Distributed Deep Packet Inspection for Network Latency Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional deep packet inspection (DPI) systems in point-to-multipoint networks are intrusive, cause significant communication latency, and require powerful, costly processing capabilities to handle all traffic flows, limiting their ability to inspect higher-layer information effectively.

Innovation Solution

A distributed DPI method where end-units in the network classify and duplicate only relevant packet flows for deep-packet inspection, performing processing locally with standard computing power, and sending results to a database server, thereby reducing latency and eliminating the need for complex, expensive DPI systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a conventional DPI system receives and processes all traffic flows between end-units and the central node, then deep packet inspection capability is provided, but communication latency increases significantly due to packet termination and mirroring

Engineering Contradiction:
Improvedeep packet inspection capabilityVSAvoidcommunication latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the DPI function from the central node and distributes it to individual end-units. Each end-unit performs DPI locally on its own traffic flows without requiring packet termination and mirroring at the central node, thereby eliminating the latency introduced by centralized packet interception while maintaining comprehensive inspection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each end-unit performs deep packet inspection on its own incoming and outgoing packets autonomously without requiring external assistance from the central node or other end-units. This self-service approach allows packets to be inspected in-place without being terminated, mirrored, or redirected, thus avoiding additional latency while maintaining inspection effectiveness.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If a DPI system inspects all packets from all end-units, then complete traffic monitoring is achieved, but processing power requirements and system cost increase significantly

Engineering Contradiction:
Improvetraffic monitoring completenessVSAvoidprocessing system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent divides the traffic monitoring task into independent segments, with each end-unit responsible for inspecting only its own traffic flows. This segmentation distributes the processing load across multiple end-units rather than concentrating it in a single centralized DPI system, reducing the processing power requirements and complexity of any single system while maintaining complete network-wide monitoring coverage.

Inventive Principle:
Principle #1Segmentation

3Quantity of substance

If all Ethernet frames are replicated to a DPI system, then complete traffic copying is achieved, but processing capability requirements remain high and higher-layer information cannot be evaluated

Engineering Contradiction:
Improvetraffic replication completenessVSAvoidprocessing capability requirements
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent performs preliminary filtering and classification of packets at each end-unit before duplication. Instead of blindly replicating all Ethernet frames, the system pre-identifies and duplicates only those packets that require deep inspection, reducing the volume of traffic sent to the DPI processing queue while ensuring that all relevant traffic is captured for higher-layer analysis.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9565120B2Method and system for performing distributed deep-packet inspection
Publication Date: 2017.02.07 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9565120B2 patent drawing
  • US9565120B2 patent drawing
  • US9565120B2 patent drawing

AI summary

A method for deep-packet inspection of packets flowing through an end unit in a point-to-multipoint network. The method comprises classifying packet flows through the end unit using their flow-identification (ID) to determine which of the packet flows should be deep-packet inspected, wherein the packet flows include incoming packets received from a central unit and outgoing packets sent to the central unit of the point-to-multipoint network; duplicating packets determined to be deep-packet inspected; saving all duplicated packets in a memory; upon collection of a predefined number of duplicated packets belonging to a certain flow-ID, performing deep-packet processing based on at least one deep-packet inspection application; and saving the deep-packet processing results in the memory.