Co-located SBC and Network Functions in Public Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud infrastructure struggles to efficiently co-locate and dynamically scale various network functions, such as session border controllers (SBC) and messaging/network functions, without the need for IPsec tunnels, which can be resource-intensive and complex to manage.

Innovation Solution

The solution involves creating a virtual machine image that includes a session border controller (SBC) and various network functions like SMS, UPF, and CPF, which can be dynamically instantiated in a public cloud environment without the need for IPsec tunnels between the SBC and network functions, allowing for secure communication through established IPsec tunnels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If SBC and network functions are co-located in virtual machines without IPsec tunnels, then device complexity and resource consumption are reduced, but security requirements become more challenging to meet

Engineering Contradiction:
Improvecomplexity of IPsec tunnel managementVSAvoidsecurity of communication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent merges the SBC and network functions (SMS, UPF, CPF) into a single co-located virtual machine infrastructure. This consolidation eliminates the need for complex IPsec tunnel management between separate components while maintaining security through integrated authentication and authorization mechanisms within the unified virtual machine environment.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces an authentication server as an intermediary component that handles security verification. The authentication server receives authentication requests from the SBC, verifies credentials against subscriber databases, and returns authorization decisions. This intermediary approach maintains security requirements while simplifying the overall architecture by centralizing security management outside the co-located SBC-network function infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If cloud resources are dynamically scaled, then productivity and flexibility are improved, but maintaining secure communication channels becomes more difficult

Engineering Contradiction:
Improvescaling speed of cloud resourcesVSAvoidmanagement of secure communication channels
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic scaling capabilities where the co-located virtual machine infrastructure can be rapidly instantiated, scaled, or terminated based on demand. The integrated SBC and network functions within the virtual machine can be dynamically provisioned without requiring pre-established IPsec tunnels, enabling fast cloud resource scaling while maintaining security through the authentication server's centralized control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication server is pre-configured with subscriber databases and authentication mechanisms before scaling events occur. When new virtual machine instances are dynamically created, the SBC automatically communicates with the pre-existing authentication server to establish secure communication channels, eliminating the need to set up security infrastructure in real-time during scaling operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250130835A1Method of co-locating session border controller (SBC) and voice/message functions in public cloud
Publication Date: 2025.04.24 AT&T INTELLECTUAL PROPERTY I L P
  • US20250130835A1 patent drawing
  • US20250130835A1 patent drawing
  • US20250130835A1 patent drawing

AI summary

Aspects of the subject disclosure may include, for example, co-locating network functions in virtual machines and/or containers in public clouds. A session border controller (SBC) may be combined with one or more voice and/or message services network functions. A virtual image or container runtime including co-located network functions may be provided to a public cloud service provider, and virtual machines or containers having co-located network functions may be instantiated as needed. Other embodiments are disclosed.