IP Library › Granted Patent US 12,388,803
Granted Patent B2
US 12,388,803 · App. 18/280,070 · Granted Aug 12, 2025

Traffic management with asymmetric traffic encryption in 5G networks

Inventors: Miguel Angel Puente Pestaña (Madrid, ES); Antonio Cañete Martinez (Madrid, ES); Miguel Angel Muñoz De La Torre Alonso (Madrid, ES)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04L63/0442H04W12/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,388,803
App. No.
18/280,070
Filed
Sep 1, 2023
Granted
Aug 12, 2025
Kind
B2
Art Unit
2497
USPC
713/168
Abstract

A network operator node ( 17 ) is provided. The network operator node ( 17 ) includes processing circuitry ( 42 ) configured to receive data traffic that is encrypted using one of an uplink and downlink public cryptographic key, decrypt the data traffic using one of an uplink and downlink private cryptographic key, apply at least a first traffic management action to the decrypted data traffic, after applying at least the first traffic management action, encrypt the data traffic using one of an application server, AS, public cryptographic key and an application client, AC, public cryptographic key where the AS public cryptographic key is associated with an AS private cryptographic key that remains unshared with the network operator node ( 17 ), and the AC public cryptographic key is associated with an AC private cryptographic key that remains unshared with the network operator node ( 17 ).

Claims (44)

1. A network operator node configured to communicate with a wireless device, the network operator node comprising: processing circuitry configured to:

share an uplink public cryptographic key and a downlink public cryptographic key with a content provider node, the uplink public cryptographic key being associated with an uplink private cryptographic key, the downlink public cryptographic key being associated with a downlink private cryptographic key;

receive data traffic that is encrypted using one of the uplink public cryptographic key and the downlink public cryptographic key;

decrypt the data traffic using one of the uplink public cryptographic key and the downlink private cryptographic key;

apply at least a first traffic management action to the decrypted data traffic;

after applying at least the first traffic management action, encrypt the data traffic using one of an application server, AS, the public cryptographic key and an application client, AC, public cryptographic key, the AS public cryptographic key being associated with an AS private cryptographic key that remains unshared with the network operator node, the AC public cryptographic key being associated with an AC private cryptographic key that remains unshared with the network operator node; and

cause transmission of the data traffic that is encrypted by one of the AS public cryptographic key and AC public cryptographic key.

2. The network operator node of claim 1 , wherein at least the first traffic management action is configured for the wireless device for a predefined software application.

3. The network operator node of claim 2 , wherein at least the first traffic management action includes modifying at least one of a property and content associated with the data traffic.

4. The network operator node of claim 2 , wherein at least the first traffic management action includes at least one of content enrichment, parental control and redirection, content filtering and application-based charging and monitoring.

5. The network operator node of claim 1 , wherein the processing circuitry is further configured to receive, from the content provider node, a request for public cryptographic keys for performing at least the first traffic management action, the sharing of the uplink public cryptographic key and downlink public cryptographic key being performed based at least in part on the request for public cryptographic keys.

6. The network operator node of claim 5 , wherein the processing circuitry is further configured to receive, from the content provider node, a request requiring the network operator node to apply at least the first traffic management action, the request including the AS, cryptographic public key and the AC public cryptographic key.

7. The network operator node of claim 6 , wherein the request to apply at least the first traffic management action is received after the request for the public cryptographic keys.

8. The network operator node of claim 1 , wherein the processing circuitry is further configured to receive an onboarding request from the content provider node, the sharing of the uplink public cryptographic key and downlink public cryptographic key being performed based at least in part on the received onboarding request.

9. A user plane function, UPF, node, that is part of a network operator node and configured to communicate with a wireless device, the UPF node comprising:

processing circuitry configured to:

receive an uplink private cryptographic key and a downlink private cryptographic key from a key generation and store entity, the uplink private cryptographic key being associated with an uplink public cryptographic key, the downlink private cryptographic key being associated with a downlink public cryptographic key;

receive data traffic that is encrypted using one of the uplink public cryptographic key and the downlink public cryptographic key;

decrypt the data traffic using one of the uplink public cryptographic key and the downlink private cryptographic key;

apply at least a first traffic management action to the decrypted data traffic;

after applying at least the first traffic management action, encrypt the data traffic using one of an application server, AS, public cryptographic key and an application client, AC, public cryptographic key that is shared with a content provider node, the AS public cryptographic key being associated with an AS private cryptographic key that is remains unshared with the network operator node, the AC public cryptographic key being associated with an AC private cryptographic key that remains unshared with the network operator node; and

cause transmission of the data traffic that is encrypted by one of the AS public cryptographic key and the AC public cryptographic key.

