IP Library › Granted Patent US 12,414,001
Granted Patent B2
US 12,414,001 · App. 18/417,892 · Granted Sep 9, 2025

Method and apparatus for network traffic management

Inventors: Uday Trivedi (Bangalore, IN); Raviraj Bhat (Bangalore, IN); Ajith Kumar Kuppan (Bangalore, IN)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
H04W28/0215H04L41/16H04L47/2483H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,414,001
App. No.
18/417,892
Granted
Sep 9, 2025
Kind
B2
Abstract

The present disclosure relates to field of telecommunication network and discloses method and apparatus e.g., network entity for network traffic management. The network entity may be associated with a Deep Packet Inspection System (DPI), the network entity receives an encrypted Quick User Datagram Protocol (UDP) Internet Connection (QUIC) data packet flow from a source. Further, network entity predicts using an Artificial Intelligence (AI) model, a relevancy of decryption for an encrypted QUIC initial handshake packet of the QUIC data packet flow based on at least one of pre-stored User Equipment (UE) context parameters, pre-stored server context parameters and flow context parameters of the encrypted QUIC data packet flow. The network entity decrypts the encrypted QUIC initial handshake packet based on the relevancy of the decryption being predicted to be useful. The present disclosure helps to optimize Deep Packet Inspection (DPI) operation.

Claims (42)

1. A method performed by a network entity for network traffic management, the method comprising:

receiving an encrypted Quick User Datagram Protocol (UDP) Internet Connection (QUIC) data packet flow from a source;

predicting using an Artificial Intelligence (AI) model, whether a server name identifier (SNI) in an encrypted QUIC initial handshake packet of the QUIC data packet flow is matched with one or more stored signatures based on at least one of stored User Equipment (UE) context parameters, stored server context parameters and flow context parameters of the encrypted QUIC data packet flow; and

decrypting the encrypted QUIC initial handshake packet based on predicting that the SNI is matched with the one or more stored signatures.

2. The method as claimed in claim 1 , wherein the stored UE context parameters comprise at least one of a UE Internet Protocol (IP) address, total number of QUIC data packet flows related to the UE in a first specified time, total number of useful QUIC data packet flows among the total number of QUIC data packet flows related to the UE in the first specified time and a QUIC Usefulness Indicator (QUI) value indicating usefulness of the QUIC data packet flow for Deep Packet Inspection (DPI) application detection.

3. The method as claimed in claim 2 , wherein the QUI value is determined based on number of QUIC data packet flows of a specific application for a UE in a current time cycle, total number of the QUIC data packet flows identified for the specific application in the current time cycle and probability of receiving a new QUIC data packet flow for the specific application.

4. The method as claimed in claim 1 , wherein the stored server context parameters comprise at least one of a server Internet Protocol (IP) address, total number of QUIC data packet flows related to the server in a second specified time and total number of useful QUIC data packet flows among the total number of QUIC data packet flows related to the server in the second specified time.

5. The method as claimed in claim 1 , wherein the stored UE context parameters and the stored server context parameters are updated upon receiving each QUIC data packet flow and at specified time intervals.

6. The method as claimed in claim 1 , wherein the flow context parameters are extracted from the QUIC data packet flow received from the source, wherein the flow context parameters comprise one or more packet features comprising at least one of a server Internet Protocol (IP) address, server port number, UE IP address, UE port number and packet bytes in the encrypted QUIC initial handshake packet.

7. The method as claimed in claim 1 , wherein decrypting the encrypted QUIC initial handshake packet comprises:

decrypting the SNI from an encrypted content in the encrypted QUIC initial handshake packet.

8. The method as claimed in claim 1 , further comprising:

verifying correctness of the prediction related to a relevancy of the decryption based on a comparison of the SNI with the one or more stored signatures; and

updating the stored UE context parameters, and the stored server context parameters based on the verification.

9. The method as claimed in claim 1 , further comprising:

forwarding the QUIC data packet flow to one or more processing engines, without decrypting, for performing one or more operations based on predicting that the SNI is not matched with the one or more stored signatures; and

updating the stored UE context parameters, and the stored server context parameters upon forwarding the QUIC data packet flow.

10. The method as claimed in claim 1 , wherein the source comprises at least one of a UE and a server.

11. The method as claimed in claim 1 , wherein the encrypted QUIC initial handshake packet is a first packet in the QUIC data packet flow used to establish a connection.

12. A network entity for network traffic management, comprising:

at least one processor comprising processing circuitry; and

a memory storing instructions,

wherein the instructions, executed by the at least one processor individually or collectively, cause the network entity to:

receive an encrypted Quick User Datagram Protocol (UDP) Internet Connection (QUIC) data packet flow from a source;

predict using an Artificial Intelligence (AI) model whether a sever name identifier (SNI) in an encrypted QUIC initial handshake packet of the QUIC data packet flow is matched with one or more stored signatures based on at least one of stored User Equipment (UE) context parameters, stored server context parameters and flow context parameters of the encrypted QUIC data packet flow; and

decrypt the encrypted QUIC initial handshake packet based on predicting that the SNI is matched with the one or more stored signatures.

