Network as a Service.
Driven by SDN and AI.

IDL integrates a cloud-native delivery model, as-a-service consumption, zero trust security and AI networking into a single architecture. One platform, nine ways to deploy it — from the carrier core to the living room, and from Wi-Fi to the IoT radios beside it. Open or IDL-native: on our access points, that stays your call.

The NaaS Architecture Every solution below is a deployment of the same platform

IDL NaaS architecture — SDN controller, AI engine, NFV, edge computing, cloud integration

SD-WiFi

Carrier Wi-Fi offload — Wi-Fi as a first-class RAT inside the 3GPP core

High-band 5G struggles to penetrate buildings, and new base stations are expensive and hard to site. IDL integrates Wi-Fi into the operator's core network as an alternate radio access technology, delivering unified mobility, unified policy and unified authentication across both networks.

  • Managed Offload — SIM-based authentication (EAP-SIM/AKA) with the operator's AAA, HSS/HLR and PCRF enforcing consistent policy
  • Integrated Offload — Wi-Fi traffic tunneled into the packet core for full feature parity and seamless mobility
  • Hyper-Cellular 5G — SDN and NFV network slicing across macro, micro and pico cells, cutting 5G build cost by over 30%
  • Wi-Fi Calling (VoWiFi) — 3GPP-compliant ePDG integration with both 4G and 5G cores, fixing indoor voice coverage
  • Wireless Access Gateway — wide-area Layer 2 via SoftGRE/EtherIP, AAA proxy, per-user policy, carrier-grade NAT, content filtering and parental control
  • Passpoint / Hotspot 2.0 — one SSID fronting many providers, with silent, secure onboarding

Proven at scale: over 100,000 access points deployed and managed across a Tier-1 operator's national converged 4G + Wi-Fi network.

IDL vCPE — home traffic tunneled to the edge cloud

OpenWiFi · Dual-Image AP

One access point. Two firmware images. The choice stays open.

Service providers are asked to make the hardest call at the worst possible moment — before a single access point is on a wall. Commit to a vendor stack and inherit lock-in. Commit to OpenWiFi and inherit its gaps in carrier authentication, billing and offload. IDL removes the fork. The same access point ships with either image: IDL's own carrier-grade firmware, or TIP OpenWiFi. The platform decision becomes a software decision — reversible, site by site, at no hardware cost.

One SKU, not twoSame silicon, same RF design, same regulatory certifications, same spares pool. One hardware qualification cycle covers both software paths — and your warehouse only stocks one part number.
Switch in the fieldMoving a site between images is a firmware operation, not a truck roll with new boxes. Pilot OpenWiFi across ten sites without buying a second inventory, and fall back just as cheaply if the pilot says so.
No bet to placeAnswer an open-standards tender without giving up the carrier feature set, or ship carrier features today without closing the open door. Whichever way the market moves, the hardware you bought is still the right hardware.

Carrying a second software line is only cheap because of how the first one is built: the wireless stack is already split from the silicon beneath it, so a second image is another consumer of that boundary rather than a second product. See the platform architecture.

What each image gives you

IDL imageOpenWiFi image
FirmwareIDL WLAN firmware, hardened across national carrier deploymentsTIP OpenWiFi, tracking the upstream release train
ManagementIDL NMP cloud platform, IAC controllers or CloudOSAny CloudSDK-compatible controller — a third-party platform or your own build
Carrier integrationEAP-SIM/AKA, Passpoint, SoftGRE/EtherIP WAG, VoWiFi, per-user policy and billingOpenWiFi standard feature set, integrated through your own controller and AAA
ProvisioningController discovery or cloud zero-touch provisioningZero-touch provisioning against your OpenWiFi controller
Multi-vendorIDL stack end to endInteroperable with any TIP OpenWiFi device and controller
SourceIDL-maintainedOpen source — auditable by your own engineering team
Best fitNetworks that need carrier authentication, billing and 3GPP offload todayEstates where openness, auditability and controller freedom decide the tender

Available on selected IDL Wi-Fi 6 and Wi-Fi 7 access points. Evaluation units and images are shipping now — ask us which models are qualified for your band plan and regulatory domain.

