Distributed DPI Proxy Server for Real-Time Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network broadband technologies face challenges in managing broadband services, performing content-based charging, and ensuring information security due to the inability of deep packet inspection (DPI) servers to process packets in real-time, as they handle a large quantity of packets and require powerful centralized processing capabilities.

Innovation Solution

Implementing a DPI proxy server configured on a distributed basis at the access-network user side, which identifies the service type and/or contents of packets and performs DPI filtering using a preset policy, thereby reducing the packet traffic processed by the DPI server and enabling real-time processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized DPI server is used to process all packets from the access network, then comprehensive packet inspection and filtering can be performed, but the server cannot process packets in real-time due to the large quantity of packets

Engineering Contradiction:
Improvepacket inspection completenessVSAvoidpacket processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the centralized DPI server into multiple distributed DPI proxy servers deployed at access nodes. Each proxy server independently processes packets from its local users, segmenting the overall packet processing task across multiple locations. This segmentation enables parallel processing and eliminates the bottleneck of a single centralized server, achieving real-time packet inspection while maintaining comprehensive coverage.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a centralized DPI server processes all packets, then unified policy enforcement is achieved, but the server requires powerful centralized processing capabilities increasing system complexity

Engineering Contradiction:
Improvepolicy enforcement uniformityVSAvoidprocessing capability requirement
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a policy distribution mechanism where the centralized policy server pre-distributes DPI filtering policies to multiple access nodes before packet processing occurs. This preliminary action ensures that all distributed proxy servers have the necessary filtering rules in advance, enabling them to enforce policies locally without requiring complex real-time communication or centralized control during packet processing, thus reducing overall system complexity.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If all packets from access network are processed by DPI server, then complete service identification is achieved, but real-time processing cannot be performed

Engineering Contradiction:
Improveservice type identification accuracyVSAvoidpacket processing delay
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent transitions from a single centralized processing dimension to a multi-dimensional distributed processing architecture. By deploying DPI proxy servers at multiple access nodes across different physical locations, the system creates parallel processing dimensions. Each proxy server performs complete service identification locally on packets from its users, eliminating the sequential processing bottleneck and achieving both accurate service type identification and real-time processing through spatial distribution.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8250646B2Method, system, and device for filtering packets
Publication Date: 2012.08.21 HUAWEI TECH CO LTD
  • US8250646B2 patent drawing
  • US8250646B2 patent drawing
  • US8250646B2 patent drawing

AI summary

A method, system, and device for filtering packets are disclosed. The method includes: by a deep packet inspection (DPI) proxy server configured at the access-network user side, identifying the service type and/or contents of a received packet, and performing DPI filtering on the packet by using a preset DPI filtering policy according to the identified service type and/or contents. In the technical solution of the present invention, DPI proxy servers are configured at the access-network user side on a distributed basis; each DPI proxy server receives packets only from a user equipment (UE) on a customer premises network (CPN), where the UE corresponds to the DPI proxy server. Compared with the DPI server configured at the edge between the core network and the access network in the prior art, the DPI proxy server provided in embodiments of the present invention processes fewer packets, thus performing real-time DPI on the packets.