10. The UPF node of claim 9 , wherein at least the first traffic management action is configured for the wireless device for a predefined software application.

11. A method implemented by a network operator node that is configured to communicate with a wireless device, the method comprising:

sharing an uplink public cryptographic key and a downlink public cryptographic key with a content provider node, the uplink public cryptographic key being associated with an uplink private cryptographic key, the downlink public cryptographic key being associated with a downlink private cryptographic key;

receiving data traffic that is encrypted using one of the uplink downlink public cryptographic key and the downlink public cryptographic key;

decrypting the data traffic using one of the uplink downlink public cryptographic key and the downlink private cryptographic key;

applying at least a first traffic management action to the decrypted data traffic;

after applying at least the first traffic management action, encrypting the data traffic using one of an application server, AS, public cryptographic key and application client, AC, public cryptographic key, the AS public cryptographic key being associated with an AS private cryptographic key that remains unshared with the network operator node, the AC public cryptographic key being associated with an AC private cryptographic key that remains unshared with the network operator node; and

causing transmission of the data traffic that is encrypted by one of the AS public cryptographic key and the AC public cryptographic key.

12. The method of claim 11 , wherein at least the first traffic management action is configured for the wireless device for a predefined software application.

13. The method of claim 12 , wherein at least the first traffic management action includes modifying at least one of a property and content associated with the data traffic.

14. The method of claim 12 , wherein at least the first traffic management action includes at least one of content enrichment, parental control and redirection, content filtering and application-based charging and monitoring.

15. The method of claim 11 , further comprising receiving, from the content provider node, a request for public cryptographic keys for performing at least the first traffic management action, the sharing of the uplink public cryptographic key and the downlink public cryptographic key being performed based at least in part on the request for public cryptographic keys.

16. The method of claim 15 , further comprising receiving, from the content provider node, a request requiring the network operator node to apply at least the first traffic management action, the request including the AS cryptographic public key and the AC public cryptographic key.

17. The method of claim 16 , wherein the request to apply at least the first traffic management action is received after the request for the public cryptographic keys.

18. A method implemented by a user plane function, UPF, node, that is part of a network operator node and configured to communicate with a wireless device, the method comprising:

receiving an uplink private cryptographic key and a downlink private cryptographic key from a key generation and store entity, the uplink private cryptographic key being associated with an uplink public cryptographic key, the downlink private cryptographic key being associated with a downlink public cryptographic key;

receiving data traffic that is encrypted using one of the uplink public cryptographic key and the downlink public cryptographic key;

decrypting the data traffic using one of the uplink public cryptographic key and the downlink private cryptographic key;

applying at least a first traffic management action to the decrypted data traffic;

after applying at least the first traffic management action, encrypting the data traffic using one of an application server, AS, public cryptographic key and an application client, AC, public cryptographic key that is shared with a content provider node, the AS public cryptographic key being associated with an AS private cryptographic key that is remains unshared with the network operator node, the AC public cryptographic key being associated with an AC private cryptographic key that remains unshared with the network operator node; and

causing transmission of the data traffic that is encrypted by one of the AS public cryptographic key and AC public cryptographic key.

19. The method of claim 18 , wherein at least the first traffic management action is configured for the wireless device for a predefined software application.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2023
From: PUENTE PESTAÑA, MIGUEL ANGEL; CAÑETE MARTINEZ, ANTONIO; MUÑOZ DE LA TORRE ALONSO, MIGUEL ANGEL
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 064776/0553 →
Priority Claims (1)
EP 21382170 · Mar 1, 2021 · regional
Continuity (1)
Related Publication 20240146702A1 · May 2, 2024
References Cited (7)
US 20110154019A1 · Wang · 2011 [cited by applicant]
US 20230092245A1 · Saroiu · 2023 [cited by examiner]
US 20230396455A1 · Wane · 2023 [cited by examiner]
CN 110519750A · 2019 [cited by applicant]
CN 112153641A · 2020 [cited by applicant]
EP 3522473A1 · 2019 [cited by applicant]
3GPP TS 29.522 V16.5.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Exposure Function Northbound APIs; Stage 3 (Release 16)”, 3GPP TS 29.522 V16.5.0,… [cited by applicant]