Technique for enabling exposure of information related to encrypted communication
A technique for enabling exposure of information related to encrypted communication between a User Equipment, UE, and an application server in a mobile communication system is disclosed. A method implementation of the technique is performed by the UE and comprises establishing (S 302 ) a communication channel with a network node of the mobile communication system, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in the communication between the UE and the application server, and sending (S 304 ) encrypted traffic through the communication channel to the network node for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node.
1 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the method being performed by the UE and comprising:
establishing a communication channel with a network node of the mobile communication system, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and
sending encrypted traffic through the communication channel to the network node for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.
2 . The method of claim 1 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.
3 . The method of claim 1 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.
4 . The method of claim 2 , wherein the application identifier is communicated from the UE to the network node together with the encrypted traffic.
5 . The method of claim 1 , further comprising receiving a network address indicative of the network node acting as application layer proxy, wherein establishing the communication channel with the network node is performed using the network address.
6 . The method of claim 5 , wherein the network address is provided by a control plane node of the mobile communication system, as part of a data session establishment procedure carried out in the mobile communication system for the UE.
7 . The method of claim 5 wherein the network address is obtained from a Domain Name System (DNS) service, wherein a Fully Qualified Domain Name (FQDN) of the network node acting as application layer proxy is pre-provisioned as part of a Service Level Agreement (SLA).
8 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the method being performed by a network node of the mobile communication system and comprising:
establishing, upon request of the UE, a communication channel with the UE, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and
receiving encrypted traffic through the communication channel from the UE for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.
9 . The method of claim 8 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.
10 . The method of claim 9 , further comprising using the application identifier to classify the encrypted traffic, for an enforcement of policy rules defined for the communication between the UE and the application server.
11 . The method of claim 8 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.
12 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the mobile communication system comprising a network node configured to act as application layer proxy in the communication between the UE and the application server when a communication channel is established as part of an application layer communication channel between the UE and the application server, the communication channel being used to communicate encrypted traffic from the UE to the network node for further delivery to the application server, and the communication channel being used to exchange supplemental information related to the encrypted traffic between the UE and the network node, the method being performed by a first control plane node of the mobile communication system and comprising:
receiving a capability indication from the network node for use in selecting a network node acting as application layer proxy for the communication between the UE and the application server, the capability indication indicating that the network node supports acting as application layer proxy, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.
13 . A method for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in a mobile communication system, the mobile communication system comprising a network node configured to act as application layer proxy in the communication between the UE and the application server when a communication channel is established as part of an application layer communication channel between the UE and the application server, the communication channel being used to communicate encrypted traffic from the UE to the network node for further delivery to the application server, and the communication channel being used to exchange supplemental information related to the encrypted traffic between the UE and the network node, the method being performed by a second control plane node of the mobile communication system and comprising:
providing, to a first control plane node, an indication of a requirement that a network node handling the communication between the UE and the application server is to support acting as application layer proxy, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.
14 . A User Equipment (UE) for enabling exposure of information related to encrypted communication between the UE and an application server in a mobile communication system, the UE comprising:
at least one processor; and
at least one memory, the at least one memory containing instructions executable by the at least one processor such that the UE is operable to:
establish a communication channel with a network node of the mobile communication system, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and
send encrypted traffic through the communication channel to the network node for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.
15 . The UE of claim 14 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.
16 . The UE of claim 14 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.
17 . The UE of claim 15 , wherein the application identifier is communicated from the UE to the network node together with the encrypted traffic.
18 . The UE of claim 14 , the at least one memory containing instructions executable by the at least one processor such that the UE is operable to receive a network address indicative of the network node acting as application layer proxy, and to establish the communication channel with the network node using the network address.
19 . The UE of claim 18 , wherein the network address is provided by a control plane node of the mobile communication system, as part of a data session establishment procedure carried out in the mobile communication system for the UE.
20 . The UE of claim 18 , wherein the network address is obtained from a Domain Name System (DNS) service, wherein a Fully Qualified Domain Name (FQDN) of the network node acting as application layer proxy is pre-provisioned as part of a Service Level Agreement (SLA).
21 . A computing unit configured to execute a network node of a mobile communication system for enabling exposure of information related to encrypted communication between a User Equipment (UE) and an application server in the mobile communication system, the computing unit comprising:
at least one processor; and
at least one memory, the at least one memory containing instructions executable by the at least one processor such that the network node is operable to:
establish, upon request of the UE, a communication channel with the UE, the communication channel being established as part of an application layer communication channel between the UE and the application server, wherein the network node acts as application layer proxy in communication between the UE and the application server; and
receive encrypted traffic through the communication channel from the UE for further delivery to the application server, wherein the communication channel is used to exchange supplemental information related to the encrypted traffic between the UE and the network node, wherein the encrypted traffic corresponds to QUIC protocol based traffic exchanged between the UE and the application server, wherein the supplemental information comprises information indicating one or more QUIC connections which are associated with an application identifier indicating an application which originates the encrypted traffic on the UE.
22 . The computing unit of claim 21 , wherein the supplemental information comprises the application identifier communicated from the UE to the network node.
23 . The computing unit of claim 22 , the at least one memory containing instructions executable by the at least one processor such that the network node is operable to use the application identifier to classify the encrypted traffic, for an enforcement of policy rules defined for the communication between the UE and the application server.
24 . The computing unit of claim 21 , wherein the encrypted traffic is communicated as part of one of a plurality of application sessions, wherein encrypted traffic of each of the plurality of application sessions is sent through the communication channel, wherein the encrypted traffic of each of the plurality of application sessions is sent over a same data session established by the mobile communication system for the UE.
25 . The computing unit of claim 21 , the at least one memory containing instructions executable by the at least one processor such that the network node is operable to:
send, prior to establishing the communication channel, a capability indication to a control plane node of the mobile communication system for use in selecting a network node acting as application layer proxy for the communication between the UE and the application server, the capability indication indicating that the network node supports acting as application layer proxy; or
provide, prior to establishing the communication channel, a network address indicative of the network node acting as application layer proxy to a control plane node of the mobile communication network.
26 . The method of claim 1 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the method further comprises using the communication channel to exchange the supplemental information between the application client and the network node at the application layer.
27 . The method of claim 8 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the method further comprises using the communication channel to exchange the supplemental information between the application client and the network node at the application layer.
28 . The UE of claim 14 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the at least one memory contains instructions executable by the at least one processor such that the UE is further operable to use the communication channel to exchange the supplemental information between the application client and the network node at the application layer.
29 . The computing unit of claim 21 , wherein the application layer communication channel is between an application client running on the UE and the application server at an application layer of a communication protocol stack, wherein the communication channel is established, as a first part of the application layer communication channel, between the application client and the network node at the application layer, wherein a second part of the application layer communication channel is established between the network node and the application server at the application layer, and wherein the at least one memory contains instructions executable by the at least one processor such that the network node is further operable to use the communication channel to exchange the supplemental information between the application client and the network node at the application layer.