IP Library › Granted Patent US 12,750,660
Granted Patent B2
US 12,750,660 · App. 18/032,863 · Granted Sep 29, 2026

Technique for enabling exposure of information related to encrypted communication

Inventors: Marcus Ihlar (Älvsjö, SE); Zaheduzzaman Sarker (Järfälla, SE); Veronica Sanchez Vega (Madrid, ES); Miguel Angel Muñoz De La Torre Alonso (Madrid, ES)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04W12/037
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,750,660
App. No.
18/032,863
Granted
Sep 29, 2026
Kind
B2
Abstract

A technique for enabling exposure of information related to encrypted communication between a User Equipment, UE, and an application server in a mobile communication system is disclosed. A method implementation of the technique is performed by the UE and comprises establishing (S 302 ) a communication channel with a network node of the mobile communication system, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in the communication between the UE and the application server, and sending (S 304 ) encrypted traffic through the communication channel to the network node for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node.

Claims (45)

1 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the method being performed by the UE and comprising:

establishing a communication channel with a network node of the mobile communication system, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and

sending encrypted traffic through the communication channel to the network node for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.

2 . The method of claim 1 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.

3 . The method of claim 1 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.

4 . The method of claim 2 , wherein the application identifier is communicated from the UE to the network node together with the encrypted traffic.

5 . The method of claim 1 , further comprising receiving a network address indicative of the network node acting as application layer proxy, wherein establishing the communication channel with the network node is performed using the network address.

6 . The method of claim 5 , wherein the network address is provided by a control plane node of the mobile communication system, as part of a data session establishment procedure carried out in the mobile communication system for the UE.

7 . The method of claim 5 wherein the network address is obtained from a Domain Name System (DNS) service, wherein a Fully Qualified Domain Name (FQDN) of the network node acting as application layer proxy is pre-provisioned as part of a Service Level Agreement (SLA).

8 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the method being performed by a network node of the mobile communication system and comprising:

establishing, upon request of the UE, a communication channel with the UE, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and

receiving encrypted traffic through the communication channel from the UE for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.

9 . The method of claim 8 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.

10 . The method of claim 9 , further comprising using the application identifier to classify the encrypted traffic, for an enforcement of policy rules defined for the communication between the UE and the application server.

11 . The method of claim 8 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.

12 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the mobile communication system comprising a network node configured to act as application layer proxy in the communication between the UE and the application server when a communication channel is established as part of an application layer communication channel between the UE and the application server, the communication channel being used to communicate encrypted traffic from the UE to the network node for further delivery to the application server, and the communication channel being used to exchange supplemental information related to the encrypted traffic between the UE and the network node, the method being performed by a first control plane node of the mobile communication system and comprising:

receiving a capability indication from the network node for use in selecting a network node acting as application layer proxy for the communication between the UE and the application server, the capability indication indicating that the network node supports acting as application layer proxy, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.

13 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the mobile communication system comprising a network node configured to act as application layer proxy in the communication between the UE and the application server when a communication channel is established as part of an application layer communication channel between the UE and the application server, the communication channel being used to communicate encrypted traffic from the UE to the network node for further delivery to the application server, and the communication channel being used to exchange supplemental information related to the encrypted traffic between the UE and the network node, the method being performed by a second control plane node of the mobile communication system and comprising:

providing, to a first control plane node, an indication of a requirement that a network node handling the communication between the UE and the application server is to support acting as application layer proxy, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.

14 . A User Equipment (UE) for enabling exposure of information related to encrypted communication between the UE and an application server in a mobile communication system, the UE comprising:

at least one processor; and

at least one memory, the at least one memory containing instructions executable by the at least one processor such that the UE is operable to:

establish a communication channel with a network node of the mobile communication system, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and

send encrypted traffic through the communication channel to the network node for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.

15 . The UE of claim 14 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.

16 . The UE of claim 14 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.

17 . The UE of claim 15 , wherein the application identifier is communicated from the UE to the network node together with the encrypted traffic.

18 . The UE of claim 14 , the at least one memory containing instructions executable by the at least one processor such that the UE is operable to receive a network address indicative of the network node acting as application layer proxy, and to establish the communication channel with the network node using the network address.

19 . The UE of claim 18 , wherein the network address is provided by a control plane node of the mobile communication system, as part of a data session establishment procedure carried out in the mobile communication system for the UE.

