Packet Telephony Transformer for Secure Network Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional packet protocol firewalls and H.323 gateways fail to provide reliable security for packet telephony exchanges, allowing potential malicious external entities to establish direct connections with internal networks, compromising security.
Innovation Solution
A packet telephony transformer (PTT) is introduced, which employs a stream transformer, protocol translator, and address transformer to insulate secure and non-secure networks by terminating incoming telephony streams at the network boundary, initiating separate secure streams, translating protocols, and assigning public aliases, thereby preventing direct access and maintaining network integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional packet protocol firewalls and H.323 gateways are used to allow packet telephony exchanges, then telephony communication between networks is enabled, but security is compromised allowing direct connections from malicious external entities to internal networks
Solution Approach 1:
The patent introduces a firewall proxy that acts as an intermediary between internal H.323 endpoints and external networks. The proxy terminates incoming telephony streams at the network boundary and initiates separate secure streams within the protected network, preventing direct connections while enabling telephony communication through controlled mediation.
Solution Approach 2:
The patent segments the telephony stream into two separate legs: an external leg that terminates at the firewall proxy and an internal leg that originates from the proxy. This segmentation isolates the internal network from direct external connections while maintaining telephony functionality through the proxy's stream transformation capability.
2Ease of operation
If direct IP connections are allowed for packet telephony, then telephony service accessibility is improved, but the possibility of malicious access to internal networks increases
Solution Approach 1:
The firewall proxy serves as a mediator that provides telephony service accessibility by accepting external calls and forwarding them internally, while simultaneously protecting network security by preventing direct IP connections. The proxy translates and transforms streams between external and internal networks, maintaining reliability through controlled access.
Solution Approach 2:
The patent creates a copy of the incoming telephony stream at the firewall proxy, terminating the external stream and initiating a separate internal stream. This copying mechanism allows telephony services to be accessible while the original external connection is blocked, preventing malicious access while maintaining service functionality.
3Productivity
If standard packet protocol firewalls are used to filter telephony traffic, then network traffic control is achieved, but telephony streams are refused as unsolicited
Solution Approach 1:
The firewall proxy acts as an intermediary that resolves the conflict between traffic control and stream acceptance. It terminates incoming telephony streams at the boundary and initiates new internal streams, allowing the firewall to maintain control over network traffic while enabling telephony communication through the proxy's stream transformation functionality.
Solution Approach 2:
The patent applies preliminary action by having the firewall proxy terminate and process incoming telephony streams before they reach the internal network. The proxy performs stream transformation and initiation in advance, converting external streams into internal streams that are already authorized and controlled, thereby enabling telephony acceptance while maintaining traffic control.
Data Source
AI summary
Described herein is a method and apparatus for connecting packet telephony calls between secure networks and non-secure networks.


