EP3485620A1 - Method for detecting and/or identifying data streams within a telecommunications network; system, telecommunications network, and content server entity for detecting and/or identifying data streams within a telecommunications network, program and computer program product - Google Patents
Method for detecting and/or identifying data streams within a telecommunications network; system, telecommunications network, and content server entity for detecting and/or identifying data streams within a telecommunications network, program and computer program productInfo
- Publication number
- EP3485620A1 EP3485620A1 EP17735454.5A EP17735454A EP3485620A1 EP 3485620 A1 EP3485620 A1 EP 3485620A1 EP 17735454 A EP17735454 A EP 17735454A EP 3485620 A1 EP3485620 A1 EP 3485620A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- information
- telecommunications network
- content server
- data
- data stream
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/80—Responding to QoS
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L65/00—Network arrangements, protocols or services for supporting real-time applications in data packet communication
- H04L65/60—Network streaming of media packets
- H04L65/75—Media network packet handling
- H04L65/765—Media network packet handling intermediate
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L67/00—Network arrangements or protocols for supporting network services or applications
- H04L67/50—Network services
- H04L67/60—Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources
- H04L67/61—Scheduling or organising the servicing of application requests, e.g. requests for application data transmissions using the analysis and optimisation of the required network resources taking into account QoS or priority requirements
Definitions
- the present invention relates to a method for detecting and/or identifying data streams within a telecommunications network, wherein a user equipment and at least one server entity are connected with the telecommunications network, wherein the user equipment is able to receive payload data of at least one payload type - as a data stream and using a data connection between the user equipment and the at least one content server entity - from the at least one content server entity.
- the invention relates to a telecommunications network for detecting and/or identifying data streams within a telecommunications network, wherein a user equipment and at least one server entity are connected with the telecommunications network, wherein the user equipment is able to receive payload data of at least one payload type - as a data stream and using a data connection between the user equipment and the at least one content server entity - from the at least one content server entity.
- the invention relates to a content server entity for detecting and/or identifying data streams within a telecommunications network, wherein a user equipment and at least one server entity are connected with the telecommunications network, wherein the user equipment is able to receive payload data of at least one payload type - as a data stream and using a data connection between the user equipment and the at least one content server entity - from the at least one content server entity.
- the invention relates to a program comprising a computer readable program code and to a computer program product for providing an enhanced level of authentication related to a secure software client application provided by an application distribution entity.
- One approach consists in more or less deep inspecting network traffic, and to directly inspect the network traffic in order to retrieve the content thereof or to identify the content thereof.
- a telecommunications network such as a mobile communication network and/or a fixed line telecommunications network
- An object of the present invention is to provide a cost-effective and comparatively fast, easy, as well as secure solution, for detecting and/or identifying data streams within a telecommunications network, wherein the detection and/or identification of the data streams serve to be able to differentiate and/or to treat different data streams differently without the need to inspect the data streams - and especially the content thereof (or the payload data of the data streams) - on an important scale and/or to a great extent (or depth) and/or to decrypt the (payload data) content of data streams that comprise (at least in part) encrypted content data or encrypted payload data, wherein the data streams are typically provided by content server entities towards clients or subscribers of the telecommunications network.
- the object of the present invention is achieved by a method for detecting and/or identifying data streams within a telecommunications network, wherein a user equipment is connected - via an access network of the telecommunications network - with the telecommunications network,
- the telecommunications network is connected to at least one server entity, wherein the user equipment is able to receive payload data of at least one payload type - as a data stream and using a data connection between the user equipment and the at least one content server entity - from the at least one content server entity, wherein the payload data of the data stream are transmitted, between the at least one content server entity on the one hand, and the user equipment on the other hand, via the telecommunications network, and involving a server certificate information
- the method comprises the following steps:
- the server certificate information is assigned to the at least one content server entity and/or to the data stream, wherein the server certificate information comprises or is associated with a stream class information,
- the telecommunications network corresponds to either a fixed-line telecommunications network (i.e.
