Subscriber-Controlled Network Traffic Inspection Filters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network traffic inspection methods lack transparency for subscribers and other parties regarding filtering processes, which can lead to concerns over data privacy and collection practices, and may require excessive computational resources or slow network traffic.

Innovation Solution

Implementing a system that allows subscribers to modify and view filter criteria used by DPI appliances, with transparent data collection practices, and providing authorized access to inspection data, enabling subscribers to control what data is collected and how it is used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If deep-packet inspection is implemented to fully inspect each data packet, then measurement precision and data collection completeness are improved, but device complexity and computational resource requirements increase significantly

Engineering Contradiction:
Improveinspection accuracyVSAvoidcomputational resource requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network traffic inspection process by implementing filters that divide traffic into inspected and non-inspected portions based on filter criteria. This allows selective deep-packet inspection of only relevant traffic segments rather than all traffic, reducing computational overhead while maintaining inspection accuracy for targeted data packets.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If deep-packet inspection is implemented to fully inspect each data packet, then measurement precision and data collection completeness are improved, but network speed deteriorates due to processing delays

Engineering Contradiction:
Improveinspection accuracyVSAvoidnetwork traffic speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The patent segments the network traffic inspection process by implementing filters that divide traffic into inspected and non-inspected portions based on filter criteria. This allows selective deep-packet inspection of only relevant traffic segments rather than all traffic, reducing computational overhead while maintaining inspection accuracy for targeted data packets.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If transparent access to inspection data is provided to multiple parties, then ease of operation and data accessibility are improved, but security risks and unauthorized access potential increase

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic access control where filter criteria and data access permissions can be modified by subscribers in real-time. This dynamic system allows authorized parties to access inspection data while maintaining security through configurable access rules that can adapt to different security requirements and user preferences.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent provides feedback mechanisms where subscribers can view and modify filter criteria, and authorized parties can access inspection data with appropriate permissions. This feedback loop enables transparent operation while maintaining security through controlled access and the ability for users to manage their own data privacy preferences.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8705356B2Transparent network traffic inspection
Publication Date: 2014.04.22 CENTURYLINK INTELLECTUAL PROPERTY LLC
  • US8705356B2 patent drawing
  • US8705356B2 patent drawing
  • US8705356B2 patent drawing

AI summary

Methods and systems are disclosed for providing parties with levels of transparency into filtering functionality of network traffic inspection implementations. Embodiments include receiving a filter change request from a subscriber over a network that defines a modification to a set of filter criteria for filtering network traffic, the filter criteria being stored in association with the subscriber in a filter criteria data store; updating the set of filter criteria in the filter criteria data store as a function of the filter change request; receiving a content dataset relating to the network traffic; identifying the content dataset as being associated with the subscriber; retrieving the set of filter criteria associated with the subscriber from the data store; and filtering the network traffic as a function of the set of filter criteria. Embodiments further provide layers of access for different entities to the filtered traffic.