Summary

  • RFC 3487 required a SIP priority indication to invoke a named policy rather than encode queueing, preemption, reserved capacity or session duration.
  • One label could cause different actions at a gateway, circuit network, proxy or receiver; recognition, authorization, admission, media capacity and completed communication remained separate receipts.

A priority label looks like an imperative. Put it on a request and the network should move the request forward. RFC 3487 began from the opposite engineering fact: the caller could not know which resource would be scarce, which institution controlled it or which action would preserve service. In February 2003, the document therefore specified requirements for emergency preparedness communications without defining a protocol feature. Its most durable choice was to make the future signal a name for policy, not a miniature policy program.

The distinction mattered because a SIP session crossed unlike machines. RFC 3487 counted at least five resource surfaces. A gateway had a finite number of trunks into a circuit-switched network. The circuit network had its own scarce paths and established schemes such as GETS or MLPP. An IP network carried signaling and media but controlled quality through mechanisms outside SIP. A receiving system could run out of sessions. A proxy could run out of computation even while access bandwidth remained available. There was no requirement that one mechanism govern all five.

Each surface could answer congestion differently. A gateway might queue an attempt or seek an alternate carrier. A circuit system might preempt an existing call where regulation and local procedures allowed it. A receiver might alert an operator that a high-priority call was waiting, or displace a current session. A proxy might schedule one class first, reject requests or silently drop selected work. The label did not erase ownership of those decisions.

Topology further limited the control plane. RFC 3487 examined IP end-to-end, IP-to-CSN, CSN-to-IP and CSN-IP-CSN paths. In a bridged call, the originating side might not know which signaling protocol the far circuit network used. A SIP gateway might not even know whether forking would end in an IP device, a circuit endpoint or both. The same request could therefore encounter a different set of controllable resources depending on its route.

The surrounding IP network also came in degrees. An agency-owned network could modify routers and reservation behavior. A transparent network merely forwarded valid packets. A SIP/RTP-transparent network might permit calls while blocking RSVP or nonzero DSCP values. A restricted SIP network might reject new headers or methods. A useful priority indication had to survive these environments rather than assume that every router or operator had joined one design.

This is where RFC 3487 drew its central line. Call-by-value would place detailed treatment in the request: queue this attempt, never preempt, restrict the session to three minutes. Call-by-reference instead supplied a label for a named policy. The element that owned the constrained resource interpreted that policy locally. Even the fraction of capacity assigned to a level stayed outside the wire signal.

The choice prevented a distant application from pretending to administer resources it could not observe. If prioritized attempts were rare and capacity large, waiting briefly might be less destructive than ending another call. Elsewhere, preemption could be necessary. Another entity could treat the label only as a reason not to discard the request. RFC 3487 explicitly allowed one indication to cause preemption in one place and altered queueing in another.

The requirements then built portability around that thin signal. Namespaces had to support different national and private schemes. The indication could not depend on one operator architecture or destination address. It had to be valid in-band SIP, work across methods, and preserve information through CSN-IP-CSN translation when both circuit networks used the same scheme. When their schemes differed, the RFC conceded that some information might be lost.

Unsupported networks exposed another boundary. The desired default was treatment no worse than an ordinary request. Yet a local network could require appropriate marking and authentication before permitting any call. Discovery could tell a terminal which namespaces an element recognized, either through an explicit list or by trying and receiving an unsupported response. Recognition was not capacity, and capacity was not authorization.

Identity alone did not settle priority. The same authorized person could place ordinary and prioritized calls, and the requested level depended on human judgment in a particular emergency. RFC 3487 described treatment as the product of authenticated identity, user choice and policy. A caller name was not a standing entitlement, while a selected label was not proof that the user was allowed to use it.

Security consequently occupied more than a closing paragraph. Priority abuse could consume the very resources reserved for recovery and deny them to legitimate users. Authentication had to occur early enough to limit packets, computation and scarce circuit time spent on unauthorized attempts. Nodes should verify authorization independently instead of relying on transitive trust. Replay, cut-and-paste and bid-down attacks all received explicit attention.

Privacy complicated that discipline. A borrowed terminal should not force an emergency worker to reveal a reusable secret. The fact that a call requested special treatment could itself disclose sensitive circumstances. Routing data might need hop-by-hop protection while information unused for routing could be protected end to end. The priority indication and the authentication mechanism therefore remained separate design objects.

RFC 4412 later turned these requirements into the Resource-Priority and Accept-Resource-Priority SIP headers. A value such as a namespace and level expressed desired priority, and an OPTIONS response could advertise accepted values. The later standard still warned that acceptance did not imply sufficient resources or success. Subsequent documents registered namespaces, connected priority to routing and admission systems, and added stronger authorization evidence. They extended the chain; they did not collapse it.

The historical reconstruction should preserve that chain in order. Record the actor, authenticated identity, selected namespace and value, SIP method and topology. Identify every gateway, proxy, receiver and circuit domain that interpreted the request, along with its local policy version. Then preserve routing, queueing, admission, preemption, media allocation and the final human outcome as distinct events.

Heng Lu's insistence on separating symbolic authority from executable control fits the design. The label was visible and portable precisely because it was thin. The operational decision remained with the element that owned the scarce resource. RFC 3487 did not promise uniform treatment. It created a common way to ask unlike systems to consult their own accountable rules—and left an evidence trail showing why the answer could change at every boundary.

Sources