3.1 NG911 Architecture: The ESInet & Core Services
Key Takeaways
- The Emergency Services IP Network (ESInet) is an engineered, private, multi-tenant IP transport infrastructure governed by NENA-STA-010 that securely interconnects originating service providers, core services, and PSAPs.
- Next Generation Core Services (NGCS) comprise specialized software functional entities including the Emergency Service Routing Proxy (ESRP), Policy Routing Function (PRF), Emergency Call Routing Function (ECRF), Location Validation Function (LVF), and Location Information Server (LIS).
- Strict Quality of Service (QoS) using Differentiated Services (DiffServ) prioritizes traffic: Expedited Forwarding (EF / DSCP 46) for emergency voice RTP, Assured Forwarding 31 (AF31 / DSCP 26) or CS3 (DSCP 24) for SIP signaling, and AF41 (DSCP 34) for real-time video.
- Common voice-quality engineering targets for ESInet designs (drawn from ITU-T G.114 guidance and carrier SLAs rather than a NENA-mandated number) keep one-way mouth-to-ear delay under about 150 ms, jitter low enough for de-jitter buffers, packet loss well under 1%, and perceived quality near toll grade (MOS about 4.0).
- Mission-critical public safety SLAs mandate 99.999% availability (maximum 5.26 minutes of unplanned downtime annually), dual-carrier transport with true physical route diversity, and a Mean Time to Repair (MTTR) under 4 hours.
3.1 NG911 Architecture: The ESInet & Core Services
Quick Answer: An Emergency Services IP Network (ESInet) is an engineered, private, managed IP transport backbone governed by NENA-STA-010. It carries emergency voice, video, text, and rich data among Originating Service Providers (OSPs), Next Generation Core Services (NGCS), and Public Safety Answering Points (PSAPs). Unlike the best-effort public Internet, an ESInet enforces strict Quality of Service (QoS) using DiffServ Expedited Forwarding (EF / DSCP 46) for audio media and Assured Forwarding (AF31 / DSCP 26) for SIP signaling. It guarantees 99.999% ("five nines") availability through physically diverse, dual-carrier transport architectures.
The Shift to Managed IP Transport
In legacy Enhanced 9-1-1 (E9-1-1) architectures, emergency calls traversed dedicated analog or time-division multiplexed (TDM) copper trunk lines, such as Centralized Automatic Message Accounting (CAMA) and Signalling System No. 7 (SS7) trunks, terminating at legacy selective routers. This architecture restricted communications to narrowband voice plus the caller's number (ANI), with location retrieved separately from the ALI database.
As described in NENA-STA-010 (NENA i3 Standard for Next Generation 9-1-1) and the design guidance in NENA-INF-016 (Emergency Services IP Network Design Information Document), the Emergency Services IP Network (ESInet) fundamentally transforms public safety communications. The ESInet is an engineered, private, managed Multi-Protocol Label Switching (MPLS) or Carrier Ethernet IP network. Rather than serving as an isolated application, the ESInet acts as the shared, secure IP transport fabric upon which all Next Generation Core Services (NGCS) operate—including the Location Information Server (LIS), Emergency Call Routing Function (ECRF), Location Validation Function (LVF), and Emergency Service Routing Proxy (ESRP).
+-------------------------------------------------------------------------+
| EMERGENCY SERVICES IP NETWORK (ESInet) |
| |
| +-------------+ +--------------+ +---------------------+ |
| | NGCS Core | <--> | Policy-Based | <--> | Location Services | |
| | (ESRP/BCF) | | Routing (PRF)| | (ECRF / LVF / LIS) | |
| +-------------+ +--------------+ +---------------------+ |
| ^ ^ |
+----------|----------------------------------------------|---------------+
| (Secure Private Ingress) | (Private Interconnect)
+----------v--------------+ +----------v--------------+
| Originating Providers | | Primary & Backup PSAPs |
| (Wireline, Wireless, IP)| | (Call-Handling / CAD) |
+-------------------------+ +-------------------------+
Key characteristics of the ESInet include:
- Inter-Agency Interoperability: Enables seamless interconnection between municipal, county, regional, state, and federal emergency entities.
- Multi-Media Delivery: Concurrently transports high-definition audio, real-time interactive video, Real-Time Text (RTT), Computer Aided Dispatch (CAD) incident data, and rich Geographic Information Systems (GIS) spatial datasets.
- Scalable Multicast and Unicast: Supports point-to-point emergency routing as well as broadcast incident dissemination to mutual-aid dispatch centers.
