Gateway Packet Marking for Fraud Detection and Resource Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current gateway technologies fail to effectively detect fraudulent behavior by local network terminals, such as generating voice over IP calls without proper protocol usage or evading authentication, leading to unauthorized access and resource consumption.

Innovation Solution

Implementing a traffic differentiation method where the gateway inserts marking information into packet headers to distinguish between packets generated by itself and those generated by local network terminals, allowing devices to process packets based on their origin and apply appropriate security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the gateway routes all packets without differentiation, then network throughput is maintained, but fraudulent behavior cannot be detected

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidpacket processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway performs preliminary marking of packets at the source before they enter the network. By inserting identification information into packet headers at the gateway level, the system enables downstream devices to detect and respond to fraudulent behavior without requiring complex analysis at each network node.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary marking mechanism that bridges the gateway and network security functions. The marking information acts as a mediator that carries identification data through the network, enabling security devices to distinguish between legitimate and fraudulent packets without requiring the gateway to perform complex real-time analysis.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If marking information is inserted into every packet header, then packet origin identification is achieved, but processing overhead increases

Engineering Contradiction:
Improvepacket origin identification accuracyVSAvoidpacket processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the packet identification function from the packet forwarding function. By separating the marking operation (performed by the gateway) from the identification operation (performed by receiving devices), the system achieves precise packet origin identification without requiring every device to perform complex analysis on every packet.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The gateway creates a simplified copy of identification information in the packet header rather than performing complex real-time analysis. This copying approach allows receiving devices to quickly extract and process identification data without significant time penalties.

Inventive Principle:
Principle #26Copying

3Reliability

If the gateway monitors all terminal traffic, then fraudulent activities are detected, but memory and calculation resources are consumed

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidmemory and calculation resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the identification function from the gateway's core processing workload. By inserting simple marking information into packet headers rather than performing complex traffic analysis, the gateway achieves fraud detection capability without consuming significant memory or calculation resources.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The marking information serves as a lightweight, disposable identifier that can be quickly inserted and processed without requiring long-term storage or complex computation. This approach enables fraud detection while minimizing resource consumption at the gateway.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentEP3949287B1Gateway and method for differentiating traffic emitted by the gateway, device and method for managing traffic
Publication Date: 2024.01.10 ORANGE SA
  • EP3949287B1 patent drawingFigure 1
  • EP3949287B1 patent drawingFigure 2
  • EP3949287B1 patent drawingFigure 3~4

AI summary

The method for differentiating traffic, implemented by the gateway (BX, Tcx) between a first (LAN) and a second (NET1) network, comprises the steps of: - inserting (E300, F300) a piece of marking information (iMRK1, iMRK2) into a label field of a packet (P, Q) transmitted by this gateway and intended to be routed to the second network (NET1) in order to differentiate whether: - the packet (Q) has been generated (F200) by the gateway, or whether - the packet (P) has been generated (E100) by a terminal (TRM) of the first network (LAN) connected to the gateway; and - sending (E400, F400) the packet (P, Q) to the second network (NET1).