Semi-Transparent Access Node for Per-Subscriber Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional broadband access nodes lack the capability to efficiently manage and enforce per-subscriber security and traffic policies, particularly in transparent cross connection mode, where they cannot replicate multicast traffic, filter packets, or enforce policies, leading to limitations in traffic management and security.

Innovation Solution

Implementing a semi-transparent mode in broadband access nodes with 1:1 mapping between logical circuits, enabling active involvement in multicast traffic replication, subscriber-specific traffic management, and policy enforcement, including authentication, packet filtering, and dynamic multicast forwarding table adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If transparent cross connection mode is used in broadband access nodes, then traffic consolidation functionality remains centralized in BRAS or Edge Router, but the access node cannot enforce per-subscriber security policies, traffic policies, or replicate multicast traffic

Engineering Contradiction:
Improvecomplexity of policy enforcement functionsVSAvoidper-subscriber security and traffic policy enforcement
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the policy enforcement functionality by introducing a separate policy server that handles complex policy decisions while the access node executes specific policy rules. This allows the access node to enforce per-subscriber policies without consolidating all traffic management functions, resolving the contradiction between centralized complexity and distributed reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a policy server as an intermediary between the access node and the network core. This intermediary handles the complex policy enforcement tasks, allowing the access node to maintain simple transparent cross-connection functionality while still achieving reliable per-subscriber policy enforcement through the mediator's intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If aggregation mode is used at the access node, then per-subscriber security and traffic policies can be enforced, but traffic from multiple subscribers must be consolidated requiring additional functions at the access node

Engineering Contradiction:
Improveper-subscriber security and traffic policy enforcementVSAvoidtraffic consolidation and policy enforcement functions
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex traffic consolidation functions from the access node and relocates them to centralized BRAS or Edge Routers. The access node retains only the essential policy enforcement capabilities through rule-based filtering, while the extracted consolidation functions are handled by specialized network elements, reducing device complexity while maintaining security and policy enforcement.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements dynamic policy rule distribution where policy rules are dynamically pushed from the policy server to the access node based on subscriber context and service requirements. This dynamic approach allows the access node to enforce policies without permanent complex consolidation functions, reducing device complexity while maintaining enforcement reliability.

Inventive Principle:
Principle #15Dynamics

3Productivity

If transparent mapping is performed in the access node, then direct forwarding is achieved, but the access node cannot become a replication point for multicast traffic or filter packets

Engineering Contradiction:
Improveforwarding efficiencyVSAvoidmulticast replication and packet filtering capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by pre-configuring the access node with subscription information and policy rules before traffic arrives. This allows the access node to perform both transparent forwarding and selective packet filtering/multicast replication based on pre-established rules, achieving both forwarding efficiency and adaptability without real-time complex processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by enabling the access node to perform different operations on different traffic flows locally - transparent forwarding for some traffic while simultaneously performing packet filtering and multicast replication for other traffic based on subscriber-specific rules. This local differentiation allows the node to achieve both forwarding efficiency and operational versatility.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7646713B1Method and access node configured for providing intelligent cross connection functionality
Publication Date: 2010.01.12 ALCATEL-LUCENT USA LNC
  • US7646713B1 patent drawing
  • US7646713B1 patent drawing

AI summary

An access node comprises an access port configured for operating in a semi-transparent mode. The semi-transparent mode provides for 1:1 between a logical circuit on a network interface of the access node and a logical circuit on an access loop between the access port and customer premise equipment (CPE). The 1:1 mapping enables manipulation of subscriber traffic at the access port on a per-subscriber basis while maintaining logical separation of per-subscriber traffic.