Split Control Plane Architecture for SD-WAN Private Mobile Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current private mobile networks based on cellular technology have not been seamlessly integrated into enterprise cloud-native technologies like SD-WAN and SSE, lacking global management and resiliency, and are inadequate for use cases requiring specific coverage, reliability, and latency, such as rural areas.
Innovation Solution
A software-defined private mobile network (SD-PMN) architecture is implemented with control plane components deployed at physical locations and SD-WAN PoPs, utilizing security gateways, UPFs, AMFs, and SMFs, along with SD-WAN edge routers and gateways to establish IPsec and DMPO tunnels, enabling centralized management and multi-tenant resiliency through a common IP address.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a private mobile network based on cellular technology is deployed, then coverage and reliability are improved, but integration with enterprise cloud-native technologies (SD-WAN, SSE) is lacking
Solution Approach 1:
The network is segmented into control plane functions (AMF, SMF, UDM) deployed at SD-WAN PoPs and user plane functions (UPF) deployed at enterprise locations. This segmentation allows the control plane to leverage SD-WAN's cloud-native integration while the user plane maintains cellular technology's reliability for local traffic handling.
Solution Approach 2:
The SD-WAN edge router acts as an intermediary between the cellular-based private mobile network and the SD-WAN core network. It establishes DMPO tunnels that enable seamless integration while preserving the distinct characteristics of both systems.
2Ease of operation
If control plane components are deployed at multiple physical locations, then global management capability is improved, but device complexity increases
Solution Approach 1:
The SD-WAN gateway deployed at each PoP provides universal control plane functions (AMF, SMF, UDM) that can serve multiple enterprises and multiple physical locations. This multi-functionality simplifies global management by providing a standardized interface across all locations while reducing overall network complexity through consolidation.
3Reliability
If SD-WAN edge routers are assigned primary and secondary gateways, then system resiliency is improved, but connection management complexity increases
Solution Approach 1:
The SD-WAN edge router dynamically selects between primary and secondary gateways based on real-time network conditions and availability. This dynamic behavior provides automatic failover capability that improves resiliency while the SD-WAN controller abstracts the complexity of managing multiple connections.
Solution Approach 2:
The system implements feedback mechanisms where the SD-WAN edge router continuously monitors the status of primary and secondary gateway connections and automatically switches between them based on this feedback, providing resiliency without requiring complex manual management.
4Reliability
If a common IP address is used for control plane components at multiple PoPs, then failover capability is improved, but network configuration complexity increases
Solution Approach 1:
The same control plane component images (AMF, SMF, UDM) are copied and deployed at multiple PoPs, each providing the same services with the same IP address. This copying approach enables seamless failover while the SD-WAN orchestrator automatically manages the configuration complexity of maintaining identical copies across locations.
Data Source
AI summary
Some embodiments provide a method for implementing a software-defined private mobile network (SD-PMN) for an entity. At a physical location of the entity, the method deploys a first set of control plane components for the SD-PMN, the first set of control plane components including a security gateway, a user-plane function (UPF), an AMF (access and mobility management function), and an SMF (session management function). At an SD-WAN (software-defined wide area network) PoP (point of presence) belonging to a provider of the SD-PMN, the method deploys a second set of control plane components for the SD-PMN that includes a subscriber database that stores data associated with users of the SD-PMN. The method uses an SD-WAN edge router located at the physical location of the entity and a SD-WAN gateway located at the SD-WAN PoP to establish a connection from the physical location of the entity to the SD-WAN PoP.


