Session Border Controller VPN Traffic Routing via VLAN Tags

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional approaches require significant effort to create and update mapping tables on session border controllers (SBCs) in VoIP networks to identify and manage traffic within virtual private networks (VPNs), which is inefficient and increases overhead.

Innovation Solution

Configuring SBCs with virtual interfaces associated with unique VPN identifiers, allowing traffic to be automatically routed and identified, eliminating the need for mapping tables and enabling seamless VPN awareness without bypassing necessary services or policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If mapping tables are used to identify VPN traffic on SBCs, then VPN traffic identification capability is improved, but device complexity and maintenance effort increase

Engineering Contradiction:
ImproveVPN traffic identification capabilityVSAvoidmapping table management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the VPN identification function from the mapping tables and relocates it to VLAN tags. By using VLAN tags that are already present in the network infrastructure, the solution eliminates the need for separate mapping tables on SBCs, thereby reducing device complexity while maintaining VPN identification capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes VLAN tags serve multiple functions: they continue to identify virtual networks as before, and additionally provide VPN identification capability. This multi-functionality approach eliminates the need for separate mapping tables, reducing complexity while improving identification capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If mapping tables are maintained on each SBC, then traffic routing accuracy is improved, but loss of time for table updates and maintenance increases

Engineering Contradiction:
Improvetraffic routing accuracyVSAvoidtable update and maintenance time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent removes the time-consuming mapping table maintenance operation by extracting the identification function and implementing it through VLAN tags that are automatically processed by the network infrastructure, eliminating manual or system-driven table updates

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The network infrastructure automatically handles VPN identification through VLAN tags without requiring manual intervention or system-driven updates. The system self-manages traffic routing decisions based on the inherent VLAN tag information, eliminating maintenance time losses

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If SBC processes all traffic for VPN identification, then traffic management capability is improved, but processing overhead increases

Engineering Contradiction:
Improvetraffic management capabilityVSAvoidSBC processing overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the VPN identification function from the SBC processing pipeline and implements it at the network infrastructure level through VLAN tags. This allows SBCs to bypass complex identification processing for intra-VPN traffic, reducing processing overhead while maintaining traffic management capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments traffic processing into two paths: one for intra-VPN traffic that can bypass the SBC, and another for inter-VPN traffic that requires SBC processing. This segmentation reduces the processing burden on SBCs by allowing them to focus only on necessary traffic management tasks

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7787478B2Managing traffic within and between virtual private networks when using a session border controller
Publication Date: 2010.08.31 CISCO TECHNOLOGY INC
  • US7787478B2 patent drawing
  • US7787478B2 patent drawing
  • US7787478B2 patent drawing

AI summary

Methods and devices for managing traffic at a session border controller (SBC) are described. A signal portion of traffic en route from a source in a virtual private network (VPN) to a destination is received. The signal portion has embedded therein an identifier that uniquely identifies the VPN. The identifier is accessed to determine whether the destination is also in the VPN. A decision whether to direct a media portion of the traffic to an SBC is made depending on whether or not the destination is outside of the VPN.