13. The network entity as claimed in claim 12 , wherein the instructions, executed by the at least one processor individually or collectively, cause the network entity to:

decrypt the SNI from an encrypted content in the encrypted QUIC initial handshake packet.

14. The network entity as claimed in claim 12 , wherein the instructions, executed by the at least one processor individually or collectively, cause the network entity to:

verify correctness of the prediction related to a relevancy of the decryption based on a comparison of the SNI with the one or more stored signatures; and

update the stored UE context parameters, and the stored server context parameters based on the verification.

15. The network entity as claimed in claim 12 , wherein the instructions, executed by the at least one processor individually or collectively, cause the network entity to:

forward the QUIC data packet flow to one or more processing engines, without decrypting, for performing one or more operations based on predicting that the SNI is not matched with the one or more stored signatures; and

update the stored UE context parameters, and the stored server context parameters upon forwarding the QUIC data packet flow.

16. The network entity as claimed in claim 12 , wherein the stored UE context parameters comprise at least one of a UE Internet Protocol (IP) address, total number of QUIC data packet flows related to the UE in a first specified time, total number of useful QUIC data packet flows among the total number of QUIC data packet flows related to the UE in the first specified time and a QUIC Usefulness Indicator (QUI) value indicating usefulness of the QUIC data packet flow for Deep Packet Inspection (DPI) application detection.

17. The network entity as claimed in claim 16 , wherein the QUI value is determined based on number of QUIC data packet flows of a specific application for a UE in a current time cycle, total number of the QUIC data packet flows identified for the specific application in the current time cycle and probability of receiving a new QUIC data packet flow for the specific application.

18. The network entity as claimed in claim 12 , wherein the stored server context parameters comprise at least one of a server Internet Protocol (IP) address, total number of QUIC data packet flows related to the server in a second specified time and total number of useful QUIC data packet flows among the total number of QUIC data packet flows related to the server in the second specified time.

19. The network entity as claimed in claim 12 , wherein the flow context parameters are extracted from the QUIC data packet flow received from the source, wherein the flow context parameters comprise one or more packet features comprising at least one of a server Internet Protocol (IP) address, server port number, UE IP address, UE port number and packet bytes in the encrypted QUIC initial handshake packet.

20. A non-transitory computer-readable storage medium, when executed by at least one processor of a network entity, stores one or more programs including instructions that cause to:

receive an encrypted Quick User Datagram Protocol (UDP) Internet Connection (QUIC) data packet flow from a source;

predict using an Artificial Intelligence (AI) model whether a sever name identifier (SNI) in an encrypted QUIC initial handshake packet of the QUIC data packet flow is matched with one or more stored signatures based on at least one of stored User Equipment (UE) context parameters, stored server context parameters and flow context parameters of the encrypted QUIC data packet flow; and

decrypt the encrypted QUIC initial handshake packet based on predicting that the SNI is matched with the one or more stored signatures.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2024
From: TRIVEDI, UDAY; BHAT, RAVIRAJ; KUPPAN, AJITH KUMAR
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 066187/0770 →
Priority Claims (2)
IN 202341028351 · Apr 18, 2023 · national
IN 202341028351 · Sep 28, 2023 · national
Continuity (2)
Continuation PCTKR2023022007 · Dec 29, 2023
Related Publication 20240357410A1 · Oct 24, 2024
References Cited (23)
US 9930057B2 · Di Pietro · 2018 [cited by applicant]
US 11894994B2 · Newell · 2024 [cited by applicant]
US 20180062950A1 · Baldi et al. · 2018 [cited by applicant]
US 20200067954A1 · Plonka · 2020 [cited by examiner]
US 20200274815A1 · Sreevalsan · 2020 [cited by examiner]
US 20200287888A1 · Moore · 2020 [cited by examiner]
US 20210021641A1 · Anderson · 2021 [cited by examiner]
US 20210044572A1 · Liu · 2021 [cited by examiner]
US 20210204152A1 · Vasudevan · 2021 [cited by examiner]
US 20210266310A1 · Moore et al. · 2021 [cited by applicant]
US 20220078208A1 · Anderson · 2022 [cited by examiner]
US 20220150143A1 · Liu · 2022 [cited by examiner]
US 20230328514A1 · Muñoz De La Torre Alonso · 2023 [cited by examiner]
US 20240380727A1 · Gomez-Hidalgo Perez · 2024 [cited by examiner]
CN 101841440 · 2012 [cited by applicant]
CN 111917694 · 2020 [cited by applicant]
CN 110311829 · 2021 [cited by applicant]
CN 113518042A · 2021 [cited by applicant]
CN 114679314A · 2022 [cited by applicant]
WO 2022026466 · 2022 [cited by applicant]
WO 2022058038 · 2022 [cited by applicant]
Search Report and Written Opinion dated Apr. 17, 2024 issued in International Patent Application No. PCT/KR2023/022007. [cited by applicant]
Saha et al., “Predicting Potentially Undetectable Flows in DPI System using Machine Learning”, IEEE, 2021, 6 pages. [cited by applicant]