Session Border Controller Virtual Interface VPN Traffic Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches require significant effort to create and update mapping tables on session border controllers (SBCs) in VoIP networks to identify and manage virtual private networks (VPNs), which is inefficient and complex.

Innovation Solution

Configuring SBCs with virtual interfaces associated with unique VPN identifiers, allowing traffic to be automatically routed and identified, eliminating the need for mapping tables and enabling VPN awareness without relying on VLAN tags.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If mapping tables are used to map VLAN tags to VPN customer identifiers on each SBC, then VPN traffic can be identified and routed, but the effort to create and update mapping tables on each SBC becomes significant and complex

Engineering Contradiction:
ImproveVPN traffic identification accuracyVSAvoidmapping table management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a network controller as an intermediary device that centralizes the management of mapping between VLAN tags and VPN customer identifiers. Instead of each SBC maintaining its own mapping tables, the network controller maintains a centralized mapping table and provides mapping information to SBCs. This mediator approach resolves the contradiction by maintaining accurate VPN identification (through centralized control) while reducing complexity (by eliminating distributed mapping table management).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the mapping table management function from individual SBCs and relocates it to a dedicated network controller. By taking out the complex mapping table creation and update operations from each SBC, the system maintains accurate VPN identification capability while significantly reducing the operational complexity at each network element. The SBCs focus on their core function of traffic forwarding while the network controller handles the complex mapping management.

Inventive Principle:
Principle #2Taking out (Extraction)

2Productivity

If VLAN tags are used to associate traffic with particular VPNs, then traffic can be identified, but VLAN tags are not globally unique requiring mapping tables on multiple SBCs

Engineering Contradiction:
Improvetraffic identification efficiencyVSAvoidVPN identifier uniqueness
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent makes the network controller a universal entity that serves all SBCs in the network with a single centralized mapping table. This universal approach allows the system to handle multiple VPNs with non-unique VLAN tags across different SBCs by providing a unified mapping perspective from the network controller, which can correlate VLAN tags to globally unique VPN customer identifiers regardless of which SBC the traffic passes through.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If SBCs process all media streams, then traffic can be monitored and controlled, but communication paths are lengthened and network performance is reduced

Engineering Contradiction:
Improvetraffic control capabilityVSAvoidcommunication path speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent enables media streams to self-determine their routing based on VPN identification. When the network controller identifies that both source and destination belong to the same VPN, it allows the media stream to bypass the SBC and route directly between endpoints. This self-service approach maintains reliability for controlled traffic (by keeping SBC processing for inter-VPN traffic) while optimizing speed for intra-VPN traffic (by enabling direct routing).

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements dynamic routing decisions for media streams based on real-time VPN identification results. The system can adaptively change the path of media streams - routing through SBC when inter-VPN control is needed, and routing directly when same-VPN optimization is applicable. This dynamic behavior resolves the contradiction by making the system flexible enough to provide both reliable control and high-speed communication as needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP1992122B1Managing traffic within and between virtual private networks when using a session border controller
Publication Date: 2016.01.13 CISCO TECHNOLOGY INC
  • EP1992122B1 patent drawingFigure 1
  • EP1992122B1 patent drawingFigure 2A
  • EP1992122B1 patent drawingFigure 2B

AI summary

Methods and devices for managing traffic are described. Traffic from a source in a virtual private network (VPN) is received. The traffic is directed to a virtual interface that is designated to receive traffic from the VPN. The virtual interface is configured to associate the traffic with an identifier that uniquely identifies the VPN to a session border controller (SBC). The SBC can use the identifier to determine whether the source and the destination of the traffic are i the same VPN.