System and method for network traffic processing based on federated services and user groups
By introducing multiple MODEM pools and VRF instances into the cellular system, combining different RF channels and spectrum parts, network service isolation between user groups and services is achieved, solving the problem of insufficient service isolation in the cellular network, and improving data security and network flexibility.
Patent Information
- Application Number
- CN202010492322.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-06-04
- Filing Date
- 2020-06-03
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2040-06-03
AI Technical Summary
In cellular network systems, the services of different Level 2 operators cannot be effectively isolated, resulting in insufficient security risks and flexibility, especially when multiple service providers share the same network resources.
By introducing multiple MODEM pools and virtual routing and forwarding (VRF) instances into the cellular system, combining different RF channels and spectrum parts, network service isolation for each user group and each service is achieved, and different identifiers and routing information are used for encapsulation and processing.
Improve the data security and flexibility of cellular systems, ensure data isolation of different user groups and services, prevent data leakage, and handle their respective services according to different rules, enhancing the flexibility and security of the network.
Smart Images

Figure CN112040451B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure generally relates to processing network traffic based on federated services and user groups. Background Art
[0002] Cellular network providers (also known as Tier 1 mobile network operators (MNOs)) can use cellular systems to provide telephony, data, and other services to subscribers via wireless devices (such as mobile phones, tablets, etc.). Cellular network providers have a designated spectrum (e.g., a range of frequencies) from which they derive the network bandwidth (measured in Hertz (Hz)) and capacity (measured in bits per second (bps)) used to provide cellular services to subscribers. This bandwidth and capacity can be greater than that required to provide the services offered by the cellular network provider. To increase revenue, the cellular network provider can sell a portion of the bandwidth, capacity, and services to Tier 2 operators (also known as mobile virtual network operators (MVNOs) or virtual network operators (VNOs)). In this model, Tier 1 operators are called Value Added Resellers (VARs) and can resell bandwidth, capacity, and services that would otherwise be "stranded" (i.e., not used to provide revenue to the VAR). The cellular system is then used to provide access to the designated cellular services or network services to the Tier 2 operator's subscribers. Although cellular systems are capable of processing traffic for different Level 2 operators, in some systems, traffic associated with a first Level 2 operator and a first service is not isolated from traffic associated with a second Level 2 operator and a second service, which may pose potential security risks to the Level 2 operators (e.g., the risk that traffic associated with a particular Level 2 operator or a particular service is processed by or provided to a device associated with a different Level 2 operator or a different service). Summary of the Invention
[0003] In a particular embodiment, a system for communication based on services and user groups includes multiple modems corresponding to multiple modem pools. The multiple modems include a first modem corresponding to a first modem pool and a second modem corresponding to a second modem pool. The first modem is configured to generate a first data packet based on a first radio frequency (RF) signal. The first data packet includes first data and a first virtual routing and forwarding (VRF) instance identifier. The second modem is configured to generate a second data packet based on a second RF signal. The second data packet includes second data and a second VRF instance identifier. The system also includes a network device in communication with the multiple modems. The network device is configured to receive the first data packet and transmit the first packet to the first device via a network. The first packet includes first data and a first header including a first indicator. The first indicator is associated with a first VRF instance corresponding to the first VRF instance identifier. The first VRF instance identifier is associated with a first service, a first user group, or both. The network device is further configured to receive a second data packet and transmit the second packet to the second device via the network. The second packet includes second data and a second header including a second indicator. The second indicator is associated with a second VRF instance corresponding to the second VRF instance identifier. The second VRF instance identifier is associated with a second service, a second user group, or both.
[0004] In another specific embodiment, a satellite includes a payload comprising one or more antennas. The satellite includes a memory configured to store channel mapping data, the channel mapping data indicating a mapping of at least one radio frequency (RF) channel to different RF channels. The satellite further includes a processor configured to initiate transmission of a second RF signal from the one or more antennas to a first device (e.g., a subscriber device) based on the channel mapping data, a first service associated with the first device, and a first user group associated with the first device. The second RF signal is based on a first RF signal received from radio frequency equipment (RFE) at the one or more antennas. The first RF signal corresponds to a first RF channel, and the second RF signal corresponds to a second RF channel different from the first RF channel.
[0005] In another specific embodiment, a method includes receiving a first data packet from a first modem in a first modem pool at a network device; transmitting the first packet from the network device to the first device via a network; receiving a second data packet from a second modem in a second modem pool at the network device; and transmitting the second packet from the network device to the second device via the network. The first data packet includes first data and a first VRF instance identifier. The first packet includes the first data and a first header including a first indicator associated with the first VRF instance. The first VRF instance is associated with a first service and a first user group. The second data packet includes second data and a second VRF instance identifier. The second packet includes second data and a second header including a second indicator associated with the second VRF instance. The second VRF instance identifier is associated with a second service and a second user group. BRIEF DESCRIPTION OF THE DRAWINGS
[0006] Figure 1 is a block diagram illustrating a first example of an implementation of a system for processing network traffic associated with different virtual routing and forwarding (VRF) instances corresponding to different user groups and service pairs;
[0007] Figure 2 is a diagram illustrating a second example of an embodiment of a system for processing network traffic associated with different VRF instances corresponding to different user groups and service pairs;
[0008] Figure 3 is a diagram illustrating a third example of an embodiment of a system for processing network traffic associated with different VRF instances corresponding to different user groups and service pairs;
[0009] Figure 4 It shows that Figures 1 to 3 a ladder diagram of a first example of network traffic transmitted by a system;
[0010] Figure 5 It shows that Figures 1 to 3 a ladder diagram of a second example of network traffic transmitted by the system;
[0011] Figure 6 is a flow chart of an example of a method for processing network traffic received from a device based on user groups and services associated with the device;
[0012] Figure 7 is a flow chart of an example of a method for processing network traffic to be transmitted to a device based on user groups and services associated with the device; and
[0013] Figure 8is a flow chart of an example of a method of processing network traffic associated with different virtual routing and forwarding (VRF) instances corresponding to different user group and service pairs. DETAILED DESCRIPTION
[0014] Specific embodiments are described with reference to the accompanying drawings. In the specification, common features throughout the accompanying drawings are represented by common reference numerals. As used herein, various terms are only used to describe specific embodiments and are not intended to be restrictive. For example, the singular forms "one", "an" and "the / said" are also intended to include plural forms, unless the context clearly indicates otherwise. It will be further understood that the term "including" can be used interchangeably with "comprising". In addition, it will be understood that the term "wherein" can be used interchangeably with "herein". As used herein, "exemplary" can indicate examples, embodiments and / or aspects, and should not be interpreted as restrictive or indicating preferences or preferred embodiments. As used herein, ordinal terms (e.g., "first", "second", "third", etc.) used to modify elements (such as structures, components, operations, etc.) do not themselves indicate any priority or order of an element relative to another element, but are merely distinguished from another element with the same name (if no ordinal terms are used). As used herein, the term "group" refers to a group of one or more elements, and the term "plurality" refers to a plurality of elements.
[0015] In the present disclosure, terms such as "determine", "calculate", "shift", "adjust", etc. can be used to describe how to perform one or more operations. It should be noted that such terms should not be interpreted as restrictive, and other technologies can be used to perform similar operations. In addition, as referred to herein, "generate", "calculate", "use", "select", "access" and "determine" can be used interchangeably. For example, "generate", "calculate" or "determine" a parameter (or signal) can refer to actively generating, calculating or determining a parameter (or signal), or can refer to using, selecting or accessing a parameter (or signal) that has been generated (such as generated by another component or device). As used herein, "coupling" can include "communicative coupling", "electrical coupling" or "physical coupling", and can also (or alternatively) include any combination thereof. Two devices (or components) can be coupled (e.g., communicatively coupled, electrically coupled or physically coupled) directly or indirectly via one or more other devices, components, wires, buses, networks (e.g., wired networks, wireless networks or combinations thereof), etc. As an illustrative, non-limiting example, two electrically coupled devices (or components) may be included in the same device or in different devices and may be connected via electronics, one or more connectors, or inductive coupling. In some embodiments, two devices (or components) that are communicatively coupled (such as electrically communicating) may send or receive electrical signals (digital or analog) directly or indirectly (such as via one or more wires, buses, networks, etc.). As used herein, "directly coupled" may include two devices that are coupled (e.g., communicatively coupled, electrically coupled, or physically coupled) without an intermediate component.
[0016] The embodiments disclosed herein are directed to systems and methods for providing network service isolation on a per-user group and per-service basis within a cellular system. In some embodiments, the systems and methods described herein are described with reference to a joint network. In other embodiments, the systems and methods described herein are applicable to other types of networks. A cellular system includes multiple components, such as network equipment (e.g., "core network" equipment), base stations, beamforming networks, radio frequency (RF) equipment (RFE), switching circuits, or other components. An operator of a cellular system (e.g., a Tier 1 operator) can sell access to the cellular system to other closed user groups ("CUGs") to provide various network services. As used herein, a "CUG" refers to a Tier 2 operator (e.g., a service provider) that pays for access to equipment associated with a Tier 1 operator. For convenience, members of a CUG are referred to as users. As a non-limiting example, a Tier 2 operator includes a mobile virtual network operator (MVNO) and a virtual network operator (VNO). In a particular aspect, an MVNO includes multiple CUGs. A person who subscribes to a service provided by a Tier 2 operator is referred to herein as a subscriber. In a particular aspect, the same type of service is provided by multiple CUGs. By isolating network traffic associated with each user group (e.g., MVNO, CUG within an MVNO, or CUG associated with a service type) and each service, the described systems and methods improve the security of data handled by the cellular system. Furthermore, the flexibility of the cellular system is increased because data associated with different user groups and different services can be handled according to different rules or standards (rather than a single set of rules or standards for all user groups and all services).
[0017] In a particular aspect, the service includes at least one of: first generation (1G) cellular communication, second generation (2G) cellular communication, third generation (3G) cellular communication, fourth generation (4G) cellular communication, fifth generation (5G) cellular communication, high speed packet access (HSPA), high speed downlink packet access (HSDPA), high speed uplink packet access (HSUPA), short message service (SMS), multimedia message service (MMS), Internet of Things (IoT) communication, Worldwide Interoperability for Microwave Access (WiMax) communication, Institute of Electrical and Electronics Engineers (IEEE) 802.11x communication, Wi-Fi communication, digital video broadcasting-satellite (DVB-S) communication, digital video broadcasting-satellite-second generation (DVB-S2) communication, DVB-S2 extension (DVB-S2X) communication, digital video broadcasting-return channel via satellite (DVB-RCS) communication, second generation DVB interactive satellite system (DVB-RCS2) communication, or proprietary government system communication.
[0018] To achieve per-user group and per-service network traffic isolation, traffic associated with different user groups and service pairs is encapsulated differently and routed and forwarded through the cellular system using different routing information. In a particular embodiment, base stations and network devices (e.g., mobility management entities, packet gateways such as packet data network gateways (PGWs), serving gateways (SGWs), etc.) are configured to use different identifiers to encapsulate traffic associated with different user groups (e.g., different MVNOs) and service pairs. For illustration, in a particular embodiment, the network devices maintain different virtual routing and forwarding (VRF) instances for each user group and service pair, which includes maintaining different routing information base (RIB) data for each user group and service pair. Due to the different RIB data, traffic associated with a first user group and a first service can traverse different paths through the external network compared to traffic associated with a second user group and a second service.
[0019] In a specific embodiment, the services associated with different user groups and service pairs are processed by different devices (or different components) within the cellular system. For illustration, the base station includes multiple modem pools (e.g., physical modem pools, virtual modem pools, or logical modem pools), the multiple modem pools including one or more modems, and the modems in each modem pool are configured to process data packets associated with the corresponding user group and the corresponding service. As a specific example, one or more modems in a first modem pool process data packets associated with the first user group and the first service (as indicated by the VRF instance identifier in the data packet), and one or more modems in a second modem pool process data packets associated with the second user group and the second service. In a specific aspect, the one or more modems in the first modem pool are different from the one or more modems in the second modem pool. In some examples, the first user group and the first service are different from the second user group and the second service, respectively. In some examples, the first user group is different from the second user group and the first service is the same as the second service (e.g., having the same type). In some examples, the first user group is the same as the second user group and the first service is different from the second service.