20 . The UE of claim 18 , wherein the network address is obtained from a Domain Name System (DNS) service, wherein a Fully Qualified Domain Name (FQDN) of the network node acting as application layer proxy is pre-provisioned as part of a Service Level Agreement (SLA).

21 . A computing unit configured to execute a network node of a mobile communication system for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in the mobile communication system, the computing unit comprising:

at least one processor; and

at least one memory, the at least one memory containing instructions executable by the at least one processor such that the network node is operable to:

establish, upon request of the UE, a communication channel with the UE, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and

receive encrypted traffic through the communication channel from the UE for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.

22 . The computing unit of claim 21 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.

23 . The computing unit of claim 22 , the at least one memory containing instructions executable by the at least one processor such that the network node is operable to use the application identifier to classify the encrypted traffic, for an enforcement of policy rules defined for the communication between the UE and the application server.

24 . The computing unit of claim 21 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.

25 . The computing unit of claim 21 , the at least one memory containing instructions executable by the at least one processor such that the network node is operable to:

send, prior to establishing the communication channel, a capability indication to a control plane node of the mobile communication system for use in selecting a network node acting as application layer proxy for the communication between the UE and the application server, the capability indication indicating that the network node supports acting as application layer proxy; or

provide, prior to establishing the communication channel, a network address indicative of the network node acting as application layer proxy to a control plane node of the mobile communication network.

26 . The method of claim 1 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the method further comprises using the communication channel to exchange the supplemental information between the application client and the network node at the application layer.

27 . The method of claim 8 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the method further comprises using the communication channel to exchange the supplemental information between the application client and the network node at the application layer.

28 . The UE of claim 14 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the at least one memory contains instructions executable by the at least one processor such that the UE is further operable to use the communication channel to exchange the supplemental information between the application client and the network node at the application layer.

29 . The computing unit of claim 21 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the at least one memory contains instructions executable by the at least one processor such that the network node is further operable to use the communication channel to exchange the supplemental information between the application client and the network node at the application layer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2023
From: IHLAR, MARCUS; SARKER, ZAHEDUZZAMAN; SANCHEZ VEGA, VERONICA; MUÑOZ DE LA TORRE ALONSO, MIGUEL ANGEL
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 063386/0846 →
Priority Claims (1)
EP 20382915 · Oct 20, 2020 · regional
Continuity (1)
Related Publication 20230388786A1 · Nov 30, 2023
References Cited (13)
US 9900313B2 · Wiest · 2018 [cited by examiner]
US 20170078922A1 · Raleigh · 2017 [cited by examiner]
US 20200169584A1 · Penner · 2020 [cited by examiner]
US 20200260284A1 · Salkintzis · 2020 [cited by examiner]
US 20210168665A1 · Salkintzis · 2021 [cited by examiner]
CN 111247821A · 2020 [cited by applicant]
Aghaei-Foroushani et al., “A Proxy Identifier Based on Patterns in Traffic Flows”, 2015 IEEE 16th International Symposium on High Assurance Systems Engineering, Date of Conference: Jan. 8-10, 2015. [cited by examiner]
2015. [cited by examiner]
Nalawade et al., “Comparison of Present-day Transport Layer network Protocols and Google's QUIC,” 2018 International Conference on Smart City and Emerging Technology (ICSCET), Mumbai, India, pp. 1-8 (Year: 2018). [cited by examiner]
3GPP, “3GPP TR 23.787 V0.4.0”, 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on encrypted traffic detection and verification (Release 16), Jun. 2018, 1-46. [cited by applicant]
Motorola Mobility, et al., “Update of UE-Assisted Solution”, SA WG2 Meeting #127, S2-184014, (revision of S2-183389), Sanya, P.R.China, Apr. 16-20, 2018, 1-12. [cited by applicant]
Qualcomm Incorporated, et al., “Alternative UE-assisted ENTRADE solution”, 3GPP TSG-WG2 Meeting #127, S2-184519, (revision of S2-173570), Sanya, China, Apr. 16-20, 2018, 1-8. [cited by applicant]
2GPP, “3GPP TS 29.244 V15.50”, 3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Interface between the Control Plane and the User Plane Nodes; Stage 3 (Release 15). [cited by applicant]