P2P Content Inspection via TURN Server Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In peer-to-peer streaming networks, malicious content can be inadvertently shared among peers without detection, posing a risk to network security as existing integrity verification schemes may fail to detect and block infected content.
Innovation Solution
A tracker in the P2P network routes unchecked content through a TURN server co-located with a firewall for inspection, ensuring that only content free of malicious code is served to other peers, and uses a publish-subscriber mechanism to block the advertisement of malicious content if detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If content is shared directly between peers in P2P network, then sharing speed and efficiency are improved, but network security deteriorates due to undetected malicious content
Solution Approach 1:
The patent introduces a TURN server as an intermediary component in the P2P network that relays content between peers. This mediator enables security inspection of content without completely breaking the P2P architecture, allowing the system to maintain sharing efficiency while adding security validation through the intermediary server.
Solution Approach 2:
The system performs preliminary security inspection of content before it is fully distributed to peers. By inspecting content upfront through the TURN server or firewall before peer-to-peer distribution, the system prevents malicious content from entering the network while maintaining efficient sharing of verified content.
2Reliability
If integrity verification schemes are used to detect malicious content, then network security is improved, but detection capability deteriorates because existing schemes fail to detect malicious content
Solution Approach 1:
The patent replaces traditional integrity verification mechanisms with a firewall-based security inspection system. This substitution introduces a more robust detection capability that can identify malicious content through firewall rules and security policies, overcoming the limitations of conventional verification schemes.
Solution Approach 2:
The TURN server acts as an intermediary that enables advanced security inspection capabilities. By routing content through this mediator, the system can implement sophisticated detection mechanisms including firewall inspection and security service integration that go beyond traditional verification methods.
3Reliability
If content is routed through TURN server for inspection, then network security is improved, but device complexity increases due to additional routing infrastructure
Solution Approach 1:
The TURN server is designed to serve multiple functions within the P2P network: it acts as both a relay for P2P communication and a security inspection point. This multi-functionality reduces the need for separate dedicated inspection infrastructure, thereby limiting the increase in overall system complexity while maintaining security capabilities.
Solution Approach 2:
The patent combines the TURN server with firewall capabilities and security inspection functions into a single integrated infrastructure. By merging these functions, the system avoids the complexity of maintaining separate inspection systems while still providing comprehensive security validation for P2P content sharing.
Data Source
AI summary
In one embodiment, A tracker computer receives from a first device in a peer-to-peer network that the first device has content for serving. A content request for the content is received from a second device in the peer-to-peer network. The tracker computer routes the content from the first device to the second device through a server. The content routed through the server is inspected for malicious code.


