Distributed ICE Policy Enforcement for VoIP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Voice Over IP (VOIP) connectivity protocols like ICE do not effectively enforce policy restrictions for media communication paths, leading to inefficient use of network resources and potential security concerns, as they rely on centralized solutions and do not account for specific enterprise requirements such as avoiding expensive WAN links or ensuring secure communication channels.

Innovation Solution

Implementing a distributed policy enforcement mechanism where endpoints involved in media communication enforce connectivity policy restrictions by selecting suitable media paths based on specified criteria, such as avoiding congested or high-cost links, using a policy manager to determine and apply restrictions directly at the client level, rather than relying on centralized hardware or servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized server or hardware is used to enforce connectivity policy restrictions, then policy enforcement capability is provided, but device complexity and cost increase

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidcentralized server hardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the policy enforcement function from the centralized server architecture and distributes it to individual endpoints. Each endpoint runs a policy enforcement module that independently evaluates and enforces connectivity policies, eliminating the need for complex centralized hardware while maintaining reliable policy enforcement through decentralized execution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Endpoints perform self-service by autonomously evaluating connectivity policies and making routing decisions without requiring centralized server intervention. The policy enforcement module at each endpoint independently assesses available paths against policy criteria and selects appropriate routes, reducing device complexity while ensuring consistent policy compliance

Inventive Principle:
Principle #25Self-service

2Speed

If the most efficient path is selected by ICE based on media latency, then communication quality is improved, but network resource utilization costs increase due to expensive WAN links

Engineering Contradiction:
Improvemedia latencyVSAvoidnetwork resource utilization cost
Core Design Contradiction:
SpeedVSLoss of energy

Solution Approach 1:

The patent extends ICE's path selection criteria by adding policy parameters beyond media latency. The policy evaluation module considers multiple parameters including cost metrics, bandwidth availability, and path restrictions, transforming the single-parameter latency optimization into a multi-parameter optimization that balances communication quality with network resource utilization costs

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system dynamically adjusts path selection based on real-time policy evaluations and network conditions. Rather than statically selecting the lowest-latency path, the endpoint continuously assesses available paths against updated policy criteria and dynamically switches between paths to optimize both communication quality and cost efficiency

Inventive Principle:
Principle #15Dynamics

3Reliability

If centralized hardware is used for policy enforcement, then security control is improved, but ease of operation and deployment deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Endpoints autonomously enforce security policies through locally executed policy modules, eliminating the operational complexity of centralized hardware deployment. Each endpoint independently loads, interprets, and enforces security policies, making the system easier to deploy and operate while maintaining strong security control through distributed enforcement

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The policy enforcement module at each endpoint provides universal functionality by handling multiple security and connectivity policy requirements through a single integrated component. This multi-functional approach simplifies deployment compared to specialized centralized hardware, as the same endpoint module handles diverse policy enforcement needs across different network scenarios

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10693919B2Distributed connectivity policy enforcement with ICE
Publication Date: 2020.06.23 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10693919B2 patent drawing
  • US10693919B2 patent drawing
  • US10693919B2 patent drawing

AI summary

Instead of utilizing a centralized server or hardware(routers/gateways) to enforce connectivity policy restrictions, the policy connectivity restrictions for media session traffic are enforced by an endpoint that is involved in the media communication. Based on the policy requirements, the client enforces the policy restrictions by restricting the candidates that may be selected for the establishment of the media path. For example, the enforcement may result in the client selecting a path from available candidates that avoids congested Wide Area Network (WAN) links, avoiding a low bandwidth link, or possibly even failing the communication completely. The clients may also provide periodic updates to the policy server to allow tracking of the utilization of managed WAN links.