Hardware TSA Engine for Network Packet Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network performance protocols, such as Netflow, lack granular visibility into network conditions and application performance at network elements like switches and routers, making it difficult to guarantee deterministic performance for IoT and other critical networks, and result in high bandwidth consumption during data aggregation.

Innovation Solution

Implementing a hardware-based Time Series Analysis (TSA) engine on network devices to trap packets, generate TSA tuples with granular data points, and perform analysis using a software module, which then exports data efficiently through lightweight protocols like Netflow for real-time processing and visualization at higher network levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If aggregated data is collected over long periods for TSA, then network performance analysis is achieved, but bandwidth consumption increases and real-time responsiveness is lost

Engineering Contradiction:
Improvenetwork performance analysis accuracyVSAvoidbandwidth consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by performing Time Series Analysis at network elements (switches and routers) before data aggregation. The TSA engine collects and analyzes performance metrics locally in real-time, then only exports condensed results via Netflow. This eliminates the need to aggregate raw data over long periods, reducing bandwidth consumption while maintaining analysis accuracy.

Inventive Principle:
Principle #10Preliminary action

2Loss of energy

If lighter weight protocols like Netflow are used for data aggregation, then bandwidth consumption is reduced, but granular visibility into network conditions is lost

Engineering Contradiction:
Improvebandwidth consumptionVSAvoidgranular network visibility
Core Design Contradiction:
Loss of energyVSLoss of information

Solution Approach 1:

The patent applies segmentation by dividing the analysis function into two parts: granular TSA is performed at network elements using a hardware-based TSA engine, while centralized Netflow analysis focuses on aggregated results. This segmentation allows granular visibility to be maintained at the edge while bandwidth is reduced in the core network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TSA engine performs preliminary analysis at network elements, extracting only essential performance metrics before export. This preliminary action ensures that granular visibility is captured where it matters most (at the network element level) while minimizing the data volume transmitted through Netflow.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If traditional software-based TSA is used, then analysis flexibility is maintained, but processing latency increases and deterministic performance cannot be guaranteed

Engineering Contradiction:
Improveanalysis flexibilityVSAvoidprocessing latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent replaces the software-based TSA mechanism with a hardware-based TSA engine implemented in Field Programmable Gate Arrays (FPGAs). This substitution provides deterministic processing with guaranteed latency bounds while maintaining analysis flexibility through reconfigurable logic, enabling real-time performance critical for IoT and industrial networks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Productivity

If hardware-based TSA engine is implemented, then processing speed and deterministic performance are improved, but device complexity increases

Engineering Contradiction:
ImproveTSA processing speedVSAvoidnetwork device complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The TSA engine is implemented using FPGAs, which provide multi-functionality and reconfigurability. This allows the same hardware platform to be adapted for different TSA requirements and network configurations, reducing overall system complexity while maintaining high processing speed and deterministic performance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11018960B2Accelerated time series analysis in a network
Publication Date: 2021.05.25 CISCO TECHNOLOGY INC
  • US11018960B2 patent drawing
  • US11018960B2 patent drawing
  • US11018960B2 patent drawing

AI summary

Techniques for accelerated Time series analysis (TSA) in a network are described. Packets from a first network flow at a network element, such as a switch or a router, are trapped using a hardware based TSA engine at the network element. The packets are then reduced into TSA tuples including TSA data points and stored into memory. A software based TSA module performs one or more TSA actions on the stored tuples, where the TSA actions produce analysis results used to determine network performance for the network and network based applications.