Multimedia Communication Control Unit for Secure H.323 to SIP Protocol Translation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for secure multimedia communication between LANs using H.323 protocol or similar protocols either compromise network security or require costly and complex firewall upgrades, or involve isolating audio/video communications on a separate network, which is inefficient and costly.
Innovation Solution
A multimedia communication control unit that filters and routes multimedia data streams only through supported protocols like H.323 or SIP, allowing secure multimedia communication between LANs and external devices without breaching firewall security, using a device with multiple input/output logical ports and a common interface to manage call management and media data streams.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If TCP/UDP ports are opened on the firewall to allow multimedia data streams to pass through, then multimedia communication capability is improved, but network security is worsened due to potential security breaches
Solution Approach 1:
A protocol translation gateway is introduced as an intermediary device between the H.323 multimedia network and the SIP network. The gateway translates H.323 protocols to SIP protocols, allowing multimedia data streams to pass through the firewall without opening direct ports between the two networks. This mediator enables communication while maintaining firewall security by keeping the translation function isolated in a controlled environment.
Solution Approach 2:
The system segments the network communication into distinct functional components: the H.323 endpoint, the protocol translation gateway, and the SIP network. By dividing the communication path into separate segments with clear protocol boundaries, the firewall only needs to handle SIP traffic from the gateway, reducing the security risk while maintaining multimedia communication capability through structured protocol separation.
2Productivity
If a separate dedicated LAN is created for audio/video communication without a firewall, then multimedia communication efficiency is improved, but network security and cost are worsened
Solution Approach 1:
The protocol translation gateway performs multiple functions: it acts as an H.323 endpoint, a SIP endpoint, and a protocol translator simultaneously. This multi-functional device enables multimedia communication across different networks and protocols without requiring separate dedicated networks, thereby maintaining network security while achieving efficient communication through a single versatile infrastructure.
3Adaptability or versatility
If a firewall compatible with H.323 protocol is implemented, then multimedia communication support is improved, but device complexity and cost are worsened
Solution Approach 1:
The protocol translation function is extracted from the firewall and placed in a separate dedicated gateway device. This allows the firewall to maintain its simple, secure architecture while the gateway handles the complex H.323 to SIP protocol translation. The firewall only needs to filter SIP traffic from the gateway, reducing its complexity and cost while still supporting multimedia communication through the external translation gateway.
Data Source
AI summary
A system and method for providing multimedia communication between a firewall protected, LAN based endpoint and an endpoint that is external to the LAN. A logical port of a multimedia communications control unit is attached to the LAN behind the firewall. Another logical port of the multimedia communications control unit is attached to the external endpoint. Multimedia communication data, consisting of call management data and media data, can be exchanged between the endpoints via the multimedia communications control unit. The multimedia communications control unit allows only multimedia communication data that strictly adheres to a particular communications protocol to pass through. Thus, the security afforded by the firewall is not compromised.