- the client or user equipment is typically connected to the telecommunications network using a wireline connection, typically to a router entity or (home) gateway entity or CPE (customer premises equipment), wherein a wireless (local area network, WLAN) connection is often used between the router entity and the user equipment) or a mobile communication network (also referred to as a public land mobile network, and typically comprising an access network comprising a plurality of base station entities, wherein the user equipments (of the mobile communication network or connected to the mobile
- a wireline connection typically to a router entity or (home) gateway entity or CPE (customer premises equipment)
- WLAN local area network
- a mobile communication network also referred to as a public land mobile network, and typically comprising an access network comprising a plurality of base station entities, wherein the user equipments (of the mobile communication network or connected to the mobile
- a communication network are connected to at least one base station entity of the plurality of base station entities using an air interface, especially according to a 3GPP (Third Generation Partnership Project) standard) or to a combined or integrated fixed-line and mobile communication network, i.e. a telecommunications network comprising (in at least a first part or in a first area) components of a wireline telecommunications network, and comprising (in the first part and/or in at least a second part or in a second area) components of a mobile communication network.
- the telecommunications network is connected to a plurality of content server entities, e.g., different streaming servers, e.g. for video streaming, audio streaming or other content providers.
- the user equipment is able to receive payload data of at least one payload type from the at least one content server entity.
- the user equipment is able to receive payload data of a plurality of different payload types, typically from a plurality of different content server entities and/or from the at least one content server entity, wherein both the case of the at least one content server entity providing different payload types (i.e. at least two different payload types) to the user equipment as well as the case of each content server entity providing each one a different payload type to the user equipment, as well as mixed scenarios thereof could be realized.
- the payload data of one data stream are typically transmitted using a data connection between the user equipment and the at least one content server entity, via the telecommunications network.
- each data stream typically consists of a plurality, even a multitude, of different data packets (typically internet protocol packets), and the payload data (or payload data packets) of such a data stream are transmitted, between the at least one content server entity on the one hand, and the user equipment on the other hand, via the telecommunications network, and involving a server certificate information.
- server certificate information it is advantageously possible to detect and/or to identify each data stream, or also a plurality of data streams (having something in common).
- this detection and/or identification (of one or a plurality data streams) can be provided in a secure and/or protected manner due to the detection and/or identification being performed or conducted upon the server certificate information (of the content server entity, wherein the server certificate information provides a certain level of authentication regarding the data stream, and especially regarding its origin, i.e. the respective content server entity).
- the detection and/or identification itself is done, according to the present invention, by means of a stream class information being part of the server certificate information and/or being associated with the server certificate information.
- the server certificate information might comprise, — regarding a first data stream, the string (or subdomain information) "video. contentproviderl .com”,
- the stream class information could correspond to or be associated to detecting and/or identifying the string "video”, which would, according to the exemplary embodiment, result in identifying the first and second data stream, whereas in case of a second use case and the stream class information corresponding to or be associated to (detecting and/or identifying) the string "contentproviderl ", the exemplary embodiment would result in identifying the first and third data stream.
- the server certificate information is assigned to the at least one content server entity and/or to the data stream, wherein the server certificate information comprises or is associated with a stream class information, and in a second step of the inventive method, subsequent to the first step - either while the data connection enabling the data stream is established or after the data connection enabling the data stream is established but while the data connection enabling the data stream is still available -, the stream class information of or associated with the server certificate information is both
- a handling alternative - out of a plurality of handling alternatives, to be potentially applied to data streams within the telecommunications network - is applied to the data stream in dependency of the detected and/or identified stream class information
- the stream class information corresponds to or is associated with at least one out of the following:
- a domain name information of the at least one content server entity the domain name information especially being a part of the server certificate information, and especially being a subdomain name information
- the uniform resource identifier information especially being a part of the server certificate information
- the payload type information especially being a part of the server certificate information
- a user equipment information of the user equipment it is especially advantageous to use a domain name information (or a part thereof) of the at least one content server entity, especially being part of the server certificate information, and especially being a subdomain name information (such as "video.contentprovider1 .com" or only
- video, contentproviderf as the stream class information.
- a uniform identifier information (or a part thereof) of the at least one content server entity especially being part of the server certificate information as the stream class information.
- a payload type information (or a part thereof) of the data stream especially being part of the server certificate information as the stream class information.
- a user equipment information of the user equipment is advantageous to use.
