Packet Content Division for DPI Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deep Packet Inspection (DPI) equipment in communication networks raises privacy concerns by potentially exposing sensitive user information, such as usernames and passwords, as encrypting data may not always protect against DPI capture, especially when intermediate networks lack decryption capabilities.

Innovation Solution

A method is introduced where a packet is divided into alternate packets, allowing sensitive content to be transmitted over diverse wireless links, ensuring that DPI equipment can only detect either portion, thus concealing the entire content from detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If packet content is transmitted over a single wireless link, then transmission simplicity is maintained, but DPI equipment can detect and capture complete sensitive information

Engineering Contradiction:
ImproveDPI detection capabilityVSAvoidpacket transmission complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent divides a single packet into multiple alternate packets and transmits them over different wireless links. This segmentation prevents DPI equipment from capturing complete sensitive information since each link only carries a portion of the packet content, while the segmentation logic is implemented at the application layer without requiring complex infrastructure changes.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If packet content is encrypted to protect privacy, then DPI detection is prevented, but decryption capability is required at the receiving end

Engineering Contradiction:
Improveprivacy protectionVSAvoid decryption capability requirement
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Instead of encrypting the entire packet, the patent segments the packet content and transmits portions over different wireless links. This approach provides privacy protection without requiring decryption capabilities at the receiving end, as the segments are transmitted in plaintext but remain useless individually for reconstructing sensitive information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces wireless link diversity as an intermediary mechanism between the packet content and DPI equipment. By routing packet segments through multiple independent wireless links, the system creates a barrier that prevents DPI from easily capturing complete information, without requiring cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of information

If packet content is divided and transmitted over diverse wireless links, then DPI detection of complete information is prevented, but transmission and routing complexity increases

Engineering Contradiction:
Improveinformation completeness exposureVSAvoidpacket division and routing logic
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent implements packet segmentation at the application layer, dividing packets into alternate packets that are transmitted over different wireless links. The receiving end reassembles the segments based on simple identification markers, maintaining information security while using straightforward division and reassembly logic that does not require complex routing infrastructure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9553817B1Diverse transmission of packet content
Publication Date: 2017.01.24 T MOBILE INNOVATIONS LLC
  • US9553817B1 patent drawing
  • US9553817B1 patent drawing
  • US9553817B1 patent drawing

AI summary

Embodiments disclosed herein provide systems and methods for dividing packet content for transmission over diverse wireless links. In a particular embodiment, a method provides generating a packet for transmission to a destination and examining the packet to determine if content within the packet qualifies for transmission over diverse wireless links comprising a first wireless link and a second wireless link. The method further provides, if the content qualifies for transmission over the diverse wireless links, generating a first alternate packet that contains a first portion of the content and a second alternate packet that contains a second portion of the content. The method further provides transferring the first alternate packet over the first wireless link for delivery to the destination and transferring the second alternate packet over the second wireless link for delivery to the destination.