Distributed Flow Identification in Access Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional flow identification and Deep Packet Inspection (DPI) systems are standalone and costly, requiring separate infrastructure for traffic inspection, which is inefficient and not scalable for high-line rate traffic.
Innovation Solution
Embedding flow identification and DPI logic into network elements, separating traffic inspection into detection and analysis phases (Fast Path FI and Deep FI), and using a centralized controller to coordinate distributed DPI elements, creating a virtualized appliance view that leverages pre-existing network packet processing functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional standalone flow identification and DPI systems are used, then traffic inspection capability is provided, but system cost and infrastructure complexity increase
Solution Approach 1:
The patent combines flow identification and deep packet inspection functions with existing network packet processing elements, eliminating the need for separate standalone inspection infrastructure. Network elements that already perform packet processing are enhanced to provide FI and DPI capabilities, merging multiple functions into unified components.
Solution Approach 2:
The patent makes existing network packet processing elements multi-functional by enabling them to perform not only their original packet processing tasks but also flow identification and deep packet inspection. This universal approach allows single elements to serve multiple purposes, reducing overall system complexity.
2Object-affected harmful factors
If standalone DPI systems are deployed, then security inspection is achieved, but scalability to high-line rate traffic is limited
Solution Approach 1:
The patent segments the traffic inspection process into two distinct phases: Fast Path Flow Identification for initial traffic classification and routing, and Deep Packet Inspection for detailed security analysis. This segmentation allows high-speed processing for most traffic while applying intensive inspection only where needed, enabling scalability to high-line rate traffic.
Solution Approach 2:
The patent introduces a centralized controller as an intermediary that coordinates between the distributed flow identification agents and deep packet inspection elements. This controller manages the segmentation strategy, directing traffic appropriately between fast path and deep inspection paths, enabling scalable coordination across the network infrastructure.
3Productivity
If flow identification is distributed across network elements, then cost and efficiency improve, but system coordination complexity increases
Solution Approach 1:
The patent implements feedback mechanisms where distributed flow identification agents report their findings and traffic characteristics to the centralized controller, which then adjusts inspection strategies and coordinates deep packet inspection resources accordingly. This feedback loop enables efficient coordination without requiring complex manual configuration or management.
Data Source
AI summary
A system and method for tracking and adjusting packet flows through a network having a service delivery node and one or more residential services gateways. Packet flows are recognized as they pass through one or more residential services gateway and flow analytics information corresponding to the packet flows recognized in the residential services gateways are transferred from the residential gateways to the flow identification control unit. The flow analytics information received from the residential services gateways is analyzed within the flow identification control unit and traffic through one or more of the service access platform and the residential services gateways is adjusted, if necessary, as a function of the flow analytics information analyzed by the flow identification control unit.