[0020] In addition to isolating network traffic through the network and cellular system by user group and service pair, the cellular system can enable different user groups and service pairs to access the cellular system via different portions of the RF spectrum (e.g., different RF channels or portions thereof). In a particular embodiment, a switching circuit on the satellite is configured to receive RF signals from RF circuitry coupled to a base station and is configured to perform a "beam-to-beam" switching (e.g., RF signal switching) such that an RF signal received from the RF circuitry and corresponding to traffic associated with a first user group and a first service is used to generate a second RF signal corresponding to a first portion of the RF spectrum associated with the first user group and the first service. Similarly, a third RF signal corresponding to traffic associated with a second user group and the second service is used to generate a fourth RF signal corresponding to a second portion of the RF spectrum associated with the second user group and the second service. The second RF signal is provided to user devices associated with the first user group and subscribed to the first service. The fourth RF signal is provided to user devices associated with the second user group and subscribed to the second service. In certain embodiments, RF signals are deployed in an overlay mode at the same location so that multiple devices at the same location can access the cellular system via different portions of the RF spectrum (e.g., via different RF channels or portions thereof). The RF signals are mapped to corresponding VRF instances (e.g., mapped to corresponding user groups and services) and converted into data packets, which are isolated and processed by the VRF instances as described herein.
[0021] By isolating and different user groups (for example, different service providers, government clients or enterprise clients) and serving to associated network business, compared with other systems, system described herein has improved data security.For example, use different VRF instance identifiers to encapsulate and process and different user groups and serve to associated data, thereby will with specific user group and serve to associated data and with other user group and serve to associated data separation (for example, isolation).In addition, use different RF channels (or other frequency bands) to carry out the communication between cellular system and the subscriber equipment, thereby further will with specific user group and serve to associated communication and with other user group and serve to associated communication isolation.With respect to different user groups (for example, different service providers) and different services, this network business isolation has improved the data security at the cellular system place.In addition, because can use to be different from other user groups and serve to handle the rule or strategy of associated data and specific user group and serve to associated business, therefore increased the flexibility of cellular system.
[0022] As an illustrative example, network business isolation based on every user group and every service is described. In some embodiments, network business isolation is provided based on various standards (such as quality of service, user group, service, user or its combination). In these embodiments, different parts of RF spectrum are allocated based on standards. For example, the first part of RF spectrum corresponds to the first quality of service, the first user group, the first service, the first user or its combination, and the second part of RF spectrum corresponds to the second quality of service, the second user group, the second service, the second user or its combination. The business that meets different standards is processed by different devices (or different components). For example, one or more first MODEMs are configured to process the data packets associated with the first quality of service, the first user group, the first service, the first user or its combination, and one or more second MODEMs are configured to process the data packets associated with the second quality of service, the second user group, the second service, the second user or its combination.
[0023] Figure 1 An example of a system 100 is shown that is configured to handle network traffic associated with different virtual routing and forwarding (VRF) instances corresponding to different user groups and service pairs. System 100 includes a satellite 102, an RFE 106, a base station 118, and a core network 130. Satellite 102 includes switching circuitry 104 and a beamforming network 108. Core network 130 includes network equipment 142, a subscriber data server 136, and an Internet Protocol (IP) multimedia subsystem server 134. Although components 102, 104, 106, 108, 118, 134, 136, and 142 are shown as being included in system 100, in other embodiments, one or more of components 102, 104, 106, 108, 118, 134, 136, and 142 are not included (and the corresponding functions are performed by one or more of the remaining components). In other embodiments, system 100 includes additional components not shown.
[0024] Satellite 102 is configured to perform communications with one or more devices (e.g., one or more subscriber devices). As non-limiting examples, the one or more devices include mobile devices such as mobile phones, tablet computers, laptop computers, smart watches, media playback devices, navigation systems, personal digital assistants (PDAs), satellite phones, vehicles (or components thereof), or combinations thereof. In some embodiments, the one or more devices also include fixed computerized devices. Satellite 102 includes a processor 180, a memory 182, a switching circuit 104, a beamforming network 108, and a payload 184. The payload 184 includes one or more antennas configured to perform communication operations with the one or more devices. In a particular embodiment, the system 100 includes or corresponds to a satellite-based cellular system. In another particular embodiment, the system 100 includes or corresponds to a hybrid cellular system (e.g., a hybrid satellite and terrestrial cellular system). For example, the satellite 102 can communicate with the one or more devices via one or more components of a terrestrial-based cellular system (such as (one or more) antennas, (one or more) satellites, (one or more) towers, etc.). In an alternative embodiment, the system 100 includes or corresponds to a terrestrial-based cellular system, as described with reference to FIG. Figure 2 as further described.
[0025] The switching circuit 104 is configured to divide a spectrum (e.g., an RF spectrum) into a plurality of smaller frequency "slices" (e.g., sub-bands, channels, sub-channels, etc.). As an example, the switching circuit 104 is configured to divide an input ultra-wideband signal into channels or sub-channels for transmission to another device or component. Although RF signals are described herein, in other embodiments, other frequency signals may be used. In a specific embodiment, the switching circuit 104 is configured to divide the RF signal into a bandwidth narrower than other filtering equipment. As a specific example, other filtering equipment can divide the RF signal into a size having a range of approximately 30-70 megahertz (MHz), which is referred to as a "transponder" or "transponder size." In contrast, the switching circuit 104 is configured to divide the RF spectrum (or another spectrum) into frequency bands or fragments of approximately 31 kilohertz (kHz). Although referred to as portions of a frequency band or frequency channel (e.g., an RF channel), the signal may also be divided into time-based channels or sub-channels (e.g., for time division multiple access (TDMA) signals) or code-based channels or sub-channels (e.g., for code division multiple access (CDMA) signals).
[0026] The beamforming network 108 is configured to enable beamforming of one or more devices. In particular embodiments, the beamforming network 108 is configured to apply beamforming weights to RF signals (e.g., "beams") to modify the directionality and spatial selectivity of the RF signals to and from the one or more devices. In particular embodiments, the beamforming weights are stored in the memory 182 as beamforming data 110, and each set of beamforming weights is associated with a corresponding user group and a corresponding service (e.g., beamforming weights are allocated on a per-user-group and per-service basis), as further described herein.
[0027] exist Figure 1 In the illustrated embodiment, beamforming network (BFN) 108 includes a first BFN 112, a second BFN 114, and an Nth BFN 116. Although three BFNs are shown in BFN 108, in other embodiments, N can be any integer greater than two. In a particular embodiment, first BFN 112 is assigned to operate on RF signals associated with a first service, a first user group, or both. For example, first BFN 112 is associated with first beamforming weights associated with the first service, the first user group, or both. In a particular aspect, second BFN 114 is assigned to operate on RF signals associated with a second service, the second user group, or both. In a particular aspect, each of BFNs 112, 114, and 116 is assigned to operate on RF signals on a unique service and user group pair.
[0028] As used herein, a "user" includes a Tier 2 operator or other service provider that provides services by using the network resources of a Tier 1 operator, such as a Tier 1 operator that owns and operates the system 100. A CUG includes a Mobile Virtual Network Operator (MVNO), a Virtual Network Operator (VNO), or other service provider that uses the system 100 to provide services to subscribers. In particular aspects, a "user group" includes multiple users, multiple MVNOs, CUGs within an MVNO, CUGs associated with a particular type of service, or a combination thereof. A subscriber includes a person who subscribes to services provided by a service provider (e.g., a CUG) and uses a device (such as a mobile phone or other device) to access the system 100. In Figure 1 In the particular embodiment shown, the switching circuitry 104 and the beamforming network 108 are integrated into the satellite 102. In another particular embodiment, the switching circuitry 104 and the beamforming network 108 are coupled between the RFE 106 and the base station 118, as shown in FIG. Figure 2 In certain aspects, base stations 118, core network 130, or both include terrestrial components.
[0029] In a particular embodiment, the switching circuit 104 is configured to generate multiple groups of RF signals associated with corresponding portions of the RF spectrum. For example, each group of RF signals includes one or more RF signals corresponding to a specific portion of the RF spectrum, such as a specific RF channel (or specific multiple RF channels). The multiple groups of RF signals include at least one RF signal associated with a specific portion of the RF spectrum, the specific portion of the RF spectrum being associated with a unique pair including a user group and a service. For illustration, the multiple RF signals include a first RF signal corresponding to a specific portion of the RF spectrum (e.g., a specific RF channel), the specific portion being designated for communications associated with a first user group (e.g., a first MVNO) and a first service. For further illustration, the multiple RF signals include a second RF signal corresponding to a specific portion of the RF spectrum (e.g., a second specific RF channel), the specific portion being designated for communications associated with a second user group (e.g., a second MVNO) and a second service.
[0030] In particular embodiments, the beamforming network 108 is configured to adjust the phase, amplitude, or both of the RF signal based on beamforming data indicating a first set of beamforming weights associated with a first user group and a first service and a second set of beamforming weights associated with a second user group and a second service. For example, the first BFN 112 is configured to adjust the phase, amplitude, or both of the RF signal based on the first set of beamforming weights, and the second BFN 114 is configured to adjust the phase, amplitude, or both of the RF signal based on the second set of beamforming weights. The RF signal is transmitted (e.g., deployed) to one or more locations to enable wireless communication with devices associated with the two user groups and the two services via different portions of the RF spectrum, as further described herein. Although illustrated as two components, in particular embodiments, the switching circuitry 104 and the beamforming network 108 are integrated into or correspond to a single component, or the operations of the switching circuitry 104 and the beamforming network 108 are performed by the processor 180.
[0031] The RFE 106 is configured to process RF signals received from one or more devices or to be sent (e.g., transmitted) to one or more devices via the satellite 102. By way of example, the RFE 106 includes one or more filters, one or more amplifiers, one or more mixers, one or more other components, or a combination thereof, which processes RF signals received from one or more user equipment (UE) devices or to be sent to one or more user equipment (UE) devices via the satellite 102.
[0032] The base station 118 includes a processor 120 and a memory 122, and the base station 118 is configured to receive RF signals from one or more devices (e.g., via components 102-108, 112-116) and process the RF signals. In certain embodiments, the processor 120 is configured to execute instructions stored in the memory 122 to perform the operations described herein. In alternative embodiments, the base station 118 includes hardware, such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a controller, that performs the operations described herein.
[0033] For illustration, base station 118 is configured to convert RF signals into a digital domain to generate data packets for routing through core network 130. To generate data packets, base station 118 includes multiple modem pools, which include multiple modems. In a specific embodiment, each modem pool is assigned to a specific user group (e.g., a specific MVNO) and a specific service, and one or more modems from a specific modem pool are assigned to process data packets associated with the corresponding user group and the corresponding service. Although described as a separate modem, in some embodiments, base station 118 includes a single modem that is virtualized to provide a virtual modem pool and a virtual modem that perform the operations of the modem described herein. In other embodiments, the modem can be a physical modem, a logical modem, a virtual modem, or a combination thereof.
[0034] exist Figure 1 In the illustrated embodiment, the base station 118 includes a first MODEM 124, a second MODEM 126, and an Nth MODEM 128. For example, each of the first MODEM 124, the second MODEM 126, and the Nth MODEM 128 is instantiated at the base station 118. Although three MODEMs are shown, in other embodiments, N can be any integer greater than 2. Each MODEM is part of a MODEM pool. As an example, the first MODEM pool 125 includes the first MODEM 124, the second MODEM pool 127 includes the second MODEM 126, and the Nth MODEM pool 129 includes the Nth MODEM 128. Although one MODEM per MODEM pool is shown, this illustration is not limiting. A MODEM pool may include any number of MODEMs. Figure 1In the illustrated embodiment, each of the first modem pool 125, the second modem pool 127, and the Nth modem pool 129 is instantiated at the base station 118. In certain embodiments, the modems in the first modem pool 125 are allocated to perform operations on services associated with a first service, and the modems in the second modem pool 127 are allocated to perform operations on services associated with a second service. In certain aspects, the first modem in the first modem pool 125 and the second modem in the first modem pool 125 are allocated to perform operations on services associated with a first user group and a second user group, respectively, for providing the first service.
[0035] In certain embodiments, the modem is configured to generate data packets based on RF signals from devices associated with different user group and service pairs. The data packets include identifiers that associate each data packet with a specific user group and a specific service. For example, the data packets include an identifier for a virtual routing and forwarding (VRF) instance. The VRF instance corresponds to a user group (e.g., a Tier 2 carrier or other service provider) and a service and is used to perform routing at network device 142, as further described herein. In certain examples, the VRF instance is instantiated at network device 142. In certain embodiments, RF signals are assigned to the modem for processing based on configuration data 123 stored in memory 122. In certain embodiments, configuration data 123 indicates an association between a VRF identifier and a user group identifier and a service identifier pair. For illustration, configuration data 123 indicates that a specific pair (including a specific user group identifier and a specific service identifier) is associated with a VRF instance (which corresponds to a specific user group identified by the user group identifier and a specific service identified by the service identifier). The data packet including the VRF instance identifier is transmitted from base station 118 to network device 142.