Next Generation Core Services (NGCS) Functional Architecture
Next Generation Core Services (NGCS) are the standardized software applications and functional elements hosted on the ESInet that process, validate, route, and log emergency sessions:
- Emergency Service Routing Proxy (ESRP): The NG911 next-hop routing engine. The ESRP is an RFC 3261 SIP proxy server that evaluates incoming emergency calls, queries location and policy engines, and forwards calls to the appropriate destination (another ESRP or a PSAP).
- Policy Routing Function (PRF): The software decision logic integrated with or queried by an ESRP. The PRF evaluates dynamic operational policies—such as time of day, console availability, queue depth, or emergency rollover conditions—to determine the final routing destination.
- Emergency Call Routing Function (ECRF): An interactive spatial database service that accepts a caller's geographic coordinates (or validated civic address) and a Service URN (
urn:service:sos), performing spatial point-in-polygon queries against authoritative GIS boundary layers to return the routable SIP URI of the serving PSAP. - Location Validation Function (LVF): A pre-call validation service that checks civic addresses against authoritative GIS road centerlines and address point layers before emergency calls are placed, ensuring that civic locations resolve deterministically during live emergencies.
- Location Information Server (LIS): A functional entity located in the originating access network that stores subscriber geodetic or civic location and provides it to endpoints or core services via Presence Information Data Format Location Objects (PIDF-LO).
- Forest Guide: A hierarchical routing infrastructure connecting regional and state ECRFs, enabling emergency calls to be routed to the correct destination even when the caller's location falls completely outside the local or regional ESInet boundary.
- Discrepancy Reporting (DR): A standardized i3 function used to log, report, and track operational, GIS, or protocol discrepancies (e.g., location lookup failures or malformed SIP headers) between interconnecting NG911 entities.
Private Managed IP Transport vs. The Public Internet
NENA's ESInet design guidance strongly favors managed, private IP transport with engineered service levels over the unmanaged public Internet as the primary path for emergency call delivery. While consumer Over-The-Top (OTT) VoIP services operate over best-effort Internet connections, emergency services demand deterministic reliability.
| Architectural Attribute | Private Managed ESInet | Public Internet |
|---|---|---|
| Packet Delivery Model | Deterministic with bandwidth guarantees | Best-effort (uncontrolled queuing) |
| Quality of Service (QoS) | Strict hardware-enforced DiffServ / MPLS EXP | Ignored or stripped across transit Autonomous Systems (AS) |
| Latency & Jitter | Contractually bounded through carrier SLAs | High variance, bufferbloat, unpredictable spikes |
| Availability SLAs | 99.999% uptime with 2-to-4 hour Mean Time to Repair (MTTR) | No availability or restoration guarantees |
| Security & Exposure | Closed perimeter, private addressing, mTLS, BCF protection | Exposed to global DDoS, scanning, BGP hijacking, spoofing |
Operational Warning: Public Internet connections may only be used as a secondary, encrypted overlay (via IPsec VPN tunnels) during catastrophic failover scenarios or for non-mission-critical out-of-band administrative updates. Routing primary live emergency voice or video across the open Internet without managed service levels conflicts with NENA ESInet design guidance and adds avoidable reliability and security risk.
Layer 2 and Layer 3 Transport Options
Public safety agencies construct ESInets using several underlying Layer 2 and Layer 3 wide area network (WAN) transport technologies:
1. Multi-Protocol Label Switching (MPLS) Layer 3 VPNs
MPLS is the industry standard for regional and statewide ESInet deployments. MPLS allows network carriers to encapsulate IP packets with 32-bit labels, establishing Virtual Private Routed Networks (VPRNs). Key public safety advantages include:
- Traffic Engineering (MPLS-TE): Pre-allocates deterministic paths through the provider core, preventing traffic congestion.
- Fast Reroute (FRR): Provides sub-50-millisecond circuit failover if a primary fiber link is severed, ensuring live 9-1-1 audio does not drop.
- Class of Service (CoS) Mapping: Maps IP Differentiated Services Code Point (DSCP) values directly to 3-bit MPLS Experimental (EXP) bits across the core.
2. Carrier Ethernet (E-Line, E-LAN, E-Tree)
Governed by the Metro Ethernet Forum (MEF), Carrier Ethernet delivers standardized Layer 2 Ethernet services across metro and regional scales:
- Ethernet Private Line (E-Line / EVPL): Point-to-point dedicated bandwidth connecting a PSAP directly to an ESInet core data center.
- Ethernet Private LAN (E-LAN): Multipoint-to-multipoint service connecting multiple PSAPs in a shared regional consortium.
