Network Device Tracking via Packet Metadata Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for network providers to analyze devices accessing their networks are inadequate, particularly in real-time, especially in dual-stack IPv4/IPv6 environments, as they fail to accurately count and classify devices, manage device state, and account for traffic, leading to challenges in enforcing policies and understanding subscriber usage patterns.
Innovation Solution
A system and method that utilize Device IDs to track and classify devices by analyzing packet metadata, incorporating techniques like Layer 7 correlation and device matching, to provide real-time identification, classification, and traffic accounting, even in complex dual-stack networks, enabling accurate device counting and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network analysis methods are used in dual-stack environments, then basic routing functionality is maintained, but device counting and classification accuracy deteriorates
Solution Approach 1:
The patent segments the network analysis function into multiple specialized components: Device ID extraction module, classification module, state management module, and traffic accounting module. Each component handles a specific aspect of device analysis, allowing the system to process complex dual-stack traffic accurately by breaking down the overall task into manageable segments that can handle IPv4 and IPv6 independently and simultaneously
Solution Approach 2:
The patent adds a new dimension of analysis by introducing Device IDs as a unique identifier that transcends the traditional IP address dimension. This allows devices to be tracked and classified across both IPv4 and IPv6 protocols simultaneously, creating a unified view of devices in dual-stack environments where traditional single-protocol methods fail
2Loss of information
If real-time device tracking is implemented, then subscriber behavior understanding is improved, but network processing overhead increases
Solution Approach 1:
The patent performs preliminary action by extracting and assigning Device IDs at the packet capture stage, before full processing occurs. The state management module pre-establishes device states and classifications, so that subsequent traffic accounting and analysis operations can proceed efficiently without repeated heavy processing, reducing overall network energy consumption while maintaining real-time tracking
Solution Approach 2:
The system implements self-service through automated device state management where the network system automatically tracks, classifies, and updates device information without requiring manual intervention. The traffic accounting mechanisms automatically correlate packets with device states, enabling continuous real-time monitoring while minimizing the operational energy required for manual management
3Adaptability or versatility
If comprehensive device classification is performed, then policy enforcement capability is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal classification framework where a single Device ID and classification structure serves multiple functions: device identification, traffic accounting, policy enforcement, and network analysis. This multi-functional approach allows comprehensive policy enforcement capabilities without requiring separate complex systems for each function, as the classification module provides a unified basis for all device-related operations
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and system for analyzing devices on a network are provided. The method includes: receiving at least one packet from a Customer Premises Equipment (CPE); determining identity metadata associated with the at least one packet; and analyzing the at least one packet to determine a device associated with the at least one packet. The system for analyzing devices on a network includes: a packet processor configured to receive at least one packet from a CPE; a subscriber/session identity module configured to determine identity metadata with the at least one packet; and a device tracker module configured to analyze the at least one packet to determine a device associated with the at least one packet.