[0036] The network device 142 includes a processor 144 and a memory 146, and the network device 142 is configured to route traffic between one or more devices and a network 156 (e.g., an external network (such as a network maintained by another Tier 1 provider), the Internet, etc.). In particular embodiments, the processor 144 is configured to execute instructions stored in the memory 146 to perform the operations described herein. In alternative embodiments, the network device 142 includes hardware, such as an ASIC, an FPGA, or a controller, that performs the operations described herein. The network device 142 may include or correspond to a signaling gateway, a packet gateway, a mobility management entity (MME), or a combination thereof. In particular embodiments, the network device 142 is a single device that performs the functions of a signaling gateway, a packet gateway, and an MME. Alternatively, more than one communicatively coupled device may perform the operations of the network device 142.
[0037] In particular embodiments, network device 142 is configured to receive data packets from a modem of base station 118 and generate packets to be sent to other devices of network 156 via core network 130 (e.g., subscriber data server 136 and IP multimedia subsystem server 134), as further described herein. Subscriber data server 136 (e.g., Customer Charging and Billing Subsystem (CCBS)) is configured to monitor network usage for billing and provisioning purposes. In particular embodiments, subscriber data server 136 is configured to track network usage and perform billing on a per-user group and per-service basis. As non-limiting examples, information about subscriber usage is maintained and stored for each user group and each service. The IP multimedia subsystem is configured to perform operations such as initiating and maintaining voice sessions, initiating and maintaining data sessions, initiating phone ringing, and other such activities that enable phone, data, and other services on one or more devices. In some embodiments, core network 130 also includes one or more security or network security systems configured to provide secure logical isolation of system 100 from external networks (such as network 156).
[0038] During operation, the system 100 enables multiple user groups (e.g., Tier 2 operators or service providers) to provide multiple services to subscribers via the system 100, such as a first service 160 (e.g., an IP core network service), a second service 164 (e.g., a circuit-based core network service), and an Nth service 168 (e.g., a proprietary core network service). Although three services are shown, in other embodiments, N can be any integer greater than two. To support multiple user groups (e.g., CUGs) and multiple services, a beam map and beamforming weights can be created and stored as beamforming data 110. In a particular embodiment, the beam map identifies a frequency reuse pattern of beams directed to multiple cells (e.g., earth cells) such that a particular frequency band (e.g., a channel, a subchannel, etc.) can be reused in different non-adjacent cells. In another particular embodiment, the beamforming data 110 indicates a carrier map that identifies the initial capacity and carrier configuration of each beam generated by the switching circuitry 104. In another specific embodiment, each user group and service pair is associated with a corresponding cell size, beam weight, mode, capacity, and carrier allocation, and the beamforming data 110 indicates multiple sets of beamforming weights associated with multiple user groups and service pairs (as well as other information such as cell size, mode, capacity, carrier allocation, etc.). In some embodiments, the beamforming data 110 (or portions thereof) is adjusted over time, such as based on changing subscriber density, changing traffic load patterns, user group policies, or service policies.
[0039] In particular embodiments, satellite 102 transmits multiple RF signals (e.g., beams) in one or more patterns across one or more regions. Each pattern of RF signals corresponds to a user group (e.g., a first MVNO) and a service pair, and enables wireless communication between devices associated with the user group and service pair and system 100. For illustration, switching circuitry 104 receives data (e.g., from network device 142 after performing one or more association operations) indicating that a unique user group and service (e.g., first service 160) pair is associated with a particular portion of spectrum, and generates at least one beam associated with the particular portion. In particular embodiments, beamforming network 108 adjusts the multiple RF signals based on beamforming data 110 and transmits each RF signal over the portion of spectrum associated with the corresponding pair (e.g., comprising the user group and service). For example, first beamforming network 112 adjusts the first RF signal based on a first set of beamforming weights corresponding to the first user group and first service 160, and second beamforming network 114 adjusts the second RF signal based on a second set of beamforming weights corresponding to the second user group and second service 164. The first RF signal is transmitted via a first portion of the spectrum corresponding to the first user group and the first service 160. The second RF signal is transmitted via a second portion of the spectrum corresponding to the second user group and the second service 164. In particular embodiments, satellite 102 stores data indicating an association between each unique pair (e.g., each user group and service pair) and the corresponding portion of the spectrum, such as channel map data 186 stored in memory 182.
[0040] Satellite 102 can transmit (e.g., deploy) multiple RF signals in one or more patterns to one or more regions. In a particular embodiment, satellite 102 deploys one or more RF signals in a first pattern 162, a second pattern 166, and an Nth pattern 170. Each of patterns 162, 166, and 170 is associated with a different user group and service pair. In a particular embodiment, first pattern 162 is associated with first service 160 and a first user group, second pattern 166 is associated with second service 164 and a second user group, and Nth pattern 170 is associated with Nth service 168 and an Nth user group. One or more of patterns 162, 166, and 170 can be superimposed in the same region. For illustration, patterns 162, 166, and 170 are superimposed in a particular region to provide wireless communication services to subscribers in the particular region via different RF channels (or other frequency bands) associated with different user groups (e.g., CUGs) and service pairs. Alternatively, one or more of patterns 162, 166, and 170 can be deployed in different regions. To illustrate, a subscriber in a first region accesses the system 100 via a first RF channel, and a second subscriber in a second region accesses the system 100 via a second RF channel.
[0041] A specific example is provided to illustrate the operation of system 100. In this example, a first pattern 162, a second pattern 166, and an Nth pattern 170 are superimposed on top of each other in a first area. A first device 172 (e.g., a first subscriber device) entering the first area synchronizes with an available operator frequency and receives data, such as master information block data and system information block data, indicating available user groups (e.g., CUGs) provided services via system 100. If the first device 172 is associated with a first service 160 and a first user group (e.g., if a subscriber associated with the first device 172 subscribes to the first service 160 provided by the first user group), the first device 172 performs one or more association operations and performs supported wireless communications via a portion of the spectrum associated with the first service 160 and the first user group. In the same location, a second device 174 (e.g., a second subscriber device) associated with a second service 164 and a second user group performs one or more association operations and performs supported wireless communications via a portion of the spectrum associated with the second service 164 and the second user group.
[0042] In this way, a portion of the spectrum associated with the first service 160 and the first user group can be accessed by a device (e.g., a subscriber device) located at the first location and associated with the first service 160 provided by the first user group (e.g., subscribed to the first service 160). This portion of the spectrum is not accessible by a device (e.g., a subscriber device) located at the first location that is not associated with the first service 160 and the first user group. However, a device can be associated with other user groups, other services, or both, and can access different portions of the spectrum at the same location. Thus, different devices associated with different user groups and service pairs can access the system 100 using different frequencies at the same location.
[0043] In another specific embodiment, a specific pattern of RF signals includes: a first set of RF signals corresponding to (one or more) RF channels associated with a first service 160 and a first user group; a second set of RF signals corresponding to (one or more) RF channels associated with a second service 164 and a second user group; and a third set of RF signals corresponding to (one or more) RF channels associated with an Nth service 168 and an Nth user group. The specific pattern is deployed at multiple different locations. As a specific example, the specific pattern is deployed in Chicago, Washington, D.C., and New York. As part of the frequency reuse design, subscribers can access the communication services associated with each user group and service pair using the same corresponding RF channel at each location. For illustration, subscribers located in each of the three cities can access the first service 160 provided by the first user group via the first RF channel, the second service 164 provided by the second user group via the second RF channel, and the Nth service 168 provided by the Nth user group via the third RF channel. Alternatively, different patterns can be deployed in different locations. As a specific example, a first mode is deployed in Chicago, which includes an RF channel associated with a first service 160 and a first user group and a second RF channel associated with a second service 164 and the second user group, and a second mode is deployed in New York, which includes a third RF channel associated with the first service 160 and the first user group and a fourth RF channel associated with an Nth service 168 and an Nth user group. Subscribers associated with the first user group access the first service 160 via the first RF channel in Chicago and via the third RF channel in New York, subscribers associated with the second user group access the second service 164 via the second RF channel in Chicago (and do not access the second service 164 in New York), and subscribers associated with the Nth user group access the Nth service 168 via the fourth RF channel in New York (and do not access the Nth service 168 in Chicago).
[0044] Performing one or more association operations may include performing a radio link attach operation, a network registration operation, an IP Multimedia Subsystem (IMS) operation, other association operations, or a combination thereof. In a particular embodiment, the one or more association operations are performed by the base station 118, the network device 142, other devices, or a combination thereof. In this embodiment, the base station 118 and the network device 142 store data at the memory 122, 146, respectively, which associates the device with a user group (e.g., CUG) and a service pair, and is updated during the performance of the one or more association operations. Figure 2 Additional details are described regarding one or more associated operations.
[0045] Once the devices are associated with the selected user group and service pair, the devices can transmit RF signals to (or receive RF signals from) the system 100 via the corresponding portion of the spectrum. In particular embodiments, the first device 172 transmits a first RF signal via a first portion of the spectrum (e.g., a first RF channel) corresponding to the first service 160 and the first user group, and the second device 174 transmits a second RF signal via a second portion of the spectrum (e.g., a second RF channel) corresponding to the second service 164 and the second user group. The RF signals are received by the satellite 102 and provided to the RFE 106 for processing. In particular embodiments, the RFE 106 is configured to perform one or more processing operations (e.g., amplification, noise reduction, etc.) on the first and second RF signals.
[0046] Base station 118 receives the first RF signal and the second RF signal and designates a specific modem for processing the RF signal (and resulting data packet) or the input data packet, as further described herein. In a particular embodiment, first modem 124 is configured to generate a first data packet based on the first RF signal, and second modem 126 is configured to generate a second data packet based on the second RF signal. A specific modem from a specific pool of modems is designated for processing the RF signal (or data packet) based on a user group and service pair associated with the RF signal (or data packet) and configuration data 123. As a specific example, configuration data 123 designates first device 172 (e.g., based on an indicator of a device ID associated with first device 172) as being associated with a first pair corresponding to a first VRF instance identifier (e.g., including first device 160 and a first user group), and designates second device 174 as being associated with a second pair corresponding to a second VRF instance identifier (e.g., including second device 164 and a second user group). Based on the configuration data 123 and the indicator of the device ID, the base station 118 (e.g., the processor 120) is configured to designate the first modem 124 to process the first RF signal (e.g., the RF signal or data packet associated with the first device 160 and the first user group), and designate the second modem 126 to process the second RF signal (e.g., the RF signal or data packet associated with the second device 164 and the second user group). In particular embodiments, the indicator includes a telephone number associated with the device, a subscription identifier (e.g., a Mobile Subscriber Integrated Services Digital Network Number (MSISDN)), or any other type of indicator of the identity of the device.
[0047] In particular embodiments, each of the plurality of modems in base station 118 is configured to process traffic (e.g., RF signals, data packets, etc.) associated with a corresponding VRF instance identifier. For purposes of illustration, first modem 124 and the other modems in first modem pool 125 are configured to process RF signals and data packets associated with a first VRF instance identifier, which corresponds to a first VRF instance associated with first service 160 and a first user group. In particular embodiments, first modem 124 is further configured to avoid processing RF signals and data packets associated with other VRF instance identifiers, such as a second VRF instance identifier corresponding to a VRF instance associated with second service 164 and a second user group. Similarly, second modem 126 and the other modems in second modem pool 127 are configured to process data packets associated with the second VRF instance identifier and avoid processing RF signals and data packets associated with the first VRF instance identifier.
[0048] Processing the RF signals at modems 124-128 includes generating data packets including data and corresponding VRF instance identifiers. For illustration, based on determining that first device 172 is associated with first service 160 and a first user group, base station 118 designates first modem 124 to generate a first data packet based on the first RF signal. Based on determining that second device 174 is associated with second service 164 and a second user group, base station 118 designates second modem 126 to generate a second data packet based on the second RF signal. The first data packet includes first data and a first VRF instance identifier, and the second data packet includes second data and a second VRF instance identifier.
[0049] In a particular embodiment, modems 124-128 are configured to encrypt data packets on a per-VRF (or per-user group and per-service) basis. For illustration, first modem 124 is further configured to encrypt a first data packet based on a first encryption key associated with a first VRF instance, and second modem 126 is configured to encrypt a second data packet based on a second encryption key associated with a second VRF instance. In a particular embodiment, the first encryption key and the second encryption key are the same type of encryption key, but different keys or other values are used to perform the corresponding encryption key. In an alternative embodiment, different types of encryption key are used to perform the first encryption key and the second encryption key. Encrypting data associated with one user group and service pair in a manner different from that used to encrypt data associated with another user group and service pair can improve the security and separation of data corresponding to different user groups and service pairs. For illustration, encrypted data mistakenly provided to a device associated with a different user group and a different service is not decrypted using the same encryption key as other data received by the device.