- Advantage: Lower protocol encapsulation overhead and native Layer 2 framing, though requiring upstream Layer 3 routing management.
3. Dark Fiber with Dense Wavelength Division Multiplexing (DWDM)
Municipalities or regional consortia that own or lease unlit optical fiber ("dark fiber") can deploy dedicated optical transceivers using Coarse or Dense Wavelength Division Multiplexing (CWDM/DWDM). By assigning dedicated optical wavelengths (lambdas) exclusively to public safety traffic, agencies achieve near-zero latency, multi-gigabit throughput, and complete physical layer isolation from commercial traffic.
4. IPsec VPN Tunnels (Overlay Transport)
When connecting remote secondary answering points or mobile incident command vehicles where dedicated fiber or MPLS circuits are economically or physically unfeasible, encrypted IPsec (Internet Protocol Security) tunnels serve as an overlay. However, IPsec incurs packet encapsulation overhead (typically 50-70 bytes per packet) and remains subject to the latency and packet loss fluctuations of the underlying broadband connection.
Quality of Service (QoS) & DiffServ DSCP Engineering
Because IP networks are packet-switched, multiple data flows compete for interface queue space. Without prioritization, large GIS shapefile transfers or CAD database synchronizations could monopolize buffer queues, causing emergency voice packets to be delayed or dropped.
NG911 networks enforce Differentiated Services (DiffServ - IETF RFC 2474 / RFC 2475). Network routers classify, mark, and police packets at the ingress edge using the 6-bit Differentiated Services Code Point (DSCP) field within the IPv4 Type of Service (ToS) byte or IPv6 Traffic Class octet.
IPv4 Header: [ Version (4b) | IHL (4b) | Type of Service / DSCP (6b) + ECN (2b) | Total Length (16b) ]
\-----------------------/
DSCP Bits 0-5 (0 to 63)
Typical ESInet QoS designs follow IETF DiffServ guidance (such as RFC 4594) to assign queuing priorities across traffic classes. The delay, jitter, and loss columns below are common engineering targets, not NENA-mandated values:
| Traffic Class | DSCP Name | DSCP Value (Dec / Bin) | Per-Hop Behavior (PHB) | Target Packet Delay | Target Jitter | Target Loss |
|---|---|---|---|---|---|---|
| Emergency Voice RTP | Expedited Forwarding (EF) | 46 / 101110 | Strict Priority Queuing (SPQ); preempts all other traffic | < 50 ms | < 10 ms | < 0.1% |
| Emergency Video RTP | Assured Forwarding (AF41) | 34 / 100010 | Low-latency weighted fair queuing (CBWFQ); rate policed | < 80 ms | < 15 ms | < 0.5% |
| SIP Signaling / Call Control | Assured Forwarding (AF31) or CS3 | 26 / 011010 (or 24 / 011000) | High-priority guaranteed bandwidth; avoids tail-drop | < 100 ms | < 20 ms | < 0.1% |
| Interactive CAD / GIS Data | Assured Forwarding (AF21) | 18 / 010010 | Guaranteed transactional bandwidth; medium drop precedence | < 200 ms | < 50 ms | < 1.0% |
| Administrative / Web | Best Effort (BE) | 0 / 000000 | Default FIFO queuing; dropped first during congestion | N/A | N/A | Variable |
Expedited Forwarding (EF - DSCP 46)
EF provides a low-loss, low-latency, low-jitter end-to-end service. In hardware routers, EF traffic is placed into a Strict Priority Queue (SPQ). As long as packets reside in the EF queue, the router services them before any other queue. To prevent a malicious or malfunctioning voice endpoint from starving other critical services, the ingress BCF applies policing and shaping to strictly limit EF traffic to its negotiated bandwidth ceiling.
Assured Forwarding (AF) and Call Signaling
SIP signaling packets (INVITE, 100 Trying, 180 Ringing, 200 OK) must not be dropped. Dropping an INVITE or ACK causes SIP retransmission timers to trigger (Timer A starts at 500 ms and doubles), introducing unacceptable call-setup delays. SIP signaling is marked with AF31 (DSCP 26) or Class Selector 3 (CS3 / DSCP 24), guaranteeing bandwidth even when network links reach 100% saturation.
Network Performance Thresholds for Public Safety
To keep emergency voice intelligible, ESInet designers typically work to the following engineering targets, drawn from ITU-T Recommendation G.114 and carrier service-level agreements:
- One-Way Latency (Delay): Keep mouth-to-ear delay under about 150 milliseconds (the ITU-T G.114 planning guideline), with network transit budgeted well below that. Delays exceeding 200 ms cause callers and call-takers to talk over one another.
