IP Phone Firewall Module for Network Packet Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IP phones lack effective mechanisms to inspect and filter data packets, leading to the potential disruption of networks and endpoints by unwanted or dangerous packets, which can be transmitted without user knowledge due to misconfiguration or viruses.

Innovation Solution

Incorporating a firewall module within IP communication devices to filter and manage data packets, including the implementation of packet filtering technologies such as Broadcom's Content Aware and BroadShield technologies, to eliminate or modify harmful packets before they reach the network or computer systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If basic switching technology is used to bridge data packets between computer system and network, then device complexity is reduced and ease of operation is improved, but network security deteriorates and harmful factors increase due to blind forwarding of uninspected packets

Engineering Contradiction:
Improveease of operationVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a firewall module as an intermediary component between the basic switching technology and the network interface. This firewall module inspects data packets before forwarding them to the network, acting as a mediator that filters harmful content while allowing legitimate traffic to pass through. The firewall module examines packet headers, identifies malicious patterns, and blocks dangerous packets without preventing normal communication operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If basic switching technology is used to bridge data packets, then device complexity is reduced, but object-generated harmful factors increase due to transmission of unwanted packets from computers

Engineering Contradiction:
Improvedevice complexityVSAvoidharmful factors
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The patent implements preliminary inspection and filtering of data packets before they are forwarded to the network. The firewall module performs packet examination, identifies harmful content, and blocks malicious packets in advance of their transmission. This preliminary action prevents unwanted and dangerous packets from reaching the network, stopping potential threats before they can cause harm to other network devices.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If packet filtering is implemented in IP phones, then network security is improved and harmful factors are reduced, but device complexity increases and ease of operation deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent integrates the firewall module within the existing IP phone device, making the IP phone perform multiple functions: voice communication, data bridging, and packet filtering. By combining these functions in a single device, the patent avoids adding separate dedicated firewall hardware, thereby limiting the increase in overall system complexity while still providing comprehensive security functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8769665B2IP communication device as firewall between network and computer system
Publication Date: 2014.07.01 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8769665B2 patent drawing
  • US8769665B2 patent drawing
  • US8769665B2 patent drawing

AI summary

Methods, systems, and apparatuses are described for implementations of an Internet protocol (IP) communication device (e.g., an IP phone) that contains a firewall. The IP communication device is coupled between a computer system and a network. A data packet is received at a first port of the IP communication device. The data packet is filtered with the firewall included in the IP communication device. The filtered data packet may be transmitted from a second port of the IP communication device (in modified or unmodified form), or may be canceled based on the filtering. In one implementation, the first port is coupled to the network and the second port is coupled to the computer system. In another implementation, the first port is coupled to the computer system and the second port is coupled to the network.