[0050] The first data packet and the second data packet are sent to the network device 142. In a particular embodiment, the data packets (including the first data packet and the second data packet) are sent via an Institute of Electrical and Electronics Engineers (IEEE) 802.11Q compliant connector or trunk. In a particular embodiment, the connector comprises a 10 gigabyte (gB) fiber optic tube. In a particular embodiment, the base station 118 manages modulation and coding (MOCOD), time slot allocation, and queuing of data packets (e.g., an Evolved Packet System (EPS) bearer) via the modems 124-128 based on one or more network quality criteria. Reference Figure 2 Additional details regarding data grouping are described.
[0051] Network device 142 receives data packets and generates packets for transmission to one or more other devices via core network 130 and network 156. For example, network device 142 is configured to receive a first data packet and transmit the first packet to a first device via network 156. Network device 142 is further configured to receive a second data packet and transmit the second packet to a second device via network 156. In a particular embodiment, the first device and the second device are the same device. In an alternative embodiment, the first device and the second device are different devices. The first packet includes first data and a first header including a first indicator associated with a first VRF instance, and the second packet includes second data and a second header including a second indicator associated with a second VRF instance.
[0052] In particular embodiments, multiple VRF instances are maintained at network device 142. Maintaining multiple VRF instances includes maintaining multiple routing information bases (RIBs) (e.g., routing and forwarding data) to be used for routing packets at network device 142. As a specific example, network device 142 stores first VRF instance RIB data 150, second VRF instance RIB data 152, and Nth VRF instance RIB data 154 at memory 146. Although Figure 1 Three instances of RIB data are shown in FIG, but in other embodiments, N is any other integer greater than two. The VRF instance RIB data 150-154 includes or indicates routing information, forwarding information, or a combination thereof.
[0053] In particular embodiments, each of the VRF instance RIB data 150-154 is associated with a user group and a service pair. For example, the first VRF instance RIB data 150 is associated with the first service 160 and the first user group, the second VRF instance RIB data 152 is associated with the second service 164 and the second user group, and the Nth VRF instance RIB data 154 is associated with the Nth service 168 and the Nth user group. The VRF instance RIB data 150-154 enable different routing paths to be established for traffic associated with different user groups and service pairs. For example, the routing path from first device 172 to the first device of network 156 may traverse different devices or different portions of devices (e.g., different modems of base station 118) through system 100, core network 130, and network 156 than the routing path from second device 174 to the second device of network 156. Alternatively, the routing path from first device 172 to the first device of the network may be the same as the routing path from second device 174 to the second device of the network.
[0054] By maintaining different RIBS for different VRF instances and by assigning different resources (e.g., MODEMs) of base station 118 to different VRF instances, logical isolation of traffic on a per-user group and per-service basis is provided. To illustrate, traffic from and to first device 172 (e.g., a subscriber device associated with first service 160 and a first user group) traverses system 100 in different time slots or with different modulation and coding schemes than traffic from and to second device 174 (e.g., a subscriber device associated with second service 164 and a second user group). Furthermore, due to the differences between first VRF instance RIB data 150 and second VRF instance RIB data, traffic from and to first device 172 is routed differently through core network 130 and network 156 than traffic from and to second device 174. By logically isolating traffic on a per-user and per-service basis, the security of a user's traffic can be improved compared to a system that does not maintain different VRF instances for different user groups and service pairs.
[0055] In particular embodiments, network device 142 stores combined RIB data 148 in memory 146 for use in routing packets through core network 130 and network 156. Combined RIB data 148 is based on VRF instance RIB data 150-154 and any additional routing information generated by network device 142 (e.g., routes associated with packets that do not correspond to one of the VRF instances). When a data packet is received at network device 142, the corresponding VRF instance RIB data is updated. For illustration, network device 142 updates first VRF instance RIB data 150 based on a first data packet, and network device 142 updates second VRF instance RIB data 152 based on a second data packet.
[0056] In particular embodiments, network device 142 generates packets (including headers that include indicators of corresponding VRF instances) based on received data packets and combined RIB data 148. As an example, network device 142 generates a first packet that includes first data and a first header that includes a first indicator associated with a first VRF instance, and network device 142 generates a second packet that includes second data and a second header that includes a second indicator associated with a second VRF instance. As non-limiting examples, the first indicator and the second indicator include or correspond to identifiers, such as a source IP address or a source port address. In particular embodiments, the indicator corresponds to a tag or to a "5-tuple" (e.g., a tuple that includes a source address, a source port, a destination address, a destination port, and a protocol associated with the packet). During processing by devices of core network 130 and network 156, encapsulating the first data associated with the first VRF instance with a different header than the second data associated with the second VRF instance logically isolates the first data from the second data.
[0057] After being transmitted by network device 142, the packet traverses core network 130 and network 156 on its way to the final destination device(s). In some embodiments, at least some components of core network 130 process packets on a per-VRF basis. In particular embodiments, subscriber data server 136 generates (or updates) first subscriber data 138 based on the first packet and generates (or updates) second subscriber data 140 based on the second packet. First subscriber data 138 indicates provisioning information, billing information, usage information, or a combination thereof associated with subscribers of a first service 160 provided by a first user group, and second subscriber data 140 indicates provisioning information, billing information, usage information, or a combination thereof associated with subscribers of a second service 164 provided by a second user group. In particular embodiments, other components of core network 130 process traffic on a per-VRF basis. As an example, the IP multimedia subsystem server 134 performs one or more operations on the first packet based on a policy or rule corresponding to the first service 160 and the first user group, and the IP multimedia subsystem server 134 performs one or more operations on the second packet based on a policy or rule corresponding to the second service 164 and the second user group. In another specific embodiment, one or more security devices or systems or network security devices or systems (also referred to as a "demilitarized zone" (DMZ)) process traffic based on rules or policies associated with corresponding VRF instances. Rules and policies based on VRF instances enable traffic associated with a particular user group and service pair to be processed differently by devices of the core network 130 than traffic associated with other user groups and service pairs.
[0058] Packets sent from devices of network 156 to subscriber devices are processed in a similar manner. Packets traverse core network 130 and the rest of system 100 on a per-VRF instance or per-user group and per-service basis until they reach the destination subscriber device. As an example, network device 142 is configured to receive a third packet from a first device via network 156 and a fourth packet from a second device via network 156. The third packet includes third data and a third header that includes an indicator associated with the first VRF instance, and the fourth packet includes fourth data and a fourth indicator associated with the second VRF instance. In particular embodiments, the third and fourth packets are routed to subscriber data server 136 before reaching network device 142, and subscriber data server 136 updates corresponding subscriber data based on the third and fourth packets, as described above.
[0059] In particular embodiments, if any new routing information is associated with the third packet or the fourth packet, network device 142 updates combined RIB data 148 based on the third packet and the fourth packet. For illustration, network device 142 updates first VRF instance RIB data 150 based on the third indicator being associated with the first VRF instance, and network device 142 updates second VRF instance RIB data 152 based on the fourth indicator being associated with the second VRF instance. Network device 142 may also generate data packets based on the received packets and transmit the data packets to a specific modem of base station 118. As an example, network device 142 generates a third data packet including third data and the first VRF instance identifier, and network device 142 generates a fourth data packet including fourth data and the second VRF instance identifier.
[0060] After generating the third and fourth packets, network device 142 transmits the third data packet to first modem 124 (e.g., associated with the first VRF instance based on the third indicator), and network device 142 transmits the fourth data packet to second modem 126 (e.g., associated with the second VRF instance based on the fourth indicator). Base station 118 converts the third and fourth data packets into third and fourth RF signals, respectively, for transmission to the corresponding subscriber devices. In certain embodiments, the RF signals are processed by components 102-108, 112-116 before transmission to the devices. For illustration, RFE 106 is configured to process the third and fourth RF signals, such as by performing filtering, amplification, and the like.
[0061] Base station 118 indicates to RFE 106 and satellite 102 that different RF signals are associated with different VRF instances, and therefore, with different user groups and service pairs. In certain embodiments, base station 118 associates the RF signals corresponding to different VRF instances with different logical interfaces. For example, base station 118 associates a first RF signal corresponding to a first VRF instance (and a first user group and a first service) with a first logical interface between base station 118 and RFE 106 (or between base station 118 and satellite 102), and base station 118 associates a second RF signal corresponding to a second VRF instance (and a second user group and a second service). In alternative embodiments, base station 118 sends the RF signals corresponding to different VRF instances to different ports (e.g., physical ports, logical ports, virtual ports, etc.) of RFE 106. As a specific example, first modem 124 sends a first RF signal associated with a first VRF instance (and a first user group and a first service) to a first port, and second modem 126 sends a second RF signal associated with a second VRF instance (and a second user group and a second service) to a second port.
[0062] In particular embodiments, RF signals associated with different logical interfaces (or sent to different ports) are transmitted to satellite 102 via different portions of the RF spectrum (e.g., different RF channels). As a specific example, RF signals associated with a first logical interface (and therefore associated with a first VRF, a first service 160, and a first user group) are transmitted via a first RF channel, and RF signals associated with a second logical interface (and therefore associated with a second VRF, a second service 164, and a second user group) are transmitted via a different RF channel. In this manner, satellite 102 receives an indication of an association between RF signals and VRF instances (corresponding to a particular service provided by a particular Tier 2 operator or service provider).
[0063] In particular embodiments, satellite 102 is configured to receive RF signals from RFE 106 and perform beam-to-beam switching to generate RF signals to be transmitted to one or more devices based on channel mapping data 186. As a specific example, processor 180 (or switching circuitry 104) is configured to initiate transmission of a second RF signal from one or more antennas of payload 184 to first device 172 based on channel mapping data 186 and based on a first user group and first service 160 associated with first device 172. The second RF signal is based on a first RF signal received from RFE 106 at one or more antennas of payload 184 (and associated with a first VRF instance). The first RF signal and the second RF signal may correspond to different RF channels. For example, the first RF signal may correspond to a first RF channel and the second RF signal may correspond to a second RF channel different from the first RF channel.
[0064] In particular embodiments, the channel mapping data 186 indicates a mapping of RF channels (or other portions of the spectrum) used for communicating with one or more devices or RFEs 106 to user groups (e.g., CUGs) and service pairs. As a specific example, the channel mapping data 186 indicates that the first service 160 and the first user group are mapped to at least a first RF channel for communication between the satellite 102 and the RFE 106, and to at least a second RF channel for communication between the satellite 102 and the first device 172 subscribed to the first service 160 provided by the first user group. The channel mapping data 186 can be generated (or updated) by the operator of the satellite control system when a service provider (e.g., an MVNO) purchases capacity and accesses the system 100. For example, when a first user group purchases capacity and accesses system 100 to provide a first service 160, the satellite control system transmits data to satellite 102 indicating that the first user group and the first service 160 are associated with a first RF channel for communication between satellite 102 and RFE 106, and associated with a second RF channel for communication between subscriber devices (associated with the first user group and the first service 160) and satellite 102. In some embodiments, channel mapping data 186 indicates a set of RF channels associated with each user group and service pair, and at least some of the channels in each set of RF channels are associated with different locations. As additional user groups (e.g., CUGs) purchase capacity and access system 100 to provide services, data indicating the mapping of the additional user groups and service pairs to RF channels can be sent to satellite 102 to update channel mapping data 186.
[0065] In particular embodiments, processor 180 is configured to initiate transmission of a fourth RF signal from one or more antennas of payload 184 to second device 174 based on channel mapping data 186 and based on second service 164 and a second user group associated with second device 174. In this example, the fourth RF signal is based on a third RF signal received from RFE 106 at one or more antennas of payload 184. The third RF signal and the fourth RF signal correspond to different RF channels, and the third RF channel and the fourth RF channel each correspond to a different RF channel compared to the first RF channel and the second RF channel. As a specific example, the third RF signal corresponds to a third RF channel that is different from the first RF channel, and the fourth RF signal corresponds to a fourth RF channel that is different from the third RF channel and the second RF channel. In this manner, different user groups and service pairs are associated with different RF channel mappings, and traffic associated with the different user groups and service pairs is transmitted via the transmission of RF signals over different RF channels. As a specific example, the RF signal transmitted to the first device 172 corresponds to a second RF channel (e.g., an RF channel associated with the first service 160 and the first user group), and the RF signal transmitted to the second device 174 corresponds to a fourth RF channel (e.g., an RF channel associated with the second service 164 and the second user group). In another specific embodiment, one or more antennas of the payload 184 are configured to superimpose transmissions of the second RF signal and the fourth RF signal at the same location.