- the stream class information of or associated with the server certificate information is linked to the domain name information and/or to the uniform resource identifier information of the at least one content server entity, and wherein a different stream class information corresponds to a different domain name information and/or to a different uniform resource identifier information of the at least one content server entity.
- the domain name information and/or the uniform resource identifier information of the server certificate information - corresponding to the domain name information and/or to the uniform resource identifier information of the at least one content server entity - is compared to the domain and/or to the uniform resource identifier initially requested by the user equipment.
- a response message is generated, especially by the at least one content server entity, wherein the response message comprises - especially within the HTTP-header - a content type information of the data stream, wherein the content type information especially corresponds to a signed information, and the detection of the content type being based on the detection of the server certificate information.
- a response message is generated, especially by the at least one content server entity, wherein the response message comprises a signed information being the result of a signature generating operation on an IP-address (Internet Protocol address) information, wherein a validation of the at least one content server entity and/or of the user equipment and/or of the content of the data stream is performed based on the detection of the server certificate information, wherein the IP-address information especially comprises the IP-address and/or the port number and/or a random number and/or a hashed value of a part of the content data of the data stream.
- IP-address Internet Protocol address
- a signed information as part of the response message, being the result of a signature generating operation on an IP-address (Internet Protocol address) information, wherein a validation of the at least one content server entity and/or of the user equipment and/or of the content of the data stream is performed based on the detection of the server certificate information, it is advantageously possible to relate a data stream to the at least one content server entity.
- the signed information is the result of a signature generating operation on the following pieces of information:
- a response message is generated, especially by the at least one content server entity, and a challenge information is transmitted, from the telecommunications network to the at least one content server entity, wherein the response message comprises a response information being the result of a signature generating operation on the challenge information, wherein a validation of the at least one content server entity and/or of the user equipment and/or of the content of the data stream is performed based on the detection of the server certificate information.
- the payload data of the data stream are at least partly encrypted and/or signed, especially using a TLS (Transport Layer Security) encryption protocol, wherein the server certificate information especially corresponds to a server certificate according to the X509 specification.
- TLS Transport Layer Security
- the payload data of the data stream can either not be efficiently controlled at all, or these payload data need to be inspected on a large scale, which in turn may cause additional processing effort to be conducted by the operator of the telecommunications network, and/or may require the user's consent to do so in accordance to data protection regulation and/or law.
- the present invention relates to a system for detecting and/or identifying data streams within a telecommunications network, wherein a user equipment is connected - via an access network of the telecommunications network - with the telecommunications network,
- the telecommunications network is connected to at least one content server entity
- system comprises the telecommunications network, the user equipment, and the at least one content server entity,
- the user equipment is able to receive payload data of at least one payload type - as a data stream and using a data connection between the user equipment and the at least one content server entity - from the at least one content server entity, wherein the payload data of the data stream are transmitted, between the at least one content server entity on the one hand, and the user equipment on the other hand, via the telecommunications network, and involving a server certificate information,
- the system in order to transmit the payload data of the data stream, the system is configured such that:
- the server certificate information is assigned to the at least one content server entity and/or to the data stream, wherein the server certificate information comprises or is associated with a stream class information,
- the stream class information of or associated with the server certificate information is - either while the data connection enabling the data stream is established or after the data connection enabling the data stream is established but while the data connection enabling the data stream is still available - both
- the present invention relates to a telecommunications network for detecting and/or identifying data streams within the telecommunications network, wherein a user equipment is connected - via an access network of the telecommunications network - with the telecommunications network,
- the telecommunications network is connected to at least one content server entity
- the user equipment is able to receive payload data of at least one payload type - as a data stream and using a data connection between the user equipment and the at least one content server entity - from the at least one content server entity,
- the payload data of the data stream are transmitted, between the at least one content server entity on the one hand, and the user equipment on the other hand, via the telecommunications network, and involving a server certificate information
- the telecommunications network in order to transmit the payload data of the data stream, is configured such that:
- the server certificate information is assigned to the at least one content server entity and/or to the data stream, wherein the server certificate information comprises or is associated with a stream class information,
- the stream class information of or associated with the server certificate information is - either while the data connection enabling the data stream is established or after the data connection enabling the data stream is established but while the data connection enabling the data stream is still available - both
- the present invention relates to a content server entity for detecting and/or identifying data streams within an inventive telecommunications network suitable to be used in an inventive system.
