Distributed Flow Identification in Access Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional flow identification and Deep Packet Inspection (DPI) systems are standalone and costly, requiring separate infrastructure for traffic inspection, which is inefficient and not scalable for high-line rate traffic.

Innovation Solution

Embedding flow identification and DPI logic into network elements, separating traffic inspection into detection and analysis phases (Fast Path FI and Deep FI), and using a centralized controller to coordinate distributed DPI elements, creating a virtualized appliance view that leverages pre-existing network packet processing functions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional standalone flow identification and DPI systems are used, then traffic inspection capability is provided, but system cost and infrastructure complexity increase

Engineering Contradiction:
Improvetraffic inspection capabilityVSAvoidseparate infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines flow identification and deep packet inspection functions with existing network packet processing elements, eliminating the need for separate standalone inspection infrastructure. Network elements that already perform packet processing are enhanced to provide FI and DPI capabilities, merging multiple functions into unified components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent makes existing network packet processing elements multi-functional by enabling them to perform not only their original packet processing tasks but also flow identification and deep packet inspection. This universal approach allows single elements to serve multiple purposes, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Object-affected harmful factors

If standalone DPI systems are deployed, then security inspection is achieved, but scalability to high-line rate traffic is limited

Engineering Contradiction:
Improvesecurity inspectionVSAvoidscalability to high-line rate traffic
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent segments the traffic inspection process into two distinct phases: Fast Path Flow Identification for initial traffic classification and routing, and Deep Packet Inspection for detailed security analysis. This segmentation allows high-speed processing for most traffic while applying intensive inspection only where needed, enabling scalability to high-line rate traffic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a centralized controller as an intermediary that coordinates between the distributed flow identification agents and deep packet inspection elements. This controller manages the segmentation strategy, directing traffic appropriately between fast path and deep inspection paths, enabling scalable coordination across the network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If flow identification is distributed across network elements, then cost and efficiency improve, but system coordination complexity increases

Engineering Contradiction:
Improveinspection efficiencyVSAvoiddistributed system coordination
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where distributed flow identification agents report their findings and traffic characteristics to the centralized controller, which then adjusts inspection strategies and coordinates deep packet inspection resources accordingly. This feedback loop enables efficient coordination without requiring complex manual configuration or management.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10284463B2Distributed system and method for flow identification in an access network
Publication Date: 2019.05.07 CALIX INC
  • US10284463B2 patent drawing
  • US10284463B2 patent drawing
  • US10284463B2 patent drawing

AI summary

A system and method for tracking and adjusting packet flows through a network having a service delivery node and one or more residential services gateways. Packet flows are recognized as they pass through one or more residential services gateway and flow analytics information corresponding to the packet flows recognized in the residential services gateways are transferred from the residential gateways to the flow identification control unit. The flow analytics information received from the residential services gateways is analyzed within the flow identification control unit and traffic through one or more of the service access platform and the residential services gateways is adjusted, if necessary, as a function of the flow analytics information analyzed by the flow identification control unit.