Distributed Traffic Inspection in Telecommunications Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Deep Packet Inspection (DPI) in telecommunications networks requires significant processing resources, leading to performance degradation and high costs due to the need for specialized nodes with high-capacity network ports, which are inefficiently utilized when dealing with a high proportion of 'easy to classify' data traffic and pose additional complexity and potential failure points in high-availability designs.
Innovation Solution
A method where nodes in a telecommunications network decide whether to perform payload inspection based on their capacity, with decisions and results communicated between nodes to distribute the processing load efficiently, allowing partial classification and reducing the need for specialized high-capacity nodes by leveraging existing nodes' processing resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If DPI is implemented in nodes conveying user plane traffic, then traffic inspection capability is provided, but performance degradation of user plane functionalities occurs
Solution Approach 1:
The patent divides the DPI function into separate specialized nodes distinct from user plane traffic forwarding nodes. The network is segmented such that inspection nodes handle payload analysis while forwarding nodes handle traffic transmission, eliminating performance degradation in user plane functionalities while maintaining inspection capability.
2Productivity
If specialized nodes with high-capacity network ports are deployed for DPI, then inspection processing capacity is increased, but device cost and complexity increase
Solution Approach 1:
The patent merges the DPI inspection function with existing network nodes that already have processing capabilities. Instead of deploying completely separate specialized nodes, the inspection functionality is integrated into nodes that participate in both user plane and control plane traffic handling, reducing overall device complexity while maintaining inspection capacity.
3Productivity
If specialized nodes are deployed for DPI, then inspection performance is improved, but network reliability decreases due to additional failure points
Solution Approach 1:
The patent designs inspection nodes to perform multiple functions - they handle both DPI inspection and user plane traffic forwarding. This multi-functionality ensures that even if dedicated inspection resources are overwhelmed or fail, the nodes can continue to forward traffic, maintaining network availability while providing inspection performance.
4Speed
If high-capacity network ports are added to nodes for DPI, then data transfer capability is improved, but manufacturing cost increases
Solution Approach 1:
The patent implements dynamic traffic steering mechanisms that adaptively route traffic based on inspection requirements and node capacity. Instead of provisioning all nodes with high-capacity ports for potential DPI workloads, the system dynamically allocates inspection tasks to nodes with available capacity, allowing standard ports to suffice while maintaining high data transfer capability when needed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A first node (210; 220) receives data packets of a flow and forwards the data packets of the flow to a second node (220; 230). The first node (210; 220) takes a first decision whether to perform inspection of a payload section of at least one data packet of the flow at the first node (210; 220) and indicate a result of the first decision to the second node (220; 230). The second node (220; 230) receives the data packets of the flow from the first node (210; 220). On the basis of the result of the first decision indicated by the first node (210; 220), the second node (220; 230) take a second decision whether to perform inspection of a payload section of at least one data packet of the flow at the second node (220; 230).