P2P Traffic Management via Application Identifier Tagging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods are inadequate for effectively detecting and controlling P2P traffic, particularly encrypted P2P packets, due to variations in technical standards and the difficulty in inspecting encrypted traffic, leading to network congestion and security vulnerabilities.

Innovation Solution

A P2P traffic management system utilizing P2P flow agents and security gateways that monitor and control encrypted P2P traffic by adding application identifiers to packets and using these identifiers to apply policies for selective passage, bandwidth restriction, or packet discard, without requiring payload or header analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If P2P traffic is monitored and controlled using existing methods, then network security and traffic management are improved, but the processing overhead and time consumption increase significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by embedding flow agents within P2P applications that pre-identify and tag packets with application identifiers before transmission. This preliminary tagging enables security gateways to recognize and control P2P traffic without performing time-consuming payload or header analysis, thus improving network security while minimizing processing time overhead

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the essential identifying feature (application identifier) from P2P traffic and separates it from the encrypted payload. By extracting only the necessary identification information and transmitting it alongside encrypted data, the system achieves effective traffic control without requiring decryption or deep packet inspection, reducing processing time while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If encrypted P2P packets are inspected using signature analysis, then detection accuracy is improved, but the cost and time for signature development and analysis increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsignature analysis time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent introduces an intermediary mechanism (flow agent) that bridges the gap between encrypted P2P traffic and security monitoring. The flow agent adds application identifiers as intermediary tags that enable accurate detection without requiring signature analysis of the encrypted payload, eliminating the need for time-consuming signature development while maintaining high detection accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the application identifier from the P2P traffic flow and separates it from the encrypted data stream. This extraction enables security gateways to identify and control traffic based on the identifier alone, achieving precise detection without the need for resource-intensive signature matching against encrypted content

Inventive Principle:
Principle #2Taking out (Extraction)

3Difficulty of detecting and measuring

If P2P traffic is controlled by analyzing packet headers and payloads, then detection capability is improved, but the device complexity and processing overhead increase

Engineering Contradiction:
Improvedetection capabilityVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The patent extracts only the essential application identifier information from P2P traffic and transmits it separately from the encrypted payload. This extraction simplifies the detection mechanism at security gateways, which only need to read the identifier tag rather than perform complex analysis of packet headers and payloads, reducing device complexity while maintaining detection capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The flow agent performs preliminary identification and tagging of P2P packets with application identifiers before they reach the security gateway. This preliminary action simplifies the gateway's task to mere identifier matching rather than complex packet analysis, reducing processing overhead and system complexity while preserving detection capability

Inventive Principle:
Principle #10Preliminary action

4Productivity

If network equipment processes large amounts of P2P traffic, then traffic throughput is maintained, but processing capabilities are consumed and network congestion occurs

Engineering Contradiction:
Improvetraffic throughputVSAvoidprocessing capability
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent extracts minimal identification information (application identifier) from P2P traffic and transmits it alongside encrypted data. This allows network equipment to process and control traffic based on the lightweight identifier without requiring resource-intensive decryption or deep packet inspection, maintaining high traffic throughput while minimizing processing capability consumption

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the parameter used for traffic identification from complex payload content to a simple application identifier tag. This parameter change enables network equipment to efficiently process large volumes of P2P traffic using lightweight identifier matching, maintaining high throughput while reducing processing energy consumption and preventing network congestion

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8146133B2Apparatus and method for managing P2P traffic
Publication Date: 2012.03.27 ELECTRONICS & TELECOMM RES INST
  • US8146133B2 patent drawing
  • US8146133B2 patent drawing
  • US8146133B2 patent drawing

AI summary

The invention relates to a P2P traffic management apparatus and method. A P2P flow agent monitors an executed application program to extract a P2P application program, adds application identifiers to packets generated by the application program according to a set policy, and transmits the packets. In this case, a P2P security gateway monitors the inflowing packets from the P2P flow agent to extract packets having the application identifiers, uses the extracted application identifiers to inquire and acquire a related policy, and controls the packets according to the acquired policy.