- Jitter (Delay Variation): Keep jitter low (designs commonly target under about 30 milliseconds). Excessive jitter exceeds the capacity of the receiving device's de-jitter buffer, leading to buffer underruns and dropped audio frames.
- Packet Loss: Keep loss well below 1% on voice streams. While VoIP concealment algorithms can reconstruct single lost packets, burst packet loss produces garbled speech and dropped syllables.
- Mean Opinion Score (MOS): Aim for perceptual voice quality around a MOS of 4.0 (on a 1.0 to 5.0 scale), representing toll-quality audio.
Bandwidth Sizing, Physical Diversity, and High Availability
Bandwidth Engineering Calculations
Bandwidth dimensioning must accommodate peak concurrent busy-hour call volumes, multi-party conferencing, high-definition video, and CAD/GIS data spikes:
- A standard uncompressed G.711 voice call generates 64 kbps of raw payload. When encapsulated with IP (20 bytes), UDP (8 bytes), RTP (12 bytes), and Layer 2 framing (18 bytes Ethernet) at a 20 ms packetization rate (50 packets per second), the actual consumed bandwidth is 87.2 kbps per concurrent call.
- A two-way interactive video stream (H.264 at 720p/30fps) consumes 1.5 to 2.5 Mbps.
- High-resolution GIS map layers, aerial orthophotography, and building floor plans pushed to CAD consoles require burst allocations of 10 to 50 Mbps.
Physical Route Diversity vs. Carrier Redundancy
A frequent operational pitfall in emergency communications procurement is confusing carrier diversity with physical route diversity.
FLAWED ARCHITECTURE (Common Point of Failure):
+-------------+ Carrier A (Contract 1) +-------------------+
| ESInet / | ===========================> | Shared Underground| ===> [ PSAP ]
| Data Center | Carrier B (Contract 2) | Conduit / Bridge |
+-------------+ ===========================> +-------------------+
^
[Severed by Backhoe!]
TRUE PHYSICALLY DIVERSE ARCHITECTURE (Zero Common Failure):
+-------------+ ===== Carrier A (North Path / Aerial) =====> [ Demarc A ]
| ESInet / | |
| Data Center | ===== Carrier B (South Path / Buried Trench) => [ Demarc B ]
+-------------+ |
[ Dual-Homed CPE Routers ]
True high availability requires:
- Diverse Rights-of-Way: Carrier circuits must travel along completely separate geographic paths (e.g., North entrance via buried trench along Highway 10; South entrance via aerial utility poles along 5th Street).
- Entrance Facility Diversity: The PSAP facility must feature two physically separated building entry points (demarcation rooms) located on opposite exterior walls.
- Dual-Homing & Hardware Redundancy: Edge routers must operate in active/standby or active/active pairs running Virtual Router Redundancy Protocol (VRRP) or Hot Standby Router Protocol (HSRP), peering over Border Gateway Protocol (BGP) with independent Autonomous System Numbers (ASNs).
Service Level Agreements (SLAs) & Operational Metrics
Public safety contracts with telecommunications carriers must mandate stringent, enforceable Service Level Agreements:
- 99.999% Availability ("Five Nines"): Total unplanned circuit unavailability across the core ESInet cannot exceed 5.26 minutes per calendar year.
- Mean Time to Repair (MTTR): In the event of a catastrophic circuit failure, the carrier must contractually guarantee an MTTR of <= 2 to 4 hours, backed by 24/7/365 dedicated public safety dispatch technicians.
- Continuous Performance Verification: The carrier must provide continuous, real-time proactive monitoring (via Synthetic Network Probes and SNMP/NetFlow monitoring) with automated alerting to the PSAP IT Director and state 9-1-1 authority upon any threshold breach.
In a standard ESInet QoS design, which Differentiated Services Code Point (DSCP) marking and Per-Hop Behavior (PHB) should be applied to real-time voice RTP streams traversing the ESInet to ensure minimal latency and jitter?
A regional 9-1-1 authority contracts with two separate telecommunications providers to provide redundant ESInet connections to an Emergency Communications Center. During highway utility work, a contractor severs a single underground concrete vault, taking down both carrier links simultaneously. What critical architectural failure does this event represent?
In an NG911 architecture, which functional entity operates as a hierarchical routing database used to resolve call routing destinations when a caller's location falls completely outside the geographic boundary of the local or regional Emergency Call Routing Function (ECRF)?