- the present invention relates to a program comprising a computer readable program code which, when executed on a computer or on a network node of a telecommunications network or on a content server entity, or in part on a network node of a telecommunications network and/or in part on a content server entity and/or in part on a content server entity, causes the computer and/or the network node of the telecommunications network and/or the content server entity to perform an inventive method.
- the present invention relates to computer program product for detecting and/or identifying data streams within a telecommunications network
- the computer program product comprising a computer program stored on a storage medium
- the computer program comprising program code which, when executed on a computer or on a network node of a telecommunications network or on a content server entity, or in part on a network node of a telecommunications network and/or in part on a content server entity and/or in part on a content server entity, causes the computer and/or the network node of the telecommunications network and/or the content server entity to perform an inventive method.
- Figure 1 schematically illustrates an exemplary system and situation according to the present invention where a telecommunications network - with a user equipment connected to the telecommunications network - is connected to content server entity, and the content server entity is able to provide a data stream to the user equipment.
- Figure 2 schematically illustrates a communication diagram related to the invention.
- FIG. 1 a system for realizing the present invention is schematically shown, the system comprising a telecommunications network 100, especially a mobile communication network (also called public land mobile network) or a fixed-line telecommunications network.
- the telecommunications network 100 is connected to a user equipment 20.
- the system furthermore also comprises at least one content server entity 201 .
- a plurality of content server entities 200 is connected to the telecommunications network 100, comprising a first content server entity 201 and a
- the at least one content server entity 201 (or first content server entity 201 ) provides data to be transmitted to the user equipment 20, especially streaming data.
- the data or payload data are transmitted to the user equipment 20 by means of at least one data stream 221 (illustrated in Figure 1 by means 10 of a double arrow).
- a plurality of data streams are transmitted from the (first) content server entity 201 to the user equipment 20 or from the first and the second content server entity 201 , 202 to the user equipment 20.
- a data stream 221 being transmitted between the at least one content server entity 201 and the user equipment 20, involves a 15 server certificate information 241 , the server certificate information 241 being assigned to the at least one content server entity 201 and/or to the data stream 221. Furthermore, the server certificate information 241 comprises or is associated with a stream class information.
- FIG. 2 a communication diagram relating to the present invention is 20 schematically represented.
- the communication diagram involves the user equipment 20, the (first or at least one) content server entity 201 , and the telecommunications network 100.
- the server certificate information 241 associated with the first content server entity 201 is transmitted to the telecommunications network 100.
- the user equipment 20 requests content data to be 25 transmitted, the content data being typically provided by the content server entity 201 , and transmitted via the telecommunications network 100 to the user equipment 20.
- the first content server entity 201 transmits a response message to at least the telecommunications network 100 (or, as it is shown in Figure 2, also to the user equipment 20).
- the content i.e. the payload data of the data stream 35 221 is encrypted, especially end-to-end encrypted from the first content server entity 201 to the user equipment 20 (and/or vice versa)
- additional measures would have to be implemented, within the telecommunications network, in order to decrypt the payload data.
- the present invention it is advantageously possible to use different pieces of subdomain information (such as "audio.contentprovider1.com”, “video.contentprovider1.com”, “html.contentprovider1 .com”) and different server certificate information in order to detect and/or to identify different types of content within the payload data. It is especially advantageous according to the present invention that one server certificate information is generated (and exchanges with the
- a stream class information e.g. all the data streams of a certain content server entity 201 , 202 (by means of using, e.g., a string of " * .contentprovider1 ") or all the data streams relating to a specific type of service (by means of using, e.g., a string of "video. * ”) or a combination thereof.
- server certificate information (or server certificates) are linked or pinned to the subdomain information and/or the certificates are transmitted per TCP/UDP connection.
- the certificates are able to be detected by means of different methods, e.g. by means of using the bit pattern in the data stream and/or by analyzing the data stream.
