Encrypted Packet Flow QoS Detection via Chunk Statistics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for quality of service (QoS) detection in networks are ineffective for encrypted packet flows, particularly for multimedia traffic, as they rely on inspecting unencrypted HTTP messages, which is not possible with Secure Hyper Text Transfer Protocol (HTTPS) or other encrypted protocols.

Innovation Solution

A monitoring station identifies and analyzes packet flows to determine chunk statistics, such as chunk size, duration, and throughput, by recognizing patterns in packet sizes and arrival times, allowing for the calculation of Quality of Experience (QoE) metrics even in encrypted environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If HTTPS encryption is used to protect video traffic, then security and privacy are improved, but quality of service detection capability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidQoS detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent changes the detection parameters from content-based inspection (requiring decryption) to metadata-based inspection using packet timing, size, and flow characteristics. This allows QoS detection to continue functioning with encrypted traffic by observing external characteristics rather than internal content.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary detection approach that observes traffic patterns at the transport layer without penetrating the encryption layer. By using packet inter-arrival times, packet sizes, and flow characteristics as intermediaries, the system can infer QoS metrics without breaking encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If packet inspection is performed to detect QoS, then measurement accuracy is improved, but applicability to encrypted protocols deteriorates

Engineering Contradiction:
ImproveQoS measurement accuracyVSAvoidprotocol compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent extracts the essential QoS measurement functions from the encrypted payload and relocates them to observable packet characteristics. By taking out the detection dependency from content inspection, the system maintains measurement capability while becoming compatible with encrypted protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal detection mechanism that works across both encrypted and unencrypted protocols by relying on common packet characteristics (timing, size, flow patterns) that exist regardless of encryption status. This multi-functional approach allows the same detection system to serve multiple protocol types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If chunk boundary detection is performed in encrypted flows, then QoE metric accuracy is improved, but detection complexity increases

Engineering Contradiction:
ImproveQoE metric accuracyVSAvoiddetection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent enables chunk boundary detection to occur naturally through analysis of existing packet patterns without requiring complex decryption or payload inspection. The detection system uses self-service approaches by leveraging inherent characteristics of DASH protocol packet flows, such as periodic timing patterns and size characteristics, to identify chunk boundaries.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10986001B2System and method for quality of service detection of encrypted packet flows
Publication Date: 2021.04.20 NOKIA SOLUTIONS & NETWORKS OY
  • US10986001B2 patent drawing
  • US10986001B2 patent drawing
  • US10986001B2 patent drawing

AI summary

A monitoring station deployed in a network monitors packets over one or more interfaces in the network. The monitoring station identifies a flow in a media session. The flow includes at least one request message that includes a request for a segment or chunk of video content and one or more response messages including the requested chunk. The monitoring determines a start of a chunk in the flow and determines an end of the chunk in the flow. Using the start and end times of the chunk and next or subsequent chunks, the monitoring station determines one or more chunk statistics, such as chunk size, chunk duration and chunk download time.