · 2020 [cited by applicant]
US 10880729B2 · Shlomo · 2020 [cited by examiner]
US 10931715B2 · Kasbekar · 2021 [cited by examiner]
US 11004106B2 · Neumann · 2021 [cited by examiner]
US 11848961B2 · Kasbekar · 2023 [cited by examiner]
US 20130024523A1 · Albasheir · 2013 [cited by examiner]
US 20140143855A1 · Keoh · 2014 [cited by examiner]
US 20140304498A1 · Gonuguntla · 2014 [cited by examiner]
US 20160094581A1 · Kasbekar · 2016 [cited by examiner]
US 20160119788A1 · Mandyam · 2016 [cited by examiner]
US 20190116535A1 · Szilagyi · 2019 [cited by examiner]
US 20200021614A1 · Kasbekar · 2020 [cited by examiner]
US 20200336321A1 · Ding · 2020 [cited by examiner]
US 20200404497A1 · Yuan · 2020 [cited by examiner]
US 20220086691A1 · Ihlar · 2022 [cited by examiner]
US 20230164186A1 · Li · 2023 [cited by examiner]
CN 105939317A · 2016 [cited by applicant]
CN 107077432A · 2017 [cited by applicant]
CN 110234112A · 2019 [cited by applicant]
CN 110858834A · 2020 [cited by applicant]
Nokia et al., “Packet Detection Information,” 3GPP TSG CT Meeting #78, CP-173145, Lisbon, Portugal, Dec. 18-19, 2017 (18 pages). [cited by applicant]
ZTE, “Header Enrichment,” 3GPP TSG CT WG4 Meeting #86bis, C4-187052, Vilnius, Republic of Lithuania, Oct. 15-19, 2018 (2 pages). [cited by applicant]
International Search Report and Written Opinion for International Application No. PCT/CN2020/102908, mailed on Mar. 25, 2021 (9 pages). [cited by applicant]
3GPP, “Technical Specification Group Services and System Aspects; Study on encrypted traffic detection and verification (Release 16),” 3GPP TR 23.787 V0.3.0 (Apr. 2018), 38 pages. [cited by applicant]
Office Action for Chinese Patent Application No. 202080102813.5, mailed Oct. 30, 2024 (53 pages). [cited by applicant]
CNIPA, Second Office Action for Chinese Application No. 202080102813.5, mailed on May 9, 2025, 54 pages with unofficial English translation. [cited by applicant]