Packet Telephony Transformer for Secure Network Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional packet protocol firewalls and H.323 gateways fail to provide reliable security for packet telephony exchanges, allowing potential malicious external entities to establish direct connections with internal networks, compromising security.

Innovation Solution

A packet telephony transformer (PTT) is introduced, which employs a stream transformer, protocol translator, and address transformer to insulate secure and non-secure networks by terminating incoming telephony streams at the network boundary, initiating separate secure streams, translating protocols, and assigning public aliases, thereby preventing direct access and maintaining network integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional packet protocol firewalls and H.323 gateways are used to allow packet telephony exchanges, then telephony communication between networks is enabled, but security is compromised allowing direct connections from malicious external entities to internal networks

Engineering Contradiction:
Improvetelephony communication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a firewall proxy that acts as an intermediary between internal H.323 endpoints and external networks. The proxy terminates incoming telephony streams at the network boundary and initiates separate secure streams within the protected network, preventing direct connections while enabling telephony communication through controlled mediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the telephony stream into two separate legs: an external leg that terminates at the firewall proxy and an internal leg that originates from the proxy. This segmentation isolates the internal network from direct external connections while maintaining telephony functionality through the proxy's stream transformation capability.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If direct IP connections are allowed for packet telephony, then telephony service accessibility is improved, but the possibility of malicious access to internal networks increases

Engineering Contradiction:
Improvetelephony service accessibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The firewall proxy serves as a mediator that provides telephony service accessibility by accepting external calls and forwarding them internally, while simultaneously protecting network security by preventing direct IP connections. The proxy translates and transforms streams between external and internal networks, maintaining reliability through controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the incoming telephony stream at the firewall proxy, terminating the external stream and initiating a separate internal stream. This copying mechanism allows telephony services to be accessible while the original external connection is blocked, preventing malicious access