[0066] Additional RF signals associated with the same user group and service pair may be transmitted or received via the same RF channel. As a specific example, processor 180 is configured to initiate transmission of a sixth RF signal from one or more antennas of payload 184 to first device 172 based on the channel mapping data and based on first service 160 and first user group. In this example, the sixth RF signal is based on a fifth RF signal received from RFE 106 at one or more antennas of payload 184. Because the fifth and sixth RF signals are associated with first service 160 and first user group, the fifth RF signal corresponds to the first RF channel and the sixth RF signal corresponds to the second RF channel.
[0067] In particular embodiments, satellite 102 (e.g., processor 180, switching circuitry 104, or both) transmits an RF signal to RFE 106 based on RF signals received from one or more subscriber devices and channel mapping data 186. As a specific example, one or more antennas of payload 184 receive an RF signal from first device 172 via a second RF channel, and processor 180 initiates transmission of the RF signal to RFE 106 via a first RF channel. RFE 106 receives the RF signal via the first RF channel and processes the RF signal before providing it to base station 118. In particular embodiments, based on receiving the RF signal via the first RF channel (e.g., an RF channel associated with first service 160 and a first user group), base station 118 assigns the RF signal to a modem (e.g., first modem 124) from first modem pool 125 for processing. Traffic received at satellite 102 from subscriber devices associated with other user groups and service pairs is similarly processed and provided to base station 118 via RFE 106. In this way, traffic sent to (or received from) subscriber devices associated with different user groups and service pairs is isolated by communicating via different RF channels (or other portions of the frequency spectrum). Carrying out communications associated with different user groups and service pairs via different RF channels (or other portions of the frequency spectrum) can improve security and prevent data associated with a particular user group and service pair from being processed together with data associated with different user groups and service pairs.
[0068] In particular embodiments, the beamforming network 108 adjusts the RF signal based on beamforming information associated with different user groups and service pairs. As an example, the beamforming network 108 is configured to adjust the second RF signal (e.g., the RF signal transmitted to the first device 172) based on the beamforming data 110 stored in the memory 182 and based on the first RF signal (e.g., based on the RF channel via which the first RF signal is received). In particular embodiments, the beamforming data 110 indicates several sets of beamforming weights that correspond to pairs of user groups that purchased capacity and accessed the system 110 to provide services. As a specific example, the beamforming data 110 indicates a first set of beamforming weights associated with the first service 160 and the first user group and a second set of beamforming weights associated with the second service 164 and the second user group.
[0069] In particular embodiments, first BFN 112 adjusts the RF signal corresponding to first service 160 and the first user group based on a first set of beamforming weights, and second BFN 114 adjusts the RF signal corresponding to second service 164 and the second user group based on a second set of beamforming weights. Adjusting the RF signal includes modifying the amplitude, phase, another characteristic, or a combination thereof of the RF signal. Adjusting the RF signal based on the beamforming weights is also referred to as applying the beamforming weights to the RF signal.
[0070] In particular embodiments, the first BFN 112 is configured to adjust an RF signal (e.g., based on the RF signal being associated with the first service 160 and the first user group) by applying one or more first beamforming weights of the beamforming data 110, and the BFN 114 is configured to adjust another RF signal (e.g., based on the other RF signal being associated with the second service 164 and the second user group) by applying one or more second beamforming weights of the beamforming data 110. Applying the beamforming weights adjusts the phase, amplitude, another characteristic, or a combination thereof of the RF signal based on the user-specific beamforming weights, which can increase the directionality and spatial selectivity of the RF signal to the device. The beamforming data 110 (or a portion thereof, such as a portion corresponding to a specific user group and a specific service) can be updated based on changes in traffic loading patterns, user group policies, or service policies.
[0071] In certain embodiments, the switching circuitry 104 generates multiple beams based on the first RF signal and the third RF signal. For illustration, the RF signal is received at the analog front end of the switching circuitry 104, converted to the digital domain, switched through a multi-stage interconnection network, and converted back to the analog domain by the analog back end of the switching circuitry 104. The RF signals are deployed via satellite 102 over different portions of the spectrum (e.g., based on the channel mapping data 186). For example, the first RF signal is converted to a specific portion of the spectrum associated with the first service 160 and the first user group, and the second RF signal may be converted to a different specific portion of the spectrum associated with the second service 164 and the second user group. The satellite 102 transmits the second RF signal (e.g., deploying one or more beams associated with the second RF signal in a first pattern 162) to the first device 172 and transmits the fourth RF signal (e.g., deploying one or more beams associated with the fourth RF signal in a second pattern 166) to the second device 174 over the corresponding portions of the spectrum, respectively.
[0072] By maintaining different VRF instances for different user groups and service pairs and by routing traffic associated with different user groups and service pairs over different RF channels (or other portions of the spectrum), system 100 can provide "end-to-end" logical isolation of traffic on a per-user-group and per-service basis. For example, traffic associated with a first service 160 and the first user group is encapsulated and identified based on a first VRF instance compared to traffic associated with a second service 164 and the second user group. Traffic associated with the first service 160 and the first user group is routed through components of system 100 (such as core network 130 and network 156) via one or more paths that may be different from the one or more paths through which traffic associated with the second service 164 and the second user group is routed. To further illustrate, traffic associated with the first service 160 and the first user group is sent to (or received from) the first device 172 over a different RF channel than traffic associated with the second service 164 and the second user group. Providing logical isolation of traffic on a per-user and per-service basis improves the security of each user group and service compared to processing traffic for all user groups and services together. Isolating traffic on a per-user and per-service basis increases the security of system 100. Compared to systems that do not isolate traffic by user group and service, the flexibility of system 100 may also be increased. For example, system 100 may be configured to process traffic associated with a particular user group and service pair according to different rules or policies than other user group and service pairs.
[0073] In the above description, Figure 1 The various functions performed by system 100 are described as being performed by components 102-108, 112-118, 134, 136, and 142. This is for illustration only. In other embodiments, one or more of components 102-108, 112-118, 134, 136, and 142 may be integrated into a single component that performs functions associated with multiple components. In addition, various functions are described as being performed by processor 120 based on the execution of instructions stored in memory 122, or by processor 144 based on the execution of instructions stored in memory 146. This is for illustration only. In alternative embodiments, one or more functions performed by processor 120 or processor 144 are instead performed by one or more hardware components. For example, a first component may generate a packet based on combined RIB data 148 and first VRF instance RIB data 150. Each component may be implemented using hardware (e.g., a field programmable gate array (FPGA) device, an application specific integrated circuit (ASIC), a digital signal processor (DSP), a controller, etc.), software (e.g., instructions executable by a processor), or a combination thereof.
[0074] Figure 2An example of a system 200 is shown that is configured to process network traffic associated with different VRF instances corresponding to different user groups and service pairs. The system 200 includes Figure 1 106, base station 118, network equipment 142, subscriber data server 136, and IP multimedia subsystem server 134. In addition, system 200 includes a cellular system 202, a switching circuit 204, and a beamforming network 206. Although components 202, 204, 206, 106, 118, 134, 136, and 142 are shown as included in system 200, in other embodiments, one or more of components 202, 204, 206, 106, 118, 134, 136, and 142 are not included (and the corresponding functions are performed by one or more of the remaining components).
[0075] Components 106, 118, 134, 136, and 142 are configured to execute reference Figure 1 The switching circuit 204 and the beamforming network 206 are configured to perform the operations described in reference Figure 1 As an example, the switching circuit 204 generates RF signals based on the channel mapping data 210 for transmission to one or more devices via different RF channels (or other parts of the spectrum), as shown in FIG. Figure 1 As another example, the beamforming network 206 adjusts the one or more RF signals based on the beamforming weights indicated by the beamforming data 208 and associated with a specific user group and service pair to adjust the amplitude, phase, etc. of the one or more RF signals, as described in reference to FIG. Figure 1 However, in Figure 2 In the illustrated embodiment, the switching circuitry 204 and the beamforming network 206 are communicatively coupled between the RFE 106 and the base station 118 (rather than being integrated within the satellite).
[0076] In particular embodiments, the RF signals generated by switching circuitry 204 (and processed by RFE 106) are transmitted (e.g., deployed) to one or more subscriber devices via cellular system 202. Cellular system 202 includes one or more components, such as antennas, satellites, towers, etc., configured to provide RF signals from one location to another. In particular embodiments, cellular system 202 includes or corresponds to a terrestrial cellular system. In another particular embodiment, cellular system 202 includes or corresponds to a hybrid system (e.g., a system including terrestrial components (such as one or more towers) and one or more satellites).
[0077] During operation, the system 200 provides end-to-end network traffic isolation for different user groups and service pairs, as shown in FIG. Figure 1 However, with the system 100 described above Figure 1 In contrast to system 100, channel mapping and beamforming operations are performed by ground-based components. For illustration, channel mapping and beamforming operations are performed by switching circuitry 204 and beamforming network 206, respectively, which are ground-based components and are communicatively coupled between RFE 106 and base station 118. Reducing the number of components integrated within the satellite can reduce costs and increase ease of maintenance of system 200.
[0078] Figure 3 An example of a system 300 is shown that is configured to process network traffic associated with different VRF instances corresponding to different user groups and service pairs. The system 300 includes Figure 1 104, RFE 106, beamforming network 108, network device 142, subscriber data server 136, and IP multimedia subsystem server 134. In addition, system 300 includes satellite 302 and operation center 303. Although components 104, 106, 108, 134, 136, 142, 302, and 330 are shown as included in system 300, in other embodiments, one or more of components 104, 106, 108, 134, 136, 142, 302, and 330 are not included (and the corresponding functions are performed by one or more of the remaining components).
[0079] Components 104, 106, 108, 134, 136, 142 are configured to execute reference Figure 1 As an example, the switching circuit 104 generates RF signals based on the channel mapping data 186 for transmission to one or more devices via different RF channels (or other parts of the spectrum), as shown in FIG. Figure 1 As another example, the beamforming network 108 adjusts the one or more RF signals based on the beamforming weights indicated by the beamforming data 110 and associated with a specific user group and service pair to adjust the amplitude, phase, etc. of the one or more RF signals, as described in reference to FIG. Figure 1 The RFE 106 is configured to process RF signals received from one or more devices at the satellite 302 or to be sent (e.g., transmitted) from the satellite 302 to one or more devices. The network device 142 is configured to receive data packets from the MODEM and generate packets to be sent to other devices on the network 156. However, in Figure 3In the illustrated embodiment, the RFE 106 and the network device 142 are integrated within the satellite 302. For example, the payload 384 of the satellite 302 includes the network device 142, the first MODEM pool 125, the second MODEM pool 127, and the Nth MODEM pool 129. For illustration, each of the first MODEM pool 125, the second MODEM pool 127, and the Nth MODEM pool 129 is instantiated at the payload 384. In some aspects, Figure 1 The illustrated implementation is referred to as a "transparent architecture," and Figure 3 The illustrated embodiment is referred to as a "regenerative architecture." For example, satellite 102 is configured to process analog RF signals, while satellite 302 is configured to regenerate RF energy into digital MODEM frames that encapsulate network packets. IP multimedia subsystem server 134 and subscriber data server 136 are integrated within operations center 330 (e.g., external to satellite 302). In certain embodiments, one or more operations described with reference to components of satellite 302 are performed by processor 380 of satellite 302.
[0080] During operation, the system 300 provides end-to-end network traffic isolation for different user groups and service pairs, as shown in FIG. Figure 1 However, with the system 100 described above Figure 1 In contrast to the system 100 of FIG. 1 , MODEM operations and packet conversion operations (e.g., between data packets corresponding to RF signals and network packets transmitted via the network 156) are performed by satellite components. For purposes of illustration, the MODEM operations and packet conversion operations are performed by one or more of the first MODEM pool 125, the second MODEM pool 127, and the Nth MODEM pool 129 of the payload 384 of the satellite 302 and the network device 142, respectively.
[0081] Figure 4 Depicted is a ladder diagram 400 showing the Figure 1 A first example of network traffic transmitted by system 100. In a particular embodiment, Figure 4 The operations shown are performed by the first device 172, the second device 174, the system front end 402, the first MODEM 124, the second MODEM 126, the network device 142, and one or more devices 404. Figure 1 ), the system front end 402 refers to the satellite 102, the switching circuit 104, the RFE 106, the beamforming network 108, or a combination thereof. In a specific embodiment (e.g., as Figure 2 ), the system front end 402 refers to the cellular system 202, the RFE 106, the switching circuit 204, the beamforming network 206, or a combination thereof. In a specific embodiment (e.g., as Figure 3As shown), the system front end 402 refers to the switching circuit 104, the RFE 106, the beamforming network 108 or a combination thereof.
