Detecting Tethered Devices via TCP Error Patterns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireline internet service providers face challenges in detecting dual-Wi-Fi ad-hoc tethering, where mobile devices connect to high-speed Wi-Fi networks while simultaneously providing hotspots to other devices, leading to unmanaged access to wireline internet services.

Innovation Solution

Monitoring Transmission Control Protocol (TCP)/IP traffic flows to establish a baseline profile of error indicative criteria, such as duplicate ACKs, and identifying deviations beyond a threshold to determine if a device is tethered, allowing network operators to differentiate between regular and tethered traffic flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dual-Wi-Fi ad-hoc tethering is enabled on mobile devices, then internet access sharing capability is improved, but network management and detection capability deteriorates

Engineering Contradiction:
Improveinternet access sharing capabilityVSAvoidtethering detection capability
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces TCP error transmission patterns as an intermediary indicator to detect tethering. Instead of directly monitoring tethering activity, the system analyzes duplicate ACKs and retransmission patterns in TCP traffic flows, which serve as indirect but reliable signals of tethering behavior without requiring direct access to device tethering status.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by continuously monitoring TCP error patterns and comparing them against baseline profiles. When error patterns deviate from the baseline beyond a threshold, the system generates a tethering detection signal, creating a closed-loop detection mechanism that adapts to normal traffic variations while identifying anomalous tethering activity.

Inventive Principle:
Principle #23Feedback

2Measurement precision

If TCP error monitoring is implemented to detect tethering, then tethering detection accuracy is improved, but network traffic analysis complexity increases

Engineering Contradiction:
Improvetethering detection accuracyVSAvoidnetwork traffic analysis complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts specific TCP error indicators (duplicate ACKs and retransmission patterns) from the overall TCP traffic flow, focusing analysis on these particular error types rather than attempting to analyze all traffic characteristics. This extraction approach simplifies the analysis complexity while maintaining detection accuracy by concentrating on the most informative error patterns.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes parameters by establishing baseline profiles of TCP error rates under normal conditions and comparing actual error rates against these baselines. By transforming the detection problem into a statistical comparison of error rate parameters rather than complex pattern recognition, the system reduces analysis complexity while preserving detection precision.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If baseline profiling of TCP error rates is performed, then false positive reduction is improved, but processing time increases

Engineering Contradiction:
Improvefalse positive reductionVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary action by establishing baseline TCP error profiles during normal operation before tethering occurs. These baselines are pre-computed and stored, allowing the system to quickly compare actual error rates against established patterns without performing complex analysis in real-time, thus reducing processing time while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies partial action by monitoring only specific TCP error types (duplicate ACKs and retransmissions) rather than all possible traffic parameters. This selective monitoring approach reduces the amount of data processing required while maintaining sufficient accuracy for tethering detection, thereby reducing processing time without significantly compromising false positive reduction.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11924078B2Identifying a tethered device using TCP error transmissions
Publication Date: 2024.03.05 CHARTER COMM OPERATING LLC
  • US11924078B2 patent drawing
  • US11924078B2 patent drawing

AI summary

Various embodiments comprise systems, methods, mechanisms, and apparatus by which a network operator such as a wireline internet service provider (ISP) may determine that an endpoint device has one or more other wireless devices tethered to it, such as a mobile handset providing dual-Wi-Fi ad-hoc tethering (i.e., connected to a high-speed Wi-Fi network while simultaneously providing Wi-Fi connections to wireless devices tethered to the mobile handset), by monitoring Transmission Control Protocol (TCP)/IP traffic flow associated with endpoint devices (i.e., to or through endpoint devices), characterizing these traffic flows in accordance with one or more error indicative criteria to establish thereby a baseline profile of error indicative criteria that is indicative of a TCP/IP traffic flow associated with an endpoint device that is not associated with tethering (e.g., a rate or number of duplicate ACKs), wherein deviations from the baseline profile of error indicative criteria beyond a threshold are indicative of a TCP/IP traffic flow associated with an endpoint device that is associated with tethering.