Multimedia Border Controller for Cross-VPN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network communication carriers face challenges in providing multimedia over Internet Protocol (MoIP) services across different virtual private networks (VPNs) without compromising security, as existing solutions require expensive equipment and complicate routing schemes due to private IP address overlaps and non-routability of entities across VPNs.

Innovation Solution

A multimedia over Internet Protocol border controller is introduced to process MoIP calls by registering endpoints, associating VPN IDs, performing address translation, and modifying message addressing to enable secure communication between endpoints from different VPNs, thereby avoiding hair-pinning and ensuring network compatibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network address translator and firewall (NAT/FW) functions are deployed at the edge of each customer network to provide centralized voice services, then each enterprise is protected from the rest of the network and is uniquely addressable, but expensive and redundant equipment must be added to each enterprise network and the routing scheme is further complicated

Engineering Contradiction:
Improvenetwork securityVSAvoidrouting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the NAT/FW functions from multiple customer network edges into a single centralized border controller. This consolidation eliminates the need for expensive NAT/FW equipment at each enterprise while maintaining security and addressability. The centralized controller handles address translation and routing for all customers, simplifying the overall routing scheme.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The border controller acts as an intermediary between the centralized voice extranet and customer networks. It performs address translation and routing functions that were previously distributed across multiple customer edge devices. This intermediary approach maintains network security while simplifying the routing infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If NAT/FW functions are deployed at customer network edges to support MoIP services, then enterprise protection and unique addressability are ensured, but the use of virtual routers at the network is limited

Engineering Contradiction:
Improveenterprise protectionVSAvoidvirtual router utility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

By consolidating NAT/FW functions into a centralized border controller, the patent frees up virtual routers to be used more effectively for their primary purpose of creating virtual links between customer sites. The virtual routers are no longer burdened with additional NAT/FW responsibilities, increasing their adaptability and versatility.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If endpoints from different VPNs need to communicate, then centralized voice services can be provided across multiple VPNs, but VPNs use private IP address schemes that overlap with each other making entities non-routable

Engineering Contradiction:
Improvecross-VPN communicationVSAvoidaddress translation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The border controller serves as an intermediary that performs address translation between different VPNs with overlapping private IP address schemes. It maintains translation tables that map private addresses from different VPNs to unique addresses in the centralized voice extranet, enabling cross-VPN communication while handling the complexity of address translation centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The centralized border controller provides a universal address translation service for all customers across multiple VPNs. Instead of each customer network needing its own translation mechanism, the single border controller handles address translation for all VPNs, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7411975B1Multimedia over internet protocol border controller for network-based virtual private networks
Publication Date: 2008.08.12 JUNIPER NETWORKS INC
  • US7411975B1 patent drawing
  • US7411975B1 patent drawing
  • US7411975B1 patent drawing

AI summary

A method for communicating packet multimedia data between a source endpoint and a destination endpoint is disclosed, wherein at least the source endpoint is within a virtual private network, and comprises the steps of receiving, at a signaling controller, a first signaling packet from the source endpoint, wherein the source endpoint is within a virtual private network; determining whether the source endpoint and destination endpoint may communicate directly over the same virtual private network; when the source endpoint and destination endpoint cannot communicate directly over the same virtual private network, associating a unique identifier of the source endpoint with a virtual private network identification marker; when the source endpoint and destination endpoint can communicate directly over the same virtual private network, instructing the source endpoint and destination endpoint to communicate media packets directly.