Who this is for

  • Operators running a multi-year tender — qualify one access point, then decide the software line per region, per contract, or per phase, without re-opening procurement
  • Wholesale and managed Wi-Fi providers — meet the enterprise customer who writes "no vendor lock-in" into the RFP, and the one who wants full-service carrier features, from the same warehouse
  • MDU, student housing and hospitality specialists — standardize on one AP across a mixed portfolio where each property owner brings a different management platform
  • Operators who want an exit that costs nothing — the strongest argument for adopting our stack is that leaving it does not mean replacing the hardware

Where this is going — one operational view

Two images should never mean two operations teams. IDL is extending NMP into a single management plane that carries both: the installed base keeps running exactly as it does today, new sites go open, and both appear in one operational view. Existing estate untouched, new capacity open, one place to look — that is the shape of the migration, and it is on the roadmap rather than a condition of starting.

Until then the open path is already unblocked: the OpenWiFi image runs under any CloudSDK-compatible controller, so you can start on a third-party platform, or your own, and consolidate later on your schedule.

SD-Edge

Simplify the edge — a fully virtualized, software-defined carrier edge

Broadband providers are squeezed: subscribers now buy connectivity alone, margins are thinning, and session management still runs on fixed hardware. IDL separates the control and data planes of the BNG and extends the home LAN into the edge cloud — so operators can move beyond selling a dumb pipe. SD-Edge ships in two product forms, sharing one platform.

IDL vCPE — home traffic tunneled to the edge cloud
Enterprise Gateway/Scenario-Based uCPE Deployment and Carrier Aggregation Layer vCPE Deployment

SD-Edge·vCPE

Remote edge — for home broadband and carriers

The ONT drops back to bridge mode and the gateway itself moves to the cloud. No access network rebuild, no truck roll.

  • Subscribers identified by QinQ, transported over SRv6; virtual gateways are allocated on demand and reclaimed when idle — 256 vGWs pooled per vCPE instance
  • For the first time the operator can see inside the home network, so faults are diagnosed online instead of on site
  • Households inherit carrier-grade security — firewall, virus scanning, intrusion detection — plus cloud NAS, cloud desktop and cloud gaming as add-ons
  • Service activation drops from 2–3 days to self-service in the operator's app, opening real upsell and ARPU growth
IDL vCPE — home traffic tunneled to the edge cloud
Home traffic tunneled to the edge cloud, where the gateway now lives

SD-Edge·uCPE

Near edge — for enterprises and branches

Where the customer needs the box on their own premises, the same software functions are modularized and virtualized onto white-box hardware. Every department gets its own security profile — because not every group carries the same risk, and performance shouldn't be spent on policies a group doesn't need.

VNF service chains are built by drag-and-drop from templates and matched by VLAN range or 5-tuple. A single VNF can be referenced by many chains; DPI, security gateway, TDF, CGNAT, WAG, BNG and ACF converge onto one virtualized platform at ultra-low latency.

IDL uCPE — VNF service chaining per department
VNF service chaining on uCPE — each department gets only the functions it needs

SD-Edge·Edge AI

Intelligence that runs where the data is

  • Containerized AI applications — Docker at the edge lets AI workloads be deployed onto converged gateways independently, in an app-store model
  • Cloud-trained, edge-inferenced — models trained in the cloud cooperate with a local AI engine, so intelligent applications work without a round trip
  • AIoT in practice — IoT data aggregation, QoE probes and scenario-specific enterprise applications

Deployment is your choice: bare metal, virtual machine (KVM, VMware, OpenStack), or public and private cloud — including hybrid.

Six things operators tell us matter: one line serving many purposes · zero access network rebuild · short activation cycle · flexible point-to-point expansion · low operational complexity · full autonomy and control.

IDL Edge AI — one model trained in the cloud, inference running on each converged gateway for AIoT aggregation, QoE probing and scenario apps
Three edge workloads on one platform — AIoT aggregation, QoE probing and scenario apps — each a container, all inferencing locally

SD-Access

A zero-trust campus fabric — without replacing your switches

Policy-driven segmentation normally arrives with a bill for a whole new equipment stack: competing fabrics expect every switch to come from one vendor. IDL takes a different route. Traffic is steered to policy enforcement nodes over a tunnel overlay, so the campus keeps the switches it already owns.

  • Dynamic segmentation — a wide Layer 2 overlay built on VxLAN, SRv6 or QinQ. VLANs bind to identity, not to a port: a user changes desk or building and the policy follows them. VRFs keep groups logically isolated. Three patents applied for on this technology.
  • PON/POL integration — our clearest differentiator. Passive optical LAN removes fabric edge nodes entirely and connects one hop to the BRAS, cutting infrastructure, power draw and capital cost
  • Intent-based automation — administrators declare the outcome; the platform configures the network, via GUI or API
  • NAC and identity services — endpoints mapped to groups automatically, with full asset visibility, which matters most for IoT
  • Policy enforcement — firewall, VPN, DPI, anti-rogue-device, with telemetry fed back for coordinated enforcement
  • AI-driven assurance — flow analysis from endpoint to application, reducing support effort and OPEX

In production: a university town campus network, and a national campus deployment in Central Asia.

