Distributed Deep Packet Inspection for Network Latency Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional deep packet inspection (DPI) systems in point-to-multipoint networks are intrusive, cause significant communication latency, and require powerful, costly processing capabilities to handle all traffic flows, limiting their ability to inspect higher-layer information effectively.
Innovation Solution
A distributed DPI method where end-units in the network classify and duplicate only relevant packet flows for deep-packet inspection, performing processing locally with standard computing power, and sending results to a database server, thereby reducing latency and eliminating the need for complex, expensive DPI systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a conventional DPI system receives and processes all traffic flows between end-units and the central node, then deep packet inspection capability is provided, but communication latency increases significantly due to packet termination and mirroring
Solution Approach 1:
The patent segments the DPI function from the central node and distributes it to individual end-units. Each end-unit performs DPI locally on its own traffic flows without requiring packet termination and mirroring at the central node, thereby eliminating the latency introduced by centralized packet interception while maintaining comprehensive inspection capability.
Solution Approach 2:
Each end-unit performs deep packet inspection on its own incoming and outgoing packets autonomously without requiring external assistance from the central node or other end-units. This self-service approach allows packets to be inspected in-place without being terminated, mirrored, or redirected, thus avoiding additional latency while maintaining inspection effectiveness.
2Measurement precision
If a DPI system inspects all packets from all end-units, then complete traffic monitoring is achieved, but processing power requirements and system cost increase significantly
Solution Approach 1:
The patent divides the traffic monitoring task into independent segments, with each end-unit responsible for inspecting only its own traffic flows. This segmentation distributes the processing load across multiple end-units rather than concentrating it in a single centralized DPI system, reducing the processing power requirements and complexity of any single system while maintaining complete network-wide monitoring coverage.
3Quantity of substance
If all Ethernet frames are replicated to a DPI system, then complete traffic copying is achieved, but processing capability requirements remain high and higher-layer information cannot be evaluated
Solution Approach 1:
The patent performs preliminary filtering and classification of packets at each end-unit before duplication. Instead of blindly replicating all Ethernet frames, the system pre-identifies and duplicates only those packets that require deep inspection, reducing the volume of traffic sent to the DPI processing queue while ensuring that all relevant traffic is captured for higher-layer analysis.
Data Source
AI summary
A method for deep-packet inspection of packets flowing through an end unit in a point-to-multipoint network. The method comprises classifying packet flows through the end unit using their flow-identification (ID) to determine which of the packet flows should be deep-packet inspected, wherein the packet flows include incoming packets received from a central unit and outgoing packets sent to the central unit of the point-to-multipoint network; duplicating packets determined to be deep-packet inspected; saving all duplicated packets in a memory; upon collection of a predefined number of duplicated packets belonging to a certain flow-ID, performing deep-packet processing based on at least one deep-packet inspection application; and saving the deep-packet processing results in the memory.


