Perfect Hash Table Update for High-Speed String Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network intrusion detection systems face challenges in efficiently implementing multi-string matching algorithms, particularly in avoiding hash collisions, optimizing memory usage, and ensuring fast hash index generation, which affects the system's performance and vulnerability to attacks.

Innovation Solution

The development of progressive perfect hashing techniques, such as P2-Hashing and 2D P2-Hashing, which involve dividing transitions into independent sets, renaming states to avoid collisions, and using bipartite graph decomposition to construct perfect hash tables, allowing for efficient insertion and updating of rules without additional memory access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional hash tables are used for multi-string matching, then memory usage is reduced, but hash collisions occur which slow down matching speed

Engineering Contradiction:
Improvematching speedVSAvoidhash collision avoidance
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent segments the hash table into multiple dimensions (e.g., primary hash table and secondary hash tables). Each dimension handles a portion of the hashing, allowing the system to achieve perfect hashing (no collisions) by distributing transitions across multiple segmented structures rather than relying on a single hash table.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from traditional one-dimensional hash tables to multi-dimensional perfect hash structures. By adding dimensional layers (primary table + secondary tables), the system resolves hash collisions that would occur in a single dimension, achieving both high speed and collision-free matching.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Speed

If perfect hash tables are constructed to avoid collisions, then matching speed is improved, but construction complexity and memory usage increase

Engineering Contradiction:
Improvehash index generation speedVSAvoidhash table construction complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent performs preliminary actions during the hash table construction phase by pre-calculating and organizing transitions into independent sets using bipartite graph decomposition. This preliminary structuring simplifies the ongoing maintenance and updating operations, as the foundation is already optimized for perfect hashing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements dynamic updating mechanisms that allow the perfect hash table to be modified efficiently. By maintaining independence between transition sets and using systematic replacement strategies, the system can update rules without reconstructing the entire hash structure, keeping complexity manageable despite the perfect hashing requirement.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If rules are updated in traditional hash tables, then new patterns are added, but existing transitions may be disrupted causing collisions

Engineering Contradiction:
Improverule update capabilityVSAvoidhash table perfection maintenance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments transitions into independent sets that can be updated separately. When a rule needs updating, only the specific transition set affected is modified, while other sets remain unchanged. This segmentation isolates the impact of updates and prevents disruptions to the overall hash table perfection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs systematic parameter changes during rule updates, such as renumbering states or adjusting transition mappings in a controlled manner. By changing parameters systematically rather than arbitrarily, the system maintains the perfect hashing property while adapting to new rules.

Inventive Principle:
Principle #35Parameter changes

4Loss of time

If multiple memory accesses are allowed for hash operations, then more complex data structures can be used, but processing time increases

Engineering Contradiction:
Improvememory access timeVSAvoiddata structure complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent performs preliminary organization of transitions into independent sets during the construction phase. This preliminary action enables single-memory-access retrieval during matching operations, as the structure is pre-optimized to provide direct access without requiring multiple sequential memory reads.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By organizing the hash structure into multiple dimensions with specific access patterns, the patent enables the system to provide fast single-access retrieval. The multi-dimensional organization allows the relevant transition information to be located and retrieved in a single memory operation, avoiding the need for multiple sequential accesses.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8775393B2Updating a perfect hash data structure, such as a multi-dimensional perfect hash data structure, used for high-speed string matching
Publication Date: 2014.07.08 POLYTECHNIC INSTITUTE OF NEW YORK UNIVERSITY
  • US8775393B2 patent drawing
  • US8775393B2 patent drawing
  • US8775393B2 patent drawing

AI summary

A representation of a new rule, defined as a set of a new transition(s), is inserted into a perfect hash table which includes previously placed transitions to generate an updated perfect hash table. This may be done by, for each new transition: (a) hashing the new transition; and (b) if there is no conflict, inserting the hashed new transition into the table. If, however, the hashed new transition conflicts with any of the previously placed transitions, either (A) any transitions of the state associated with the conflicting transition are removed from the table, the hashed new transition is placed into the table, and the removed transitions are re-placed into the table, or (B) any previously placed transitions of the state associated with the new transition are removed, and the transitions of the state associated with the new transition are re-placed into the table.