IDL SD-Access campus fabric architecture
Campus fabric — automation, assurance, identity services and policy enforcement

SD-Branch

Networking, security and SD-WAN converged into one gateway

Small and medium businesses are being asked to digitize with none of the budget, none of the certified staff and none of the tolerance for complexity that legacy enterprise networking assumes. IDL collapses routing, switching, security and Wi-Fi management into a single software-defined platform.

  • Intelligent security gateway — the cornerstone. SD-WAN link optimization and automatic routing, firewall and DPI, and management of the branch's own APs, switches and IoT devices. It is the single interface between the branch and the cloud orchestrator
  • Zero-touch provisioning — ship the device to the site and it comes up configured. No IT visit, which is the whole game across dozens of branches
  • Cloud-edge collaborative scheduling — compute placed at the edge and dynamically scheduled against the cloud, cutting latency and cost
  • An app store for the network — Docker and VM workloads run directly on the converged gateway: IoT data aggregation, QoE probes, line-of-business applications
  • Three-in-one gateway — PoE, access control and routing in one unit, built for operators reselling into the SMB market
IDL SD-Access campus fabric architecture

MDU

One SSID for the whole property. A private network for every unit.

The router-per-apartment habit quietly destroys the airwaves: dozens of SSIDs, beacons eating over half the available airtime, and neighbours' signals bleeding through walls. Residents respond by installing their own gear, which makes it worse for everyone. Enterprise-style per-device onboarding is no answer either — no resident wants a RADIUS workflow for a new TV.

  • sPSK (Sensed PSK) — our patented technology, and the heart of the design. Each unit gets its own pre-shared key, distributed encrypted, while the property broadcasts a single SSID. A resident onboards once through a captive portal; after that every device they own — laptop, printer, Apple TV, or a headless IoT sensor with no screen at all — joins with the same unit key
  • Per-unit VLAN isolation — Unit 501 lands on VLAN 501. Devices inside a home talk to each other freely; nothing crosses between homes
  • vTenant — centralized or local forwarding, so the network follows the resident across the property, with SLA monitoring and failover keepalive
  • Managed Mesh — residents extend coverage inside their own unit with EasyMesh, third-party APs included, and every mesh stays visible to the operator

Built for: apartments · student housing · senior and assisted living · townhouses.

Why property owners care: Wi-Fi becomes a billable utility like water or power — bundled into the lease or tiered as an upsell. Occupancy rises, churn and trouble tickets fall, and the same network carries the building's own systems: access control, surveillance, climate, door locks.

IDL MDU — one SSID, per-unit PPSK and VLAN isolation
One SSID across the property; a per-unit key mapped to a per-unit VLAN

IoT-Convergence

One site install. Wi-Fi and IoT on the same access point.

Every new IoT service arrives with its own radio and,usually, its own network. Door locks speak one protocol, safety buttons another, asset tags a third,thermostats plain Wi-Fi. Each lands as a parallel overlay with its own hubs, its own cable run, its own PoE ports, its own controller and its own support contract. In a hospital or a hotel that means opening the ceiling a second, third and fourth time — and paying for every one of those installs. IDL access points carry a PCIe expansion slot. The IoT radio goes inside the AP, not on a hub bolted up beside it. One site survey, one cable, one PoE port,one management plane — and the IoT layer can be added long after the Wi-Fi went in, by fitting a module rather than re-wiring a building.

  • PCIe, not a dongle — an internal bus gives the module a real power budget and real bandwidth, antennas integrated into the enclosure, and nothing exposed to be knocked off or walked away with in a guest area. Modules run alongside the Wi-Fi radios and feed straight into the AP's own CPU
  • LoRa / LoRaWAN — sub-GHz carries across a whole building and into the basements, stairwells and lift shafts short-range radio never reaches, at battery life measured in years rather than weeks. Standard LoRaWAN, so the device ecosystem stays open: badges, trackers, sensors and meters from any LoRa Alliance vendor
  • BLE 5.x — the ecosystem locks, panic buttons and asset tags already ship with. Every AP becomes a receiver, so there is no separate beacon grid to install, power, battery-swap and maintain
  • Hybrid positioning — models trained on the Wi-Fisignals already in the air give zone-level location with no beacons at all, and combine with GPS, BLE, Wi-Fi and LoRa for tracking that survives the walk from the car park to the ward
  • Processing at the AP — the containerized edge runtime from SD-Edge runs the aggregation and positioning engine on site. A duress alarm is raised inside the building even if the WAN is down, while northbound MQTT and REST feed the partner application
  • One management plane — Wi-Fi, wired and IoT together under NMP: device inventory, module firmware, protocol state and telemetry in one console, not four

