Access Point Traffic Pairing for HTTPS Performance Analytics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing use of HTTPS encryption in network communications makes it difficult to accurately calculate and report network performance metrics, such as HTTP response times, as requests and responses can no longer be directly correlated, leading to inaccurate or unavailable performance analysis.

Innovation Solution

Methods and systems that record, analyze, and report network traffic metrics by pairing outgoing and incoming transfer units using identifiers, and apply unsupervised machine learning to cluster and aggregate metrics into normalized quality of experience scores, enabling accurate performance analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If HTTPS encryption is used for network communications, then security and data protection are improved, but the ability to correlate requests and responses for calculating network performance metrics deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidnetwork performance metrics accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary mechanism (the access point acting as a mediator) that receives both the request and response transfer units, extracts identifiers from them, and uses these identifiers to correlate and group the transfer units for calculating network performance metrics without needing to decrypt the HTTPS-encrypted data

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the identifier information from the transfer units (such as TCP sequence numbers, packet IDs, or application-layer identifiers) and uses this extracted information to correlate requests with responses. This allows the system to calculate performance metrics like response time and throughput without needing to access or decrypt the encrypted payload data

Inventive Principle:
Principle #2Taking out (Extraction)

2Loss of time

If network performance monitoring is performed in near-real time, then responsiveness to adverse events is improved, but system complexity and processing requirements worsen

Engineering Contradiction:
Improveresponse time to adverse eventsVSAvoidmonitoring system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The access point performs self-service by autonomously collecting transfer units, extracting identifiers, grouping correlated request-response pairs, and calculating performance metrics locally. This self-service capability enables near-real-time monitoring without requiring complex centralized processing systems, as each access point independently manages its own monitoring tasks

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the monitoring function at the access point level rather than implementing a centralized monitoring system. Each access point independently handles transfer units, extracts identifiers, groups related packets, and calculates local performance metrics. This segmentation distributes the processing load and reduces overall system complexity while enabling real-time response

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12587455B2Methods, systems, and devices for analyzing network performance
Publication Date: 2026.03.24 RUCKUS IP HOLDINGS LLC
  • US12587455B2 patent drawing
  • US12587455B2 patent drawing
  • US12587455B2 patent drawing

AI summary

Methods, systems, and devices for performing analytics on communications networks. For example, methods may include receiving, at an access point of a wireless network, a first transfer unit comprising first data destined for a first destination; receiving, at the access point, a second transfer unit comprising second data destined for a second destination; grouping, by the access point, the first and second transfer units into a group; and calculating, by the access point and based on the transfer units of the group, a response time associated with the first destination based on a time difference between the receiving of the first transfer unit and the receiving of the second transfer unit. The transfer units may comprise encrypted data.