Physical Layer Packet Inspection for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security systems face limitations in speed, flexibility, and reliability, particularly in access networks where upgrading control planes and managing security threats efficiently is challenging due to complex architectures and distributed control logic.

Innovation Solution

The implementation of a physical layer device with a memory control module and a physical layer module that inspects packets using a control module or regular expression module to determine security levels, allowing secure packet forwarding and centralized inspection, thereby simplifying network security management and upgrading processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If distributed control logic is used in line cards for security management, then security coverage is improved, but device complexity and management difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidcontrol plane complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts security management functions from the distributed control planes of line cards and consolidates them into a dedicated security management device. This centralizes security policy management, threat detection, and packet inspection while simplifying the control logic in individual line cards, resolving the contradiction between comprehensive security coverage and system complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a dedicated security management device as an intermediary between network traffic and line cards. This intermediary handles security-related processing, allowing line cards to maintain simple forwarding functions while achieving comprehensive security coverage through the intermediary's centralized management capabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If control planes are upgraded to improve security management, then security capabilities are improved, but network downtime and operational disruption increase

Engineering Contradiction:
Improvesecurity capabilitiesVSAvoidnetwork downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments security management functions into a separate, independently upgradable security management device. This allows security capabilities to be upgraded without affecting the operational line cards, enabling continuous network operation during security updates and eliminating network downtime associated with control plane upgrades

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security management device performs security inspections and threat detection in advance before packets reach the main switching fabric. This preliminary security processing allows for proactive threat mitigation without disrupting ongoing network operations or requiring downtime for security policy changes

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If deep packet inspection is performed to improve security detection, then threat detection accuracy is improved, but processing speed and network throughput decrease

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidnetwork throughput
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements selective deep packet inspection where only packets matching security criteria or exhibiting suspicious patterns undergo extensive inspection. Routine traffic receives streamlined processing, maintaining high throughput while achieving accurate threat detection for problematic packets, thus resolving the contradiction between inspection depth and network speed

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2742649B1Intelligent PHY with security detection for ethernet networks
Publication Date: 2015.06.03 MARVELL WORLD TRADE LTD
  • EP2742649B1 patent drawingFigure 1
  • EP2742649B1 patent drawingFigure 2
  • EP2742649B1 patent drawingFigure 3

AI summary

A physical layer device includes memory, a memory control module, and a physical layer module. The memory control module is configured to control access to the memory. The physical layer module is configured to store packets in the memory via the memory control module. The physical layer module includes an interface configured to receive the packets from a network device via a network and an interface bus. The interface bus includes at least one of a control module and a regular expression module. The at least one of the control module and the regular expression module is configured to inspect the packets to determine a security level of the packets. A network interface is configured to, based on the security level, provide the packets to a device separate from the physical layer device.