Built for the buildings where both networks share a ceiling

  • Hospitals— staff duress badges that report a location, not just an alarm; wander protection for patients; wheelchairs, pumps and beds tracked instead of hunted for; cold-chain temperature and humidity monitoring for pharmacy and lab refrigeration
  • Hotels— housekeeping safety buttons that name the exact room, connected door locks reporting open and unlocked status, in-room climate and energy control, minibar and room-status sensing— all over the same APs already carrying guest Wi-Fi
  • MDU — smart locks and virtual re-keying, leak and smoke detection, sub-metering, parcel lockers, parking and EV charging. Devices that do speak Wi-Fi are already handled by per-unit VLANs and sPSK; this covers everything that doesn't

Why it pays: one truck roll instead of four, cabling and PoE ports that aren't duplicated, and capital deferred until the service is actually sold — fit the module then. When the next protocol wins, it is a module, not a forklift. For property owners, IoT becomes a service line sitting on top of the Wi-Fi they were building anyway.

IDL context-aware DPI — turning traffic into user context for QoE, location and cloud services
The IoT radio moves inside the access point — one install, one uplink, one management plane
Expansion slot support and module availability vary by AP model and by regional radio approval — ask us which platforms fit your deployment.

AIOPS

From reactive monitoring to a network that explains itself

Traditional monitoring is single-signal and after-the-fact: it tells you something broke, once users have already noticed. IDL's AIOps platform ingests logs, metrics and external signals together, and reasons across them.

  • One model, many signals — log rates, sequences and structure, numeric and discrete field behaviour, and time-of-day seasonality are learned in a single unified model rather than a stack of disconnected alarms
  • Anomalies found, not thresholded — bidirectional transformers detect contextual anomalies in log sequences; distribution drift is measured continuously against learned baselines; density clustering isolates numeric outliers
  • Root cause, not just a score — correlated symptoms are traced back to the exact originating log lines, and the precise moment a fault began is located automatically
  • Ranked by an LLM — the noisiest part of any incident is the log flood. A large language model ranks what actually matters and writes an actionable root-cause summary
  • It keeps learning — models retrain as the environment changes, with reinforcement learning tuning detection in place
IDL AIOps — from raw signal to actionable root cause
From raw signal to actionable root cause

Security

Secure gateway and DPI engine

Security stopped being a box you bolt on at the perimeter. In every solution above it is already there: in the campus enforcement node, in the edge service chain, in the carrier Wi-Fi gateway filtering content for a family. IDL builds it in rather than selling it back to you.

IDL DPI engine — AI-driven identify, process and adapt cycle

Secure Gateway — UTM and next-generation firewall

This is the same gateway that anchors SD-Branch. Deployed at a branch it is an SD-WAN edge; deployed at a perimeter it is a next-generation firewall. One product, one policy model, one console.

  • Firewall and VPN, application control, intrusion prevention, antivirus and URL filtering — consolidated into one platform instead of four standalone appliances
  • Sized for the market it serves: enterprise firewall, UTM and SD-WAN for small business, and hardened security for OT environments
  • Delivered as an appliance, a virtual machine, or from the cloud

IDL DPI Engine

Visibility is the prerequisite for every other control. The IDL DPI Engine is available as an embedded SDK and as a standalone probe, built on industry-leading deep packet inspection technology.

  • Identifies 3,600+ protocols and applications, including encrypted and evasive traffic, and SCADA/IoT industrial protocols
  • Extracts 5,400+ metadata attributes for real-time classification of packets and flows
  • Optimize — SD-WAN steering, policy control, QoS and network performance monitoring
  • Monetize — subscriber analytics and vCPE value-added services
  • Protect — next-generation firewall, malware detection, DLP and secure web gateway

Around the engine, IDL builds what turns detection into product: the policy enforcement layer, unified policy push from the cloud platform to every gateway, and the application control, content filtering and parental control your subscribers actually touch.

IDL context-aware DPI — turning traffic into user context for QoE, location and cloud services
The DPI engine turns raw traffic into user context that every service above can act on

Want the detail behind any of these?

Architecture notes, deployment references and technical documentation are available on request. Tell us which solution you're evaluating and we'll get the right material to you.

Talk to our team

Let's talk about the network you're building.