Session Aggregator for Secure Data Stream Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multiprotocol label switching (MPLS) is statically configured and delivers communication services as a proprietary, expensive solution, while 'over-the-top' Internet communication is inherently insecure, lacking flexible and cost-effective secure communication options across multiple networks without network-to-network interfaces (NNIs).
Innovation Solution
An orchestrator virtualized network function (VNF) collects performance metrics to dynamically determine secure routing paths and configure edge and core routers, establishing trusted end-to-end communication links without NNIs, using a trusted security zone with hardware root of trust and secure execution environment to ensure secure and flexible communication over the Internet.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If MPLS is used to provide communication services, then communication speed and reliability are improved, but cost and device complexity increase
Solution Approach 1:
The patent implements dynamic routing path determination based on real-time performance metrics collected from multiple networks. The orchestrator VNF continuously monitors network conditions and dynamically selects optimal routing paths, replacing static MPLS configuration with adaptive routing that responds to changing network states, thereby maintaining reliability without requiring complex static configuration.
Solution Approach 2:
The session aggregator node acts as an intermediary between customer premises equipment and multiple network service providers. It consolidates routing instructions from multiple networks and manages end-to-end communication sessions, simplifying the complexity by providing a single point of control rather than requiring direct configuration across multiple network boundaries.
2Speed
If static MPLS configuration is used, then routing speed is improved, but adaptability to changing network conditions deteriorates
Solution Approach 1:
The system dynamically determines routing paths based on real-time performance metrics collected from routers across multiple networks. The orchestrator VNF continuously monitors network conditions and updates routing instructions accordingly, enabling the system to adapt to changing network states while maintaining efficient data transmission through optimized path selection.
Solution Approach 2:
The patent implements a feedback mechanism where performance metrics are continuously collected from network routers and fed back to the orchestrator VNF. This feedback loop enables real-time adjustment of routing paths based on actual network conditions, allowing the system to respond to changes in network performance, load, and availability dynamically.
3Adaptability or versatility
If over-the-top Internet communication is used, then cost and flexibility are improved, but security deteriorates
Solution Approach 1:
The patent establishes trusted security zones within the session aggregator node where sensitive operations such as routing instruction generation and session management occur. By creating localized secure environments for critical functions while allowing flexible over-the-top communication elsewhere in the system, it achieves both security for critical operations and flexibility for data transmission.
Solution Approach 2:
The session aggregator node serves as a trusted intermediary that manages end-to-end communication sessions over the Internet. It establishes secure communication channels and manages routing instructions between customer premises equipment and multiple network service providers, providing security through centralized control and verification while maintaining the flexibility of over-the-top Internet communication.
4Adaptability or versatility
If network-to-network interfaces (NNI) are used to connect multiple networks, then network interoperability is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the NNI functionality from the traditional network architecture by implementing session aggregation at the application layer over standard Internet protocols. Instead of requiring specialized NNI interfaces between networks, the system uses existing Internet infrastructure with the session aggregator node managing multi-network communication through software-based routing instructions, eliminating complex interface hardware and configuration.
Data Source
AI summary
A system for proving secure streamed data sessions is disclosed. The system comprises a first computer system executing an orchestrator virtualized network function (VNF). The orchestrator VNF collects performance metrics on routers, receives a request for a secure streamed data session, analyzes the metrics based on the request, determines a secure routing path, creates a routing instruction set that defines the secure routing path, and transmits the routing instruction set to a session aggregator. The system further comprises a second computer system that executes the session aggregator in a trusted security zone. The session aggregator establishes trusted end-to-end communication links with a first edge router, a second edge router, and at least one of the plurality of routers and configures the routing instruction set into each of the CPE node, the first edge router, the second edge router, and the at least one router via the trusted end-to-end communication link.


