Policy Tagging for Encrypted Packet Congestion Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deep packet inspection (DPI) techniques are ineffective in examining encrypted packets, leading to inadequate network congestion management as transmission policies cannot be properly applied.

Innovation Solution

A system that determines the attributes of encrypted content using a unique identifier, generates a transmission policy, and applies it by tagging packets, allowing network devices to implement the policy without needing DPI, thereby enabling effective policy application for encrypted content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet inspection (DPI) techniques are used to examine packets and apply transmission policies, then network congestion management is improved, but the technique becomes ineffective for encrypted packets

Engineering Contradiction:
Improvenetwork congestion managementVSAvoideffectiveness with encrypted packets
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by determining content attributes and generating transmission policies before the packets are encrypted and transmitted. The content server identifies attributes of the content to be transmitted, determines appropriate transmission policies based on these attributes, and tags packets with policy information prior to encryption. This allows network devices to apply policies to encrypted packets without needing to decrypt them or perform DPI.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces an intermediary approach by using content attribute determination and policy tagging as a bridge between the content server and network devices. Instead of relying on network devices to perform DPI on encrypted packets, the content server acts as an intermediary that pre-processes content, determines attributes, generates policies, and embeds policy tags in packets. This intermediary mechanism enables policy application without direct inspection of encrypted content.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If DPI is performed on all packets to determine transmission policies, then policy accuracy is improved, but processing complexity and time increase

Engineering Contradiction:
Improvepolicy determination accuracyVSAvoidprocessing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs content attribute determination and policy generation as preliminary actions at the content server before packets are transmitted through the network. By determining attributes and generating policies in advance, the system eliminates the need for complex DPI processing at network devices, reducing processing complexity while maintaining policy accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The content server performs self-service by autonomously determining content attributes, generating transmission policies, and tagging packets with policy information. This self-service approach at the source eliminates the need for external DPI processing at network devices, simplifying the overall system while maintaining accurate policy determination.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If DPI techniques are used to identify content attributes, then policy application capability is improved, but the approach fails for encrypted content

Engineering Contradiction:
Improvepolicy application capabilityVSAvoidineffectiveness with encrypted packets
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system determines content attributes and generates transmission policies as preliminary actions before packets are encrypted. By establishing the policy framework in advance, the system enables policy application to encrypted packets without needing to inspect their contents, overcoming the limitation of DPI with encrypted data.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention uses content attribute determination and policy tagging as an intermediary mechanism that bridges the gap between encrypted packets and policy application. Instead of directly inspecting encrypted content through DPI, the system uses pre-determined attributes and tags as intermediaries to enable policy application without decrypting or directly examining encrypted packet contents.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10069737B2Applying policies based on unique content identifiers
Publication Date: 2018.09.04 VERIZON PATENT & LICENSING INC
  • US10069737B2 patent drawing
  • US10069737B2 patent drawing
  • US10069737B2 patent drawing

AI summary

A first server device may receive, from a second server device, a unique identifier (ID) relates to content stored by the second server device; determine a policy based on the unique ID; generate a policy tag identifying the determined policy; and output the policy tag to the second server device. Outputting the policy tag may cause the second server device to apply the policy tag to a packet associated with the content, and output the packet towards a requesting user device that requests the content.