Landscapes
- Engineering & Computer Science (AREA)
- Multimedia (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP16179757 | 2016-07-15 | ||
| PCT/EP2017/065933 WO2018010959A1 (en) | 2016-07-15 | 2017-06-27 | Method for detecting and/or identifying data streams within a telecommunications network; system, telecommunications network, and content server entity for detecting and/or identifying data streams within a telecommunications network, program and computer program product |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3485620A1 true EP3485620A1 (en) | 2019-05-22 |
Family
ID=56551176
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP17735454.5A Ceased EP3485620A1 (en) | 2016-07-15 | 2017-06-27 | Method for detecting and/or identifying data streams within a telecommunications network; system, telecommunications network, and content server entity for detecting and/or identifying data streams within a telecommunications network, program and computer program product |
Country Status (2)
| Country | Link |
|---|---|
| EP (1) | EP3485620A1 (en) |
| WO (1) | WO2018010959A1 (en) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109450975A (en) * | 2018-10-10 | 2019-03-08 | 海南高灯科技有限公司 | Concurrency performance optimization method, device, electronic equipment, readable storage medium storing program for executing |
Family Cites Families (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9978025B2 (en) * | 2013-03-20 | 2018-05-22 | Cisco Technology, Inc. | Ordered-element naming for name-based packet forwarding |
| US10171532B2 (en) * | 2014-09-30 | 2019-01-01 | Citrix Systems, Inc. | Methods and systems for detection and classification of multimedia content in secured transactions |
-
2017
- 2017-06-27 WO PCT/EP2017/065933 patent/WO2018010959A1/en not_active Ceased
- 2017-06-27 EP EP17735454.5A patent/EP3485620A1/en not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| WO2018010959A1 (en) | 2018-01-18 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11848961B2 (en) | HTTPS request enrichment | |
| US9237168B2 (en) | Transport layer security traffic control using service name identification | |
| CN110190955B (en) | Information processing method and device based on secure socket layer protocol authentication | |
| CN105141636B (en) | Suitable for the HTTP safety communicating methods and system of CDN value-added service platforms | |
| US20130268681A1 (en) | Method and Apparatuses for End-to-Edge Media Protection in ANIMS System | |
| CN104247485A (en) | Network application function authorisation in a generic bootstrapping architecture | |
| WO2017185978A1 (en) | Method and device for parsing packet | |
| CN105959105A (en) | Data transmission method and data transmission device | |
| CN107135190A (en) | Method and device for identifying data traffic attribution based on transport layer security connection | |
| CN116635880A (en) | Disposal of trusted service business in core network domain | |
| CN102231766B (en) | Method and system for analyzing and verifying domain name | |
| WO2018010958A2 (en) | Method for detecting and/or identifying data streams within a telecommunications network; system, telecommunications network, and content server entity for detecting and/or identifying data streams within a telecommunications network, program and computer program product | |
| US20100095361A1 (en) | Signaling security for IP multimedia services | |
| US10958751B2 (en) | Method for verifying a user association, intercepting module and network node element | |
| CN103546442A (en) | Communication monitoring method and communication monitoring device for browsers | |
| CN102843335B (en) | The processing method of streaming medium content and equipment | |
| WO2018010959A1 (en) | Method for detecting and/or identifying data streams within a telecommunications network; system, telecommunications network, and content server entity for detecting and/or identifying data streams within a telecommunications network, program and computer program product | |
| CN107483197B (en) | VPN network terminal key distribution method and device | |
| CN116887274A (en) | Terminal identity authentication system and method | |
| US20240097903A1 (en) | Ipcon mcdata session establishment method | |
| US20060075229A1 (en) | Method and apparatus for maintaining a communications connection while guarding against bandwidth consuming attacks | |
| Zaghal et al. | Extending AES with DH key-exchange to enhance VoIP encryption in mobile networks | |
| Fietkau et al. | Free by Design: On the Feasibility | |
| CN121792155A (en) | Message filtering method, device, equipment, storage medium and program product | |
| CN118827600A (en) | Information processing method, device, equipment and computer storage medium |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20190215 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20200325 |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: GERHARZ, CHRISTOPHER Inventor name: SCHMIDT, LUKAS Inventor name: FRIELINGSDORF, MATTHIAS |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20230817 |