Media Port Access Control via Dynamic Token Bucket Feedback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mechanisms for controlling access to open media ports, such as VoIP gateways and UDP ports, are vulnerable to denial of service attacks and cannot adjust their operation in response to changes in data packet streams, leading to resource overload.

Innovation Solution

A packet token bucket system that uses feedback from the state of incoming data packets to adjust flow control parameters, incrementing and decrementing a counter to regulate data packet flow and reject malicious packets, while authenticating data packets to ensure valid sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traffic shaping mechanisms like leaky bucket or token bucket are used to control data packet flow rates, then resource overload is prevented, but the mechanisms cannot adjust their operation in response to changes in data packet streams

Engineering Contradiction:
Improveprotection from resource overloadVSAvoidability to adjust to observed conditions
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements feedback by monitoring the state of data packet streams (such as packet arrival rates, patterns, and characteristics) and using this information to dynamically adjust flow control parameters. The system observes incoming traffic conditions and modifies its behavior accordingly, allowing the flow control mechanism to adapt to changing network conditions while maintaining protection against resource overload.

Inventive Principle:
Principle #23Feedback

2Productivity

If open media ports accept all incoming packets to ensure legitimate traffic passes through, then authorized media streams are delivered, but rogue or malicious packets can consume common resources

Engineering Contradiction:
Improvedelivery of authorized media streamsVSAvoidimpact from rogue or malicious packets
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by implementing flow control and monitoring specific to each media port or channel. Instead of applying a uniform flow control policy across all ports, the system tailors flow control parameters and monitoring to the characteristics of individual ports and their associated media streams. This allows legitimate traffic on authorized ports to pass through while malicious packets on unauthorized ports are identified and blocked, protecting common resources from harmful factors.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8169901B1Method and apparatus for controlling access to a media port
Publication Date: 2012.05.01 AVAYA INC
  • US8169901B1 patent drawing
  • US8169901B1 patent drawing
  • US8169901B1 patent drawing

AI summary

The present invention is directed to protecting media packet processors from rogue or malicious data packet flows. According to the present invention, feedback obtained from components of a media packet processor having information regarding media stream flows is used to adjust a counter or token bucket controlling the admission of such flows. More specifically, feedback is used to adjust a counter value such that the count value is decremented, or the operation of the counter in incrementing the count value according to a periodic schedule is suppressed, if a dropped packet is detected. Accordingly, the present invention may utilize the predictable quality of media stream flows, and information from components such as jitter buffers and CODECs, in order to tailor bounds on the flow of ingress traffic to a media packet processor.