[0082] like Figure 4 As depicted, the first device 172 performs a first association operation(s) 410 with the base station 118 (or satellite 302) and the network device 142 to associate with the base station 118 (or satellite 302). Figure 1 System 100, Figure 2 System 200 or Figure 3 The first association operation(s) 410 may include a radio link attach operation, a network registration operation, an IMS registration operation, or a combination thereof.
[0083] In certain embodiments, the first device 172 is associated with the first service 160 (e.g., the first device 172 subscribes to the first service 160 for a first user group), and the first device 172 performs one or more radio link attachment operations in accordance with one or more wireless communication standards, such as a Third Generation Partnership Project (3GPP) standard. For purposes of illustration, the first device 172 synchronizes to an available operator frequency and receives Master Information Block (MIB) data and System Information Block (SIB) data. The MIB data and SIB data indicate available operators associated with the system 100 (or system 200) and information for connecting to the system 100 (or system 200). The first device 172 initiates a Random Access Channel (RACH) procedure to attach to the network. As part of the RACH procedure, the first device 172 and the base station 118 (or satellite 302) perform a handshake procedure that results in establishing a MAC layer connection between the first device 172 and the first modem 124.
[0084] In certain embodiments, after one or more radio link attach operations, the first device 172 performs one or more network registration operations. In some embodiments, the one or more network registration operations are in accordance with one or more wireless standards, such as 3GPP standards. For illustration, the first device 172 initiates a handshake process with the MME (e.g., network device 142) to verify and authenticate the identities of the first device 172 and the network, respectively. During the handshake process, the MME coordinates with the Equipment Identity Registration (EIR) to verify that the first device 172 is authorized to access the network. The MME and the EIR store and maintain per-user group and per-service data used to perform the handshake process. The MME manages a second handshake process with the SGW, PGW, and base station 118 (or satellite 302), which results in the assignment of a session (e.g., a session with a core network 130 (e.g., an Evolved Packet Core (EPC) network)) to the first device 172 and the establishment of an initial Evolved Packet System (EPS) bearer from the first device 172. The network devices 142 (e.g., MME, SGW, PGW) and base station 118 (or satellite 302) are configured to store data associated with each user group and each service and support multi-VRF RIB data and queue structures. Depending on the request for the first service 160 by the first device 172, the network devices 142 (e.g., MME, SGW, and PGW) may create additional EPS bearers. Once one or more radio link attach operations and one or more network registration operations are completed, the first device 172 is able to transmit and receive data via system 100 (or system 200).
[0085] In certain embodiments, after completing one or more network registration operations, the first device 172 performs one or more IMS registration operations. For illustration, the first device 172 registers the device 172 by transmitting a Session Initiation Protocol (SIP) REGISTER message to the Figure 1 、 Figure 2 or Figure 3The first device 172 initiates an IMS registration process with the IP Multimedia Subsystem server 134. The Proxy Call Setup Control Function (P-CSCF) of the IP Multimedia Subsystem server 134 receives the SIP REGISTER message and triggers a handshake process between the P-CSCF, the Interrogating CSCF (I-CSCF) of the IP Multimedia Subsystem server 134, and the Serving CSCF (S-CSCF) of the IP Multimedia Subsystem server 134, which verifies the authorization of the first device 172 to access IMS-based services. The S-CSCF also performs a handshake process with the Telephony Application Server (TAS), allowing the TAS to query the Home Subscriber Server database for Voice over Long Term Evolution (VoLTE) data associated with the first device 172. The first device 172, the P-CSCF, and the TAS then engage in a handshake process to subscribe to a registration event package in order to be informed of future changes to the registration status associated with the first device 172. The second device 174 performs second association operations 412 with the base station 118 (or satellite 302) and the network device 142 in a manner similar to the first association operations 410 (except that the second device 174 is associated with the second service 164 and the second user group). The above association operations are illustrative and not limiting. In other embodiments, one or more other association operations are performed, one or more of the above association operations are not performed, or both.
[0086] After performing the first association operation(s) 410, the first device 172 transmits a first RF signal 414 to the system head end. The system head end receives the first RF signal 414 and performs initial processing (e.g., amplification, filtering, noise reduction, etc.) before transmitting the first RF signal 414 to the base station 118 (or the payload 384 of the satellite 302). The first modem 124 receives the first RF signal 414 and generates a first data packet 416. The first data packet includes first data 420 (e.g., data indicated by the first RF signal 414) and a first identifier 422. In particular embodiments, the first identifier 422 includes or corresponds to a tag. Tags include a switch tag (also known as a virtual local area network (VLAN) tag or an 802.1Q tag), a VRF instance identifier, and an Open Shortest Path First (OSPF) process identifier (PID).
[0087] A first data packet 416 is sent from the first modem 124 to the network device 142. The network device 142 receives the first data packet 416 and generates a first packet 418 based on the first data packet 416. The first packet 418 includes first data 420 and a first indicator 424. In particular embodiments, the network device 142 is configured to replicate any changes made to the per-VRF instance RIB data in the combined RIB data 148 (e.g., also referred to as the trunk RIB or the global VRF instance RIB). For purposes of illustration, the combined RIB data 148 is updated based on updates to the first VRF instance RIB data 150. In addition, the first identifier 422 is stripped from the first data 420, and the first indicator 424 is included in the first packet 418. The first indicator 424 (e.g., a "per-VRF identifier") indicates the VRF instance associated with the first service 160 and the first user group. In particular embodiments, the first indicator 424 is included in the header of the first packet 418. In some embodiments, the first indicator 424 is indicated by a source address or source port number of a header of the first packet 418. Figure 1 or Figure 2 core network 130 and network 156 or via Figure 3 The network 156 sends the first packet 418 to one or more devices 404.
[0088] After performing the second association operation(s) 412, the second device 174 transmits a second RF signal 430 to the system head end. The system head end receives the second RF signal 430 and performs initial processing (e.g., amplification, filtering, noise reduction, etc.) before transmitting the second RF signal 430 to the base station 118 (or the payload 384 of the satellite 302). The second modem 126 receives the second RF signal 430 and generates a second data packet 432. The second data packet includes second data 440 (e.g., data indicated by the second RF signal 430) and a second identifier 442. In particular embodiments, the second identifier 442 includes or corresponds to a tag. Tags include a switch tag, a VRF instance identifier, and an OSPF PID.
[0089] A second data packet 432 is sent from the second MODEM 126 to the network device 142. The network device 142 receives the second data packet 432 and generates a second packet 434 based on the second data packet 432. The second packet 434 includes second data 440 and a second indicator 444. In a particular embodiment, the network device 142 is configured to replicate any changes made to the per-VRF instance RIB data in the combined RIB data 148. For illustration, the combined RIB data 148 is updated based on an update to the second VRF instance RIB data 152. In addition, the second identifier 442 is stripped from the second data 440 and the second indicator 444 is included in the second packet 434. The second indicator 444 indicates the VRF instance associated with the second service 164 and the second user group. In a particular embodiment, the second indicator 444 is included in the header of the second packet 434. In some embodiments, the second indicator 444 is indicated by a source address or a source port number of the header of the second packet 434. After generation, the second indicator 444 is sent to the second packet 434 via Figure 1 or Figure 2 core network 130 and network 156 or via Figure 3 The network 156 sends the second packet 434 to the one or more devices 404.
[0090] Figure 5 Depicted is a ladder diagram 500 showing the Figure 1 System 100, Figure 2 System 200 or Figure 3 A second example of network traffic transmitted by the system 300. In a particular embodiment, Figure 5 The operations shown are performed by the first device 172 , the second device 174 , the system front end 402 , the first MODEM 124 , the second MODEM 126 , the network device 142 , and one or more devices 404 .
[0091] like Figure 5 As depicted, network device 142 receives a third packet 502 from one or more devices 404. The third packet includes third data 510 and a first indicator 424. The first indicator 424 indicates a VRF instance associated with the first service 160 and the first user group. In particular embodiments, the first indicator 424 is included in a header of the third packet 502. In some embodiments, the first indicator 424 is indicated by a source address or a source port number in the header of the third packet 502. In particular embodiments, network device 142 is configured to update combined RIB data 148 based on the third packet 502 and to copy any changes made to the combined RIB data 148 to the corresponding per-VRF instance RIB data. For purposes of illustration, the first VRF instance RIB data 150 is updated based on the updates to the combined RIB data 148.
[0092] Network device 142 receives third packet 502 and generates third data packet 504 based on third packet 502. Third data packet 504 includes third data 510 and first identifier 422. In certain embodiments, first identifier 422 includes or corresponds to a tag. The tag includes a switching tag (also known as a VLAN tag or 802.1Q tag), a VRF instance identifier, and an OSPF PID. For illustration, first indicator 424 is stripped from third packet 502 and third data 510 is encapsulated in third data packet 504 along with first identifier 422.
[0093] First modem 124 receives third data packet 504 and modulates third data 510 to generate third RF signal 506. For example, third data packet 504 is received and processed at first modem 124 (e.g., a modem of first modem pool 125 associated with first service 160 and first user group) based on first identifier 422 identifying the first VRF instance (which corresponds to first service 160 and first user group). Third RF signal 506 represents third data 510 and is provided by system front end 402 for additional processing (e.g., by RFE 106) and for transmission to first device 172. In particular embodiments, third RF signal 506 corresponds to an RF channel (or other portion of the frequency spectrum) associated with first service 160 and first user group.
[0094] Network device 142 also receives a fourth packet 520 from one or more devices 404. The fourth packet includes fourth data 540 and a second indicator 444. Second indicator 444 indicates the VRF instance associated with second service 164 and the second user group. In particular embodiments, second indicator 444 is included in a header of fourth packet 520. In some embodiments, second indicator 444 is indicated by a source address or source port number in the header of fourth packet 520. In particular embodiments, network device 142 is configured to update combined RIB data 148 based on fourth packet 520 and to copy any changes made to combined RIB data 148 to the corresponding per-VRF instance RIB data. For illustration, second VRF instance RIB data 152 is updated based on updates to combined RIB data 148.
[0095] Network device 142 receives fourth packet 520 and generates fourth data packet 522 based on fourth packet 520. Fourth data packet 522 includes fourth data 540 and second identifier 442. In particular embodiments, second identifier 442 includes or corresponds to a tag. The tag includes a switch tag (also known as a VLAN tag or 802.1Q tag), a VRF instance identifier, and an OSPF PID. For illustration, second indicator 444 is stripped from fourth packet 520 and fourth data 540 is encapsulated in fourth data packet 522 along with second identifier 442.
[0096] Second modem 126 receives fourth data packet 522 and modulates fourth data 540 to generate fourth RF signal 524. For example, based on second identifier 442 identifying the second VRF instance (which corresponds to second service 164 and the second user group), fourth data packet 522 is received and processed at second modem 126 (e.g., a modem from second modem pool 127 associated with second service 164 and the second user group). Fourth RF signal 524 represents fourth data 540 and is provided by system front end 402 for additional processing (e.g., by RFE 106) and for transmission to second device 174. In particular embodiments, fourth RF signal 524 corresponds to an RF channel (or other portion of the frequency spectrum) associated with second service 164 and the second user group.
[0097] Figure 6 A method 600 for processing network traffic received from a device based on user groups and services associated with the device is shown. In a particular embodiment, as a non-limiting example, the method 600 is performed by Figure 1 System 100, Figure 2 System 200 or Figure 3 The method 600 is performed by the system 300. For convenience, the method 600 is described with respect to a particular service (eg, the first service 160) and a particular user group (eg, the first user group), and this description is not limiting.
[0098] Method 600 includes, at 602, receiving an RF signal from a subscriber device (e.g., a UE, a radio communication terminal) associated with a user group and a service via a specific RF channel accessible to the subscriber device associated with the user group and the service after the subscriber device has performed association with a network device to establish a session with the network. As a specific example, after the first device 172 has performed association with the network device 142, the satellite 102 (or satellite 302) receives an RF signal from the first device 172 via an RF channel associated with the first service 160 and the first user group (e.g., the first MVNO).
[0099] The method 600 includes performing front-end processing on the RF signal at the RFE, at 604. As a specific example, the RF signal is used to generate a second RF signal (e.g., an RF signal corresponding to a second RF channel associated with the first service 160 and the first user group) that is transmitted to the RFE 106, and the RFE 106 performs front-end processing (e.g., amplification, noise reduction, etc.) on the second RF signal.
