Distributed ICE Policy Enforcement for VoIP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Voice Over IP (VOIP) connectivity protocols like ICE do not effectively enforce policy restrictions for media communication paths, leading to inefficient use of network resources and potential security concerns, as they rely on centralized solutions and do not account for specific enterprise requirements such as avoiding expensive WAN links or ensuring secure communication channels.
Innovation Solution
Implementing a distributed policy enforcement mechanism where endpoints involved in media communication enforce connectivity policy restrictions by selecting suitable media paths based on specified criteria, such as avoiding congested or high-cost links, using a policy manager to determine and apply restrictions directly at the client level, rather than relying on centralized hardware or servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a centralized server or hardware is used to enforce connectivity policy restrictions, then policy enforcement capability is provided, but device complexity and cost increase
Solution Approach 1:
The patent segments the policy enforcement function from the centralized server architecture and distributes it to individual endpoints. Each endpoint runs a policy enforcement module that independently evaluates and enforces connectivity policies, eliminating the need for complex centralized hardware while maintaining reliable policy enforcement through decentralized execution
Solution Approach 2:
Endpoints perform self-service by autonomously evaluating connectivity policies and making routing decisions without requiring centralized server intervention. The policy enforcement module at each endpoint independently assesses available paths against policy criteria and selects appropriate routes, reducing device complexity while ensuring consistent policy compliance
2Speed
If the most efficient path is selected by ICE based on media latency, then communication quality is improved, but network resource utilization costs increase due to expensive WAN links
Solution Approach 1:
The patent extends ICE's path selection criteria by adding policy parameters beyond media latency. The policy evaluation module considers multiple parameters including cost metrics, bandwidth availability, and path restrictions, transforming the single-parameter latency optimization into a multi-parameter optimization that balances communication quality with network resource utilization costs
Solution Approach 2:
The system dynamically adjusts path selection based on real-time policy evaluations and network conditions. Rather than statically selecting the lowest-latency path, the endpoint continuously assesses available paths against updated policy criteria and dynamically switches between paths to optimize both communication quality and cost efficiency
3Reliability
If centralized hardware is used for policy enforcement, then security control is improved, but ease of operation and deployment deteriorate
Solution Approach 1:
Endpoints autonomously enforce security policies through locally executed policy modules, eliminating the operational complexity of centralized hardware deployment. Each endpoint independently loads, interprets, and enforces security policies, making the system easier to deploy and operate while maintaining strong security control through distributed enforcement
Solution Approach 2:
The policy enforcement module at each endpoint provides universal functionality by handling multiple security and connectivity policy requirements through a single integrated component. This multi-functional approach simplifies deployment compared to specialized centralized hardware, as the same endpoint module handles diverse policy enforcement needs across different network scenarios
Data Source
AI summary
Instead of utilizing a centralized server or hardware(routers/gateways) to enforce connectivity policy restrictions, the policy connectivity restrictions for media session traffic are enforced by an endpoint that is involved in the media communication. Based on the policy requirements, the client enforces the policy restrictions by restricting the candidates that may be selected for the establishment of the media path. For example, the enforcement may result in the client selecting a path from available candidates that avoids congested Wide Area Network (WAN) links, avoiding a low bandwidth link, or possibly even failing the communication completely. The clients may also provide periodic updates to the policy server to allow tracking of the utilization of managed WAN links.


