Detecting Unauthorized Tethering via Short-Lived Data Flow Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized tethering by wireless devices leads to increased network resource consumption and congestion, causing unfairness among subscribers as network operators do not allocate resources for unauthorized tethering, resulting in disproportionate bandwidth usage.

Innovation Solution

Detecting unauthorized tethering by monitoring the number of short-lived data flows from wireless devices and identifying those exceeding a data flow threshold, which indicates tethering activity, allowing for subsequent adjustments in data flow or connection limitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless devices share network access with other devices (tethering), then network connectivity and service availability are improved, but network resource consumption increases and causes congestion

Engineering Contradiction:
Improvenetwork connectivityVSAvoidnetwork resource consumption
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent performs preliminary detection of tethering activity by monitoring data flow patterns before significant resource consumption occurs. The system identifies short-lived data flows and counts them during an observation time period, detecting unauthorized tethering early to prevent excessive network resource usage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the access node continuously monitors data flows from wireless devices, compares the observed patterns against expected patterns, and takes corrective action when unauthorized tethering is detected. This closed-loop control prevents resource exhaustion by responding to detected anomalies.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If network operators allocate resources proportionally to data transferred, then fairness among authorized subscribers is improved, but unauthorized tethering devices exploit the system and consume disproportionate resources

Engineering Contradiction:
Improveresource allocation fairnessVSAvoidunauthorized resource exploitation
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary detection of unauthorized tethering by analyzing data flow patterns before significant resource consumption occurs. By identifying short-lived data flows and counting them during an observation period, the system detects tethering activity early to prevent unfair resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the harmful effect of unauthorized tethering into a detectable pattern. By monitoring for short-lived data flows characteristic of tethering activity, the system identifies and can subsequently block or throttle these connections, transforming the resource exploitation problem into a detectable and manageable condition.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If the access node monitors and inspects packets to detect unauthorized tethering, then network control and fairness are improved, but processing complexity and computational load increase

Engineering Contradiction:
Improvenetwork controlVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by focusing monitoring efforts on specific characteristics of data flows rather than analyzing all packet content. The system specifically looks for short-lived data flows with particular patterns, applying detailed inspection only where needed rather than uniformly across all traffic.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters by monitoring aggregate flow characteristics (duration, frequency, count) rather than individual packet contents. By counting short-lived data flows during an observation time period and comparing against a threshold, the system achieves reliable detection with reduced processing complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9380462B1Detecting unauthorized tethering
Publication Date: 2016.06.28 SPRINT SPECTRUM LLC
  • US9380462B1 patent drawing
  • US9380462B1 patent drawing
  • US9380462B1 patent drawing

AI summary

In systems and methods of detecting a wireless device utilizing unauthorized tethering, it is determined that a number of wireless devices in active communication with the access node meets a connections criteria, and that an access node loading meets a loading criteria. Packets received at the access node from the wireless devices are inspected to identify at least one short-lived data flow and a source wireless device of the at least one short-lived data flow. It is determined for the source wireless device a number of short-lived data flows during an observation time period, and the source wireless device is identified as performing unauthorized tethering when the number of short-lived data flows during the first time period meets a data flow threshold.