Stateful ICE Message Authorization via Management Device

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Endpoints behind restrictive Network Address Translators (NATs) and firewalls, including asymmetric ones, are unable to establish multimedia communications due to the restrictive security policies that block Interactive Connectivity Establishment (ICE) messages, preventing the traversal of multimedia communications across these security boundaries.

Innovation Solution

A management device stores information about initial messages and sends authorization requests to security devices, allowing authorized forwarding of ICE messages through security policies and opaque tokens, enabling multimedia communications to traverse NATs and asymmetric firewalls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security devices forward all ICE messages, then multimedia communications can be established, but security policies are violated and unauthorized communications are permitted

Engineering Contradiction:
Improvemultimedia communication establishmentVSAvoidsecurity policy enforcement
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A management device is introduced as an intermediary between security devices and ICE messages. The management device receives authorization requests from security devices, validates them against stored initial message information, and provides authorization decisions. This mediator enables security devices to enforce security policies while still permitting legitimate ICE messages to traverse through NATs and firewalls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The management device stores information about initial ICE messages before actual ICE communication occurs. By pre-storing this reference information, the system enables subsequent authorization decisions to be made efficiently without blocking legitimate traffic, resolving the contradiction between security enforcement and communication establishment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security devices block ICE messages, then security policies are enforced, but multimedia communications cannot traverse NATs and firewalls

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidmultimedia communication establishment
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Security devices send authorization requests to the management device, which compares them against stored initial message information and provides authorization feedback. This feedback mechanism allows security devices to dynamically adjust their filtering behavior, permitting authorized ICE messages while maintaining security policy enforcement.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The management device acts as an intermediary that receives authorization requests from security devices, validates them against stored initial message information, and provides authorization decisions. This mediator enables security devices to enforce security policies while still permitting legitimate ICE messages to traverse through NATs and firewalls.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If ICE messages are inspected statefully, then security boundaries are protected, but message forwarding is blocked without authorization

Engineering Contradiction:
Improvesecurity boundary protectionVSAvoidICE message forwarding
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The management device stores information about initial ICE messages before actual ICE communication occurs. By pre-storing this reference information, the system enables subsequent authorization decisions to be made efficiently without blocking legitimate traffic, resolving the contradiction between security enforcement and communication establishment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The management device acts as an intermediary that receives authorization requests from security devices, validates them against stored initial message information, and provides authorization decisions. This mediator enables security devices to enforce security policies while still permitting legitimate ICE messages to traverse through NATs and firewalls.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7472411B2Method for stateful firewall inspection of ICE messages
Publication Date: 2008.12.30 CISCO TECHNOLOGY INC
  • US7472411B2 patent drawing
  • US7472411B2 patent drawing
  • US7472411B2 patent drawing

AI summary

An endpoint uses Interactive Connectivity Establishment (ICE) to enable multimedia communications to traverse Network Address Translators (NATs). A security policy enables security devices and asymmetric security devices to forward ICE messages. A management device stores information about an initial message. Later, a security device receives an ICE message and sends and authorization request to the management device. The management device compares information in the authorization request to information in memory. According to the comparison, the management device authorizes the security device to forward the ICE message.