Session Border Controller Virtual Interface VPN Traffic Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional approaches require significant effort to create and update mapping tables on session border controllers (SBCs) in VoIP networks to identify and manage virtual private networks (VPNs), which is inefficient and complex.
Innovation Solution
Configuring SBCs with virtual interfaces associated with unique VPN identifiers, allowing traffic to be automatically routed and identified, eliminating the need for mapping tables and enabling VPN awareness without relying on VLAN tags.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If mapping tables are used to map VLAN tags to VPN customer identifiers on each SBC, then VPN traffic can be identified and routed, but the effort to create and update mapping tables on each SBC becomes significant and complex
Solution Approach 1:
The patent introduces a network controller as an intermediary device that centralizes the management of mapping between VLAN tags and VPN customer identifiers. Instead of each SBC maintaining its own mapping tables, the network controller maintains a centralized mapping table and provides mapping information to SBCs. This mediator approach resolves the contradiction by maintaining accurate VPN identification (through centralized control) while reducing complexity (by eliminating distributed mapping table management).
Solution Approach 2:
The patent extracts the mapping table management function from individual SBCs and relocates it to a dedicated network controller. By taking out the complex mapping table creation and update operations from each SBC, the system maintains accurate VPN identification capability while significantly reducing the operational complexity at each network element. The SBCs focus on their core function of traffic forwarding while the network controller handles the complex mapping management.
2Productivity
If VLAN tags are used to associate traffic with particular VPNs, then traffic can be identified, but VLAN tags are not globally unique requiring mapping tables on multiple SBCs
Solution Approach 1:
The patent makes the network controller a universal entity that serves all SBCs in the network with a single centralized mapping table. This universal approach allows the system to handle multiple VPNs with non-unique VLAN tags across different SBCs by providing a unified mapping perspective from the network controller, which can correlate VLAN tags to globally unique VPN customer identifiers regardless of which SBC the traffic passes through.
3Reliability
If SBCs process all media streams, then traffic can be monitored and controlled, but communication paths are lengthened and network performance is reduced
Solution Approach 1:
The patent enables media streams to self-determine their routing based on VPN identification. When the network controller identifies that both source and destination belong to the same VPN, it allows the media stream to bypass the SBC and route directly between endpoints. This self-service approach maintains reliability for controlled traffic (by keeping SBC processing for inter-VPN traffic) while optimizing speed for intra-VPN traffic (by enabling direct routing).
Solution Approach 2:
The patent implements dynamic routing decisions for media streams based on real-time VPN identification results. The system can adaptively change the path of media streams - routing through SBC when inter-VPN control is needed, and routing directly when same-VPN optimization is applicable. This dynamic behavior resolves the contradiction by making the system flexible enough to provide both reliable control and high-speed communication as needed.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Methods and devices for managing traffic are described. Traffic from a source in a virtual private network (VPN) is received. The traffic is directed to a virtual interface that is designated to receive traffic from the VPN. The virtual interface is configured to associate the traffic with an identifier that uniquely identifies the VPN to a session border controller (SBC). The SBC can use the identifier to determine whether the source and the destination of the traffic are i the same VPN.