Packet Analysis Device Firewall Delay Calculation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewall devices face challenges in accurately calculating device delays, leading to potential communication quality degradation due to overloaded states, which existing technologies fail to address effectively.

Innovation Solution

A packet analysis system that calculates device delays by sorting and comparing round-trip times between communication devices and a relay device, allowing for high-accuracy delay calculations without requiring association of connections, thereby detecting overloaded states efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional packet monitoring technologies are used to calculate device delays, then basic delay measurement is achieved, but measurement precision deteriorates due to inability to accurately detect overloaded states

Engineering Contradiction:
Improvedevice delay measurement accuracyVSAvoidoverloaded state detection accuracy
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the delay measurement process into distinct components: obtaining first delay times from packets before the firewall, obtaining second delay times from packets after the firewall, and calculating device delays as the difference between corresponding pairs. This segmentation allows accurate isolation of firewall-specific delays from total transmission delays, resolving the contradiction by enabling precise measurement while maintaining reliable overloaded state detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements feedback by continuously monitoring device delays and using this information to detect overloaded states. The system feeds back delay measurements to determine whether the firewall is overloaded, creating a closed-loop system that improves both measurement precision and reliability through iterative detection and analysis of delay patterns.

Inventive Principle:
Principle #23Feedback

2Reliability

If packet monitoring is performed to detect security threats, then security protection is achieved, but communication quality deteriorates due to processing overhead causing delays

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidpacket processing delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by measuring delay times at specific points (before and after firewall processing) rather than attempting to measure all delays continuously. This allows the system to pre-establish baseline delay measurements and only calculate device delays when necessary for overloaded state detection, reducing ongoing processing overhead while maintaining security protection capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3767891B1Packet analysis program, packet analysis method, and packet analysis device
Publication Date: 2023.09.06 FUJITSU LTD
  • EP3767891B1 patent drawingFigure 1
  • EP3767891B1 patent drawingFigure 2
  • EP3767891B1 patent drawingFigure 3

AI summary

The process includes acquiring, from a relay device that relays a packet between a first communication device and a second communication device, a plurality of first delay times generated by a round trip of the packet between the first communication device and the relay device, and a plurality of second delay times generated by a round trip of the packet between the second communication device and the relay device, sorting separately the plurality of first delay times and the plurality of second delay times based on a length of a delay time, and calculating device delay times based on a first delay calculation that calculates a difference between each of the plurality of first delay times and each of the plurality of second delay times in a same rank after the sorting.