[0100] Method 600 includes, at 606, assigning a first modem from a first modem pool to process an RF signal based on the association of the subscriber device with the user group and the service to generate a data packet, the data packet including data and an identifier of a first VRF instance associated with the user group and the service. As a specific example, base station 118 (or satellite 302) assigns a first modem 124 from a first modem pool 125 to process the second RF signal based on the association of the second RF signal with the first service 160 and the first user group (as indicated by the second RF signal corresponding to a second RF channel associated with the first service 160 and the first user group). After being assigned the second RF signal, first modem 124 generates a first data packet including the first data and a first VRF instance identifier that identifies the first VRF instance associated with the first service 160 and the first user group.
[0101] Method 600 includes, at 608, generating a packet at a network device. The packet includes data based on the combined RIB data and a header, the header including an indicator of the VRF instance. As a specific example, network device 142 generates a first packet based on combined RIB data 148, the first packet including first data and an indicator of a first VRF instance associated with a first service 160 and a first user group (e.g., as a non-limiting example, a tag or a 5-tuple). Method 600 includes, at 610, updating RIB data associated with the VRF instance based on the data packet, and, at 612, updating the combined RIB data based on the RIB data associated with the VRF instance. As a specific example, before generating the packet, network device 142 updates first VRF instance RIB data 150 based on the first data packet, and network device 142 updates combined RIB data 148 based on the update to the first VRF instance RIB data 150 (or updates to any other VRF-specific RIB data).
[0102] Method 600 includes updating subscriber information associated with the first VRF instance based on the grouping at 614. As a specific example, subscriber data server 136 updates first subscriber data 138 (e.g., subscriber data associated with the VRF instance corresponding to first service 160 and first user group) based on the first grouping.
[0103] Method 600 further includes transmitting the packet to the device via the network at 616. As a specific example, the first packet reaches the destination device via a first route through the core network 130, the network 156, or both. The first route is indicated by the first VRF instance RIB data 150 and can be different from routes traversed by packets associated with other VRF instances (and other user groups and service pairs).
[0104] By transmitting RF signals for different user groups and service pairs via different RF channels (e.g., different portions of the spectrum) and by maintaining different VRF instances for different user groups and service pairs, method 600 provides end-to-end network traffic isolation for different user groups and service pairs. Providing end-to-end network traffic isolation reduces the likelihood that subscribers of different user groups and service pairs can access data associated with a particular user group and service pair.
[0105] Figure 7 A method 700 is shown for processing traffic to be transmitted to a device based on the user group and services associated with the device. In a specific embodiment, as a non-limiting example, the method 700 is performed by Figure 1 System 100, Figure 2 System 200 or Figure 3 In some embodiments, when executing Figure 6 After or during execution of method 600 Figure 6 Method 700 is performed before method 600. For convenience, method 700 is described with respect to a particular service (eg, second service 164) and a particular user group (eg, second user group), and this description is not limiting.
[0106] Method 700 includes, at 702, receiving a packet at a network device from another device via a network. The packet includes data and a header, the header including an indicator of a VRF instance associated with a user group and a service. As a specific example, network device 142 receives a second packet from a device via network 156, core network 130, or both. The second packet includes second data and a second header, the second header indicating a second indicator of a second VRF instance associated with a second service 164 and a second user group (e.g., a second MVNO).
[0107] Method 700 includes updating subscriber information associated with the VRF instance based on the packet, at 704. As a specific example, before network device 142 receives the second packet, subscriber data server 136 receives the second packet and updates second subscriber data 140 based on the second packet.
[0108] Method 700 includes, at 706, generating a data packet based on RIB data associated with the VRF instance, the data packet including data and an identifier of the VRF instance. As a specific example, network device 142 generates a second data packet based on second VRF instance RIB data 152, the second data packet including second data and a second VRF instance identifier. Method 700 includes, at 708, updating combined RIB data based on the packet, and, at 710, updating RIB data associated with the VRF instance based on the combined RIB data. As a specific example, before generating the second data packet, network device 142 updates combined RIB data 148 based on the second packet, and network device 142 updates second VRF instance RIB data 152 based on the update to combined RIB data 148.
[0109] Method 700 includes, at 712, transmitting a data packet from the network device to a modem of the first modem pool based on the VRF instance identifier. The data packet includes data and the VRF instance identifier. For illustration, base station 118 (or satellite 302) assigns a second modem 126 (of the second modem pool 127 associated with the second service 164 and the second user group) to process the second data packet based on the second data packet including the second VRF instance identifier corresponding to the second VRF instance (e.g., the VRF instance associated with the second service 164 and the second user group).
[0110] Method 700 includes, at 714, generating an RF signal based on the data packet at the modem. As a specific example, second modem 126 generates a second RF signal based on the second data packet and provides the second RF signal to RFE 106 for front-end processing (e.g., amplification, filtering, etc.). In certain embodiments, second modem 126 associates the second RF signal with a specific logical interface (or sends the RF signal to a specific port) associated with the second service 164 and the second user group.
[0111] Method 700 further includes, at 716, transmitting an RF signal to a subscriber device associated with the user group and the service via a specific RF channel. As a specific example, satellite 102 (or payload 384 of satellite 302) receives a second RF signal from RFE 106 via a specific RF channel associated with second service 164 and the second user group. Based on the second RF signal being associated with the second service 164 and the second user group, satellite 102 (or satellite 302) generates a third RF signal corresponding to a second RF channel associated with the second service 164 and the second user group and designated for communication between the device and satellite 102 (or satellite 302). In a particular embodiment, satellite 102 (or satellite 302) transmits the third RF signal to second device 174 via the second RF channel.
[0112] By transmitting RF signals for different services and user group pairs via different RF channels (e.g., different portions of the spectrum) and by maintaining different VRF instances for different user groups and service pairs, method 700 provides end-to-end network traffic isolation for different user groups and service pairs. Providing end-to-end network traffic isolation reduces the likelihood that subscribers of different user groups and service pairs can access data associated with a particular user group and service pair.
[0113] Figure 8 A method 800 of processing network traffic associated with different VRF instances corresponding to different user groups and service pairs is shown. In a specific embodiment, as a non-limiting example, the method 800 is performed by Figure 1 System 100, Figure 2 System 200 or Figure 3 Executed by system 300, such as by network device 142.
[0114] The method 800 includes receiving a first data packet from a first MODEM in a first MODEM pool at a network device at 802. For example, the network device 142 receives a first data packet 416 from a first MODEM 124 in a first MODEM pool 125, as shown in FIG. Figure 4 The first data packet 416 includes first data 420 and a first identifier 422 (eg, a first VRF instance identifier).
[0115] Method 800 includes transmitting a first packet from a network device to a first device via a network at 804. For example, network device 142 transmits first packet 418 to first device 172 via core network 130, network 156, or both, as described with reference to FIG. Figure 4As described above, the first packet 418 includes first data 420 and a first header including a first indicator 424 associated with a first VRF instance. A first identifier 422 (e.g., a first VRF instance identifier) is associated with the first service 160 and the first user group. The first identifier 422 (e.g., a first VRF instance identifier) corresponds to (e.g., identifies) the first VRF instance associated with the first service 160 and the first user group.
[0116] The method 800 includes receiving a second data packet from a second MODEM in a second MODEM pool at the network device at 806. For example, the network device 142 receives the second data packet 432 from the second MODEM 126 in the second MODEM pool 127, as shown in FIG. Figure 4 The second data packet 432 includes second data 440 and a second identifier 442 (eg, a second VRF instance identifier).
[0117] The method 800 further includes transmitting the second packet from the network device to the second device via the network at 808. For example, the network device 142 transmits the second packet 434 via the core network 130, the network 156, or both, as described in reference to FIG. Figure 4 As described. The second packet 434 includes second data 440 and a second header, the second header including a second indicator 444 associated with the second VRF instance. A second identifier 442 (e.g., a second VRF instance identifier) is associated with the second service 164 and the second user group. The second identifier 442 (e.g., a second VRF instance identifier) corresponds to (e.g., identifies) the second VRF instance associated with the second service 164 and the second user group.
[0118] In certain embodiments, method 800 further includes generating first RIB data associated with the first VRF instance (e.g., first VRF instance RIB data 150) based on the first data packet 416, and generating second RIB data associated with the second VRF instance (e.g., second VRF instance RIB data 152) based on the second data packet 432. In some embodiments, method 800 further includes generating combined RIB data 148 (e.g., trunk RIB data) based on the first VRF instance RIB data 150 and the second VRF instance RIB data 152. In some embodiments, a first header and a second header are generated based on the combined RIB data.
[0119] In another specific embodiment, the method 800 further includes logically isolating data associated with the second VRF instance from data associated with the first VRF instance by encapsulating the data associated with the first VRF instance with a different header than the data associated with the second VRF instance. As a specific example, data packets generated by the base station 118 (or satellite 302) and associated with different VRF instances include different VRF instance identifiers (e.g., Figure 4 42 ), and packets generated by network device 142 and associated with different VRF instances include headers that include different indicators (e.g., Figure 4 424 and the second indicator 444).
[0120] In another particular embodiment, method 800 further includes updating first subscriber information (e.g., first subscriber data 138) associated with the first VRF instance based on the first grouping 418 and updating second subscriber information (e.g., second subscriber data 140) associated with the second VRF instance based on the second grouping 434.
[0121] although Figures 1 to 8 One or more of the embodiments shown or described herein may illustrate systems, devices, and / or methods according to the teachings of the present disclosure, but the present disclosure is not limited to these illustrated systems, devices, and / or methods. Figures 1 to 8 One or more functions or components of any of Figures 1 to 8 For example, the operation may be performed in combination with other operations described herein. Figure 6 One or more of the elements of method 600, Figure 7 One or more of the elements of method 700, Figure 8 Therefore, any single embodiment described herein should not be interpreted as limiting, and the embodiments of the present disclosure may be appropriately combined without departing from the teachings of the present disclosure. As an example, refer to Figures 6 to 8 One or more of the operations described may be optional, may be performed at least partially concurrently, and / or may be performed in an order different from that shown or described.
[0122] Furthermore, the present disclosure includes embodiments according to the following clauses:
[0123] 1. A system for communicating based on services and user groups, the system comprising: a plurality of modems corresponding to a plurality of modem pools, the plurality of modems comprising a first modem corresponding to a first modem pool and a second modem corresponding to a second modem pool, the first modem being configured to generate a first data packet based on a first radio frequency (RF) signal, wherein the first data packet comprises first data and a first virtual routing and forwarding (VRF) instance identifier, the second modem being configured to generate a second data packet based on a second RF signal, wherein the second data packet comprises second data and a second VRF instance identifier; and a network device communicating with the plurality of modems and being configured to : receiving the first data packet and transmitting the first packet to a first device via a network, wherein the first packet includes the first data and a first header including a first indicator, the first indicator being associated with a first VRF instance corresponding to the first VRF instance identifier, wherein the first VRF instance identifier is associated with a first service, a first user group, or both; and receiving the second data packet and transmitting a second packet to a second device via the network, wherein the second packet includes the second data and a second header including a second indicator, the second indicator being associated with a second VRF instance corresponding to the second VRF instance identifier, wherein the second VRF instance identifier is associated with a second service, a second user group, or both.
[0124] 2. A system according to clause 1, wherein the first service includes at least one of the following: first generation (1G) cellular communication, second generation (2G) cellular communication, third generation (3G) cellular communication, fourth generation (4G) cellular communication, fifth generation (5G) cellular communication, high speed packet access (HSPA), high speed downlink packet access (HSDPA), high speed uplink packet access (HSUPA), short message service (SMS), multimedia message service (MMS), Internet of Things (IoT) communication, Worldwide Interoperability for Microwave Access (WiMax) communication, Institute of Electrical and Electronics Engineers (IEEE) 802.11x communication, Wi-Fi communication, digital video broadcasting-satellite (DVB-S) communication, digital video broadcasting-satellite-second generation (DVB-S2) communication, DVB-S2 extension (DVB-S2X) communication, digital video broadcasting-return channel via satellite (DVB-RCS) communication, second generation DVB interactive satellite system (DVB-RCS2) communication or proprietary government system communication.
[0125] 3. A system according to clause 1, wherein the network device is further configured to: receive a third packet from the first device via the network, the third packet including third data and a third header including a third indicator, the third indicator being associated with the first VRF instance; and transmit a third data packet to the first MODEM, the third data packet including the third data and the first VRF instance identifier.
[0126] 4. The system of clause 3, further comprising a beamforming network configured to adjust a third RF signal based on a first set of beamforming weights associated with the first user group and the first service, wherein the first user group and the first service correspond to the first VRF instance and wherein the third RF signal is generated based on the third data packet.
[0127] 5. The system of clause 1, further comprising radio frequency equipment (RFE) configured to transmit a third RF signal, wherein the third RF signal is based on a third data packet received from the network device at the first MODEM, and wherein the third data packet includes the first VRF instance identifier.
[0128] 6. The system according to clause 5 further includes a switching circuit configured to generate multiple groups of RF signals, each group of RF signals being associated with a corresponding portion of the RF spectrum, wherein the multiple groups of RF signals include at least one RF signal, and the at least one RF signal is associated with a specific portion of the RF spectrum associated with a user group and a service.
[0129] 7. The system according to clause 6 further includes a cellular system configured to deploy the multiple groups of RF signals in an overlay pattern at a first location, wherein the specific portion of the RF spectrum is accessible by devices at the first location and associated with the user group and the service, and is inaccessible to devices not associated with the user group and the service.
[0130] 8. The system of clause 7, wherein the cellular system comprises a satellite-based cellular system or a terrestrial-based cellular system.
[0131] 9. The system of clause 6, wherein the user group includes a first mobile virtual network operator (MVNO), and wherein the plurality of modems and the network device are configured to logically isolate traffic associated with the first MVNO and the service from traffic associated with a second MVNO and another service.
[0132] 10. The system of clause 1, wherein a plurality of modem pools are associated with a plurality of virtual radio frequency (VRF) instance identifiers, and wherein each modem of the plurality of modem pools is configured to process traffic associated with a corresponding VRF instance identifier, wherein the corresponding VRF instance identifier is associated with a service, a user group, or both.
[0133] 11. The system of clause 1, wherein the first MODEM is further configured to encrypt the first data packet based on a first encryption associated with the first VRF instance, and wherein the second MODEM is further configured to encrypt the second data packet based on a second encryption associated with the second VRF instance.
[0134] 12. A satellite comprising: a payload comprising one or more antennas; a memory configured to store channel mapping data, the channel mapping data indicating a mapping of at least one radio frequency (RF) channel to different RF channels; and a processor configured to initiate transmission of a second RF signal from the one or more antennas to a first device based on the channel mapping data, a first service associated with the first device, and a first user group associated with the first device, wherein the second RF signal is based on a first RF signal received from radio frequency equipment (RFE) at the one or more antennas, wherein the first RF signal corresponds to a first RF channel, and wherein the second RF signal corresponds to a second RF channel different from the first RF channel.
[0135] 13. The satellite of clause 12, wherein the processor is further configured to initiate transmission of a fourth RF signal from the one or more antennas to the second device based on the channel mapping data, a second service associated with the second device, and a second user group associated with the second device, wherein the fourth RF signal is based on a third RF signal received from the RFE at the one or more antennas, wherein the third RF signal corresponds to a third RF channel different from the first RF channel, and wherein the fourth RF signal corresponds to a fourth RF channel different from the third RF channel and the second RF channel.
[0136] 14. The satellite of clause 13, wherein the one or more antennas are configured to superimpose transmissions of the second RF signal and the fourth RF signal at the same location.
[0137] 15. The satellite of clause 12, further comprising a beamforming network configured to adjust the second RF signal based on beamforming data stored in the memory and the first RF signal, wherein the beamforming data indicates one or more sets of beamforming weights associated with one or more user groups and one or more services.
[0138] 16. The satellite of clause 12, wherein the processor is further configured to initiate transmission of a sixth RF signal from the one or more antennas to the first device based on the channel mapping data, the first service, and the first user group, wherein the sixth RF signal is based on a fifth RF signal received at the one or more antennas from the RFE, wherein the fifth RF signal corresponds to the first RF channel, and wherein the sixth RF signal corresponds to the second RF channel.
[0139] 17. A method comprising: receiving a first data packet from a first MODEM of a first MODEM pool at a network device, the first data packet including first data and a first virtual routing and forwarding (VRF) instance identifier; transmitting the first packet from the network device to the first device via a network, wherein the first packet includes first data and a first header including a first indicator, wherein the first indicator is associated with a first VRF instance, and wherein the first VRF instance identifier is associated with a first service and a first user group; receiving a second data packet from a second MODEM of a second MODEM pool at the network device, the second data packet including second data and a second VRF instance identifier; and transmitting the second packet from the network device to the second device via the network, wherein the second packet includes second data and a second header including a second indicator, wherein the second indicator is associated with a second VRF instance, and wherein the second VRF instance identifier is associated with a second service and a second user group.
[0140] 18. The method of clause 17, wherein each of the first MODEM pool, the second MODEM pool, the first VRF instance, and the second VRF instance is instantiated at a payload of the satellite.
[0141] 19. The method of clause 17, wherein each of the first MODEM pool, the second MODEM pool, the first VRF instance, and the second VRF instance is instantiated at one or more on-ground components.
[0142] 20. The method of clause 17, further comprising: generating first routing information base (RIB) data associated with the first VRF instance based on the first data packet; and generating second RIB data associated with the second VRF instance based on the second data packet.
[0143] 21. The method of clause 20, further comprising generating combined RIB data based on the first RIB data and the second RIB data, wherein the first header and the second header are generated based on the combined RIB data.
[0144] 22. The method of clause 17, further comprising logically isolating data associated with the second VRF instance from data associated with the first VRF instance by encapsulating data associated with the first VRF instance with a different header than data associated with the second VRF instance.
[0145] 23. The method of clause 17, further comprising: updating first subscriber information associated with a first VRF instance based on the first data packet; and updating second subscriber information associated with the second VRF instance based on the second packet.
[0146] The description of the examples described herein is intended to provide a general understanding of the structure of various embodiments. The description is not intended to be a complete description of all elements and features of the apparatus and system utilizing the structure or method described herein. Many other embodiments will be readily apparent to those skilled in the art after reviewing this disclosure. Other embodiments may be utilized and may be derived from this disclosure so that structural and logical replacements and changes may be made without departing from the scope of this disclosure. For example, method operations may be performed in an order different from that shown in the figures, or one or more method operations may be omitted. Therefore, this disclosure and the accompanying drawings should be considered to be illustrative and not restrictive.
[0147] In addition, although specific examples have been shown and described herein, it should be understood that any subsequent arrangement designed to achieve the same or similar results may replace the specific embodiments shown. This disclosure is intended to cover any and all subsequent changes or modifications of the various embodiments. Combinations of the above embodiments and other embodiments not specifically described herein will be readily apparent to those skilled in the art after reading this description.
[0148] The disclosed abstract is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. In addition, in the aforementioned detailed description, various features may be combined together or described in a single embodiment to simplify the disclosure. The examples described above illustrate but do not limit the disclosure. It should also be understood that many modifications and variations are possible based on the principles of the disclosure. As reflected in the following claims, the claimed subject matter may be directed to less than all the features of any one of the disclosed examples. Therefore, the scope of the disclosure is defined by the appended claims and their equivalents.
Claims
1. A system for communicating based on services and user groups, the system comprising: Corresponding to a plurality of MODEMs in a plurality of MODEM pools, the plurality of MODEMs include: a first modem corresponding to a first modem pool, the first modem being configured to generate a first data packet based on a first radio frequency signal, namely a first RF signal, wherein the first data packet includes first data and a first virtual routing and forwarding instance identifier, namely a first VRF instance identifier; and a second MODEM corresponding to the second MODEM pool, the second MODEM being configured to generate a second data packet based on the second RF signal, wherein the second data packet includes second data and a second VRF instance identifier; and A network device, which communicates with the plurality of MODEMs and is configured to: receiving the first data packet and transmitting the first packet to a first device via a network, wherein the first packet includes the first data and a first header including a first indicator associated with a first VRF instance corresponding to the first VRF instance identifier, wherein the first VRF instance identifier is associated with a first service, a first user group, or both; and receiving a second data packet and transmitting the second packet to a second device via the network, wherein the second packet includes the second data and a second header including a second indicator associated with a second VRF instance corresponding to the second VRF instance identifier, wherein the second VRF instance identifier is associated with a second service, a second user group, or both, Each of the first MODEM pool, the second MODEM pool, the first VRF instance, and the second VRF instance is instantiated at a payload of a satellite.
2. The system of claim 1 , wherein the first service comprises at least one of first generation (1G) cellular communication, second generation (2G) cellular communication, third generation (3G) cellular communication, fourth generation (4G) cellular communication, fifth generation (5G) cellular communication, high speed packet access (HSPA), high speed downlink packet access (HSDPA), high speed uplink packet access (HSUPA), short message service (SMS), multimedia message service (MMS), Internet of Things (IoT) communication, Worldwide Interoperability for Microwave Access (WiMax) communication, Institute of Electrical and Electronics Engineers (IEEE) 802.11x communication, Wi-Fi communication, digital video broadcasting-satellite (DVB-S) communication, digital video broadcasting-satellite-second generation (DVB-S2) communication, DVB-S2 extension (DVB-S2X) communication, digital video broadcasting-return channel via satellite (DVB-RCS) communication, second generation DVB interactive satellite system (DVB-RCS2) communication, or proprietary government system communication.
3. The system of claim 1 , wherein the network device is further configured to: receiving a third packet from the first device via the network, the third packet including third data and a third header including a third indicator, the third indicator being associated with the first VRF instance; and A third data packet is transmitted to the first MODEM, where the third data packet includes the third data and the first VRF instance identifier.
4. The system of claim 3 , further comprising a beamforming network configured to adjust a third RF signal based on a first set of beamforming weights associated with the first user group and the first service, wherein the first user group and the first service correspond to the first VRF instance, and wherein the third RF signal is generated based on the third data packet.
5. The system of claim 1 , further comprising a radio frequency equipment (RFE) configured to transmit a third RF signal, wherein the third RF signal is based on a third data packet received from the network device at the first modem, and wherein the third data packet includes the first VRF instance identifier.
6. The system according to claim 5 further includes a switching circuit configured to generate multiple groups of RF signals, each group of RF signals being associated with a corresponding portion of the RF spectrum, wherein the multiple groups of RF signals include at least one RF signal, and the at least one RF signal is associated with a specific portion of the RF spectrum associated with a user group and a service.
7. The system according to claim 6 further includes a cellular system configured to deploy the multiple groups of RF signals in an overlay mode at a first location, wherein the specific portion of the RF spectrum is accessible by devices at the first location and associated with the user group and the service, and is inaccessible to devices not associated with the user group and the service.
8. The system of claim 7, wherein the cellular system comprises a satellite-based cellular system or a terrestrial-based cellular system.
9. The system of claim 6, wherein the user group includes a first mobile virtual network operator (MVNO), and wherein the plurality of modems and the network device are configured to logically isolate traffic associated with the first MVNO and the service from traffic associated with a second MVNO and another service.
10. The system of claim 1, wherein the first MODEM is further configured to encrypt the first data packet based on a first encryption associated with the first VRF instance, and wherein the second MODEM is further configured to encrypt the second data packet based on a second encryption associated with the second VRF instance.
11. The system according to any one of claims 1 to 10, wherein the plurality of MODEM pools are associated with a plurality of VRF instance identifiers, and wherein each MODEM in the plurality of MODEM pools is configured to process traffic associated with a corresponding VRF instance identifier, wherein the corresponding VRF instance identifier is associated with a service, a user group, or both.
12. A method performed by the system of any one of claims 1 to 11, the method comprising: Receiving, at a network device, a first data packet from a first modem in a first modem pool, the first data packet including first data and a first virtual routing and forwarding instance identifier, i.e., a first VRF instance identifier; transmitting a first packet from the network device to a first device via a network, wherein the first packet includes the first data and a first header including a first indicator, wherein the first indicator is associated with a first VRF instance, and wherein the first VRF instance identifier is associated with a first service and a first user group; receiving, at the network device, a second data packet from a second MODEM in a second MODEM pool, the second data packet including second data and a second VRF instance identifier; and A second packet is transmitted from the network device to a second device via the network, wherein the second packet includes the second data and a second header including a second indicator, wherein the second indicator is associated with a second VRF instance, and wherein the second VRF instance identifier is associated with a second service and a second user group.
13. The method according to claim 12, further comprising: generating first routing information base data (i.e., first RIB data) associated with the first VRF instance based on the first data packet; and Second RIB data associated with the second VRF instance is generated based on the second data packet.
14. The method of claim 12, further comprising logically isolating data associated with the second VRF instance from data associated with the first VRF instance by encapsulating data associated with the first VRF instance using a different header than the data associated with the second VRF instance.
15. The method according to claim 12, further comprising: updating first subscriber information associated with the first VRF instance based on the first packet; and Second subscriber information associated with the second VRF instance is updated based on the second packet.
Citation Information
Patent Citations
System and method for federated network traffic processing
CN108738073A