Layer-7 and 5-Tuple Information Analysis Framework for Providing Positional Flexibility In Location Determination for Service Provision
Yuri Sato, Yohei Namba, Hiroaki Nishi · 2023
In a smart community, which is an initiative to create an efficient regional society by leveraging information and communications technology (ICT), various data exchanges and data processing are performed. Owing to the demand for network transparency in data processing, packet rewriting is required at network edges. In the packet rewriting process, packets need to be analyzed after obtaining the necessary permissions. A conventional method for packet analysis is using a 5-tuple. While this method can analyze packets by a service user, it cannot analyze packets by a service. Moreover, service provision needs to take place at the appropriate locations with respect to the privacy level, and service provision locations need to be flexible enough to change even subsequent to the commencement of services. To address this issue, there is a need to enable positional flexibility in determining the location for service provision between the data source and cloud. In this study, assuming that the permission to analyze packets had been obtained within the smart community, we implemented a framework that could analyze not only 5-tuple but also layer-7 (L7) information and rewrite packet contents based on the analysis results. The process performed at the edge first analyzed the header of the incoming packet to determine whether the packet was subject to L7 information analysis. If the packet was subject to analysis, the L7 information was analyzed to determine whether the packet was subject to rewriting. A packet subject to rewriting were rewritten and forwarded accordingly. For this series of packet process, we used the Data Plane Development Kit (DPDK), a tool that could speed up packet processing. The framework was applied to the anonymization process, and the delay due to the anonymization process was 0.195 ms. With this framework, it is possible to achieve the packet content rewriting process at any point between the IoT device and the cloud by modifying the location of the edge node.