Intelligent Switch Segregating Voice and Data Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional VoIP networks are vulnerable to security threats and reliability issues, where a compromised data network can lead to outages in the IP-based voice network, making it undesirable for enterprise environments.
Innovation Solution
An intelligent switch for packetized voice communication that employs a multi-layer switch with ingress processing and filtering means to segregate voice and data networks, policing data rates, authenticating devices, and ensuring only authorized voice traffic passes through, thereby preventing unauthorized data from entering the voice network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If VoIP networks are built on top of enterprise data networks to maximize network utilization, then cost efficiency and resource sharing are improved, but security and reliability deteriorate because data network outages or compromises directly affect voice services
Solution Approach 1:
The patent segments the network into distinct voice network and data network domains using a multi-layer switch. The switch separates voice traffic (IP phones, VoIP servers) from data traffic (computers, printers) at Layer 2, while maintaining controlled interconnection at Layer 3. This segmentation allows voice services to operate independently from data network issues, resolving the reliability problem while preserving network utilization benefits.
Solution Approach 2:
The multi-layer switch acts as an intermediary device between the voice network and data network. It controls and filters traffic flow between these domains, allowing necessary communication while preventing harmful traffic from affecting voice services. The switch's ingress filtering and policing functions serve as protective mediation, enabling both networks to coexist without direct vulnerability exposure.
2Ease of operation
If conventional LAN switches are used for voice traffic without ingress filtering, then device simplicity and ease of operation are improved, but security deteriorates because unauthorized or malicious traffic can enter the voice network
Solution Approach 1:
The patent implements preliminary action by configuring ingress filtering rules and data rate policing parameters on the multi-layer switch before deploying voice services. The switch is pre-configured with ACLs, VLAN assignments, and bandwidth limits that automatically filter and control traffic. This preliminary setup ensures security is built-in from the start, maintaining ease of operation while preventing unauthorized traffic intrusion.
Data Source
AI summary
A switching apparatus for switching packetized voice traffic between a plurality of communication devices, the switching apparatus comprises a multi-layer switch, a plurality of communication ports, control means and ingress processing means, said packetized voice traffic comprises call control packets and medium packets which are exchanged between the communication devices via said communication ports, wherein medium packet traffic from a first communication device to a second communication device is split into a first call segment and a second call segment, the first call segment originates from said first communication devices and terminates at said switching apparatus, the second call segment originates from said switching apparatus and terminates at said second communication device, each medium packet from said first communication device is processed by said ingress processing means of said switching apparatus before onward transmission to said second communication device.


