Multipath Network Device Centralized Traffic Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network systems lack effective centralized monitoring and protection mechanisms for data traffic in multipath transmission links, which are vulnerable to cyber attacks and require application software on customer equipment, complicating management and security.

Innovation Solution

A multipath capable network device with a protection software component that centrally monitors and controls data traffic across multiple paths, implementing firewall-like functionality without requiring software on customer equipment, using protection rules based on protocol, IP addresses, and content filtering to detect and block malicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application software is installed on customer equipment for monitoring and controlling data traffic, then security and management capabilities are improved, but device complexity and ease of operation deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a network device as an intermediary between the customer equipment and the network. This network device executes the protection software component and implements monitoring and control functions centrally, eliminating the need for complex application software on customer equipment while maintaining security capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If centralized monitoring and control is implemented in the network device, then ease of operation and management are improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the monitoring and control functionality from customer equipment and places it in a dedicated network device. The protection software component is implemented centrally in the network device, separating complex control functions from end-user devices and simplifying operation for customers.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If protection software is executed on customer equipment, then security against cyber attacks is improved, but ease of manufacture and deployment deteriorate

Engineering Contradiction:
Improveprotection against cyber attacksVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The network device serves as an intermediary that centralizes security functions. The protection software component runs in the network device rather than on customer equipment, simplifying manufacturing and deployment since customers only need standard equipment without additional software installation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If multiple paths are monitored and controlled individually, then measurement precision and control accuracy are improved, but loss of time and processing overhead increase

Engineering Contradiction:
Improvepath specific information trackingVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The network device implements a universal monitoring and control mechanism that handles multiple paths through a single protection software component. This multi-functional approach allows individual path tracking while maintaining centralized control, reducing processing overhead compared to distributed multi-path management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3866429B1Multipath capable network device and communication systems for centrally monitoring and controlling data traffic to and/or from a multipath capable customer equipment
Publication Date: 2023.05.24 DEUTSCHE TELEKOM AG
  • EP3866429B1 patent drawingFigure 1
  • EP3866429B1 patent drawingFigure 2
  • EP3866429B1 patent drawingFigure 3

AI summary

The present invention relates inter alia to a multipath capable network device (240) for centrally monitoring and controlling data traffic to and/or from a multipath capable customer equipment (210), wherein the multipath capable network device (240) is configured to be connected to a data network (250) and, via a multipath transmission link (260) established over at least one access network (220) to at least one multipath capable customer equipment (210) in order to enable the at least one multipath capable customer equipment (210) to get access to the data network (250) and/or services provided by the data network, and wherein the multipath capable network device (240) is further configured to monitor and control data traffic transmitted through each single multipath of an established multipath transmission link (260) from and/or to at least one multipath capable customer equipment (210) in response to at least one protection rule.