Hybrid Peer-to-Peer System Bypassing NAT via Centralized Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional peer-to-peer networks face security risks due to insecure endpoint information distribution and can become bottlenecks in client/server models, where all communications must pass through a central server, leading to performance issues.
Innovation Solution
A hybrid peer-to-peer system with an access server that uses standardized communication protocols like SIP and RTP, and endpoints equipped with softswitches for direct signaling and media traffic management, enabling secure and efficient communication without relying on external servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional peer-to-peer networks distribute endpoint information throughout the network on various endpoints, then direct communication between endpoints is enabled, but security risk increases due to insecure information distribution
Solution Approach 1:
The patent introduces a controller as an intermediary component that centralizes the storage and management of endpoint information (addresses and credentials). Instead of distributing this sensitive information across multiple insecure endpoints, the controller acts as a secure mediator that provides authentication and authorization services, thereby enabling direct peer-to-peer communication while maintaining centralized security control
Solution Approach 2:
The system segments the functionality by separating the control plane (handled by the controller) from the data plane (peer-to-peer communication). The controller handles only signaling and authentication functions, while actual media traffic flows directly between endpoints. This segmentation allows direct communication to occur without compromising security, as the sensitive endpoint information remains centralized in the controller rather than distributed across endpoints
2Reliability
If client/server networks localize credential storage on a server, then security is improved, but the server becomes a bottleneck for all communications
Solution Approach 1:
The patent applies segmentation by dividing the system into control functions (handled by the controller) and media transmission functions (handled directly by endpoints). The controller localizes credential storage and authentication operations, maintaining security, while media traffic bypasses the controller and flows directly between endpoints, eliminating the bottleneck effect and maintaining high communication efficiency
Solution Approach 2:
The patent extracts the media traffic flow from the server/controller, allowing it to proceed independently between endpoints without passing through the centralized authority. Only signaling and authentication traffic pass through the controller, which maintains security through centralized credential management. This extraction eliminates the bottleneck problem while preserving security benefits
Data Source
AI summary
An improved system and method are disclosed for peer-to-peer communications. In one example, the method enables an endpoint to use a tunneling server to bypass a network address translation (NAT) device that is blocking messages to an endpoint on the other side of the NAT device.


