Stateful ICE Message Authorization via Management Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Endpoints behind restrictive Network Address Translators (NATs) and firewalls, including asymmetric ones, are unable to establish multimedia communications due to the restrictive security policies that block Interactive Connectivity Establishment (ICE) messages, preventing the traversal of multimedia communications across these security boundaries.
Innovation Solution
A management device stores information about initial messages and sends authorization requests to security devices, allowing authorized forwarding of ICE messages through security policies and opaque tokens, enabling multimedia communications to traverse NATs and asymmetric firewalls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If security devices forward all ICE messages, then multimedia communications can be established, but security policies are violated and unauthorized communications are permitted
Solution Approach 1:
A management device is introduced as an intermediary between security devices and ICE messages. The management device receives authorization requests from security devices, validates them against stored initial message information, and provides authorization decisions. This mediator enables security devices to enforce security policies while still permitting legitimate ICE messages to traverse through NATs and firewalls.
Solution Approach 2:
The management device stores information about initial ICE messages before actual ICE communication occurs. By pre-storing this reference information, the system enables subsequent authorization decisions to be made efficiently without blocking legitimate traffic, resolving the contradiction between security enforcement and communication establishment.
2Reliability
If security devices block ICE messages, then security policies are enforced, but multimedia communications cannot traverse NATs and firewalls
Solution Approach 1:
Security devices send authorization requests to the management device, which compares them against stored initial message information and provides authorization feedback. This feedback mechanism allows security devices to dynamically adjust their filtering behavior, permitting authorized ICE messages while maintaining security policy enforcement.
Solution Approach 2:
The management device acts as an intermediary that receives authorization requests from security devices, validates them against stored initial message information, and provides authorization decisions. This mediator enables security devices to enforce security policies while still permitting legitimate ICE messages to traverse through NATs and firewalls.
3Object-affected harmful factors
If ICE messages are inspected statefully, then security boundaries are protected, but message forwarding is blocked without authorization
Solution Approach 1:
The management device stores information about initial ICE messages before actual ICE communication occurs. By pre-storing this reference information, the system enables subsequent authorization decisions to be made efficiently without blocking legitimate traffic, resolving the contradiction between security enforcement and communication establishment.
Solution Approach 2:
The management device acts as an intermediary that receives authorization requests from security devices, validates them against stored initial message information, and provides authorization decisions. This mediator enables security devices to enforce security policies while still permitting legitimate ICE messages to traverse through NATs and firewalls.
Data Source
AI summary
An endpoint uses Interactive Connectivity Establishment (ICE) to enable multimedia communications to traverse Network Address Translators (NATs). A security policy enables security devices and asymmetric security devices to forward ICE messages. A management device stores information about an initial message. Later, a security device receives an ICE message and sends and authorization request to the management device. The management device compares information in the authorization request to information in memory. According to the comparison, the management device authorizes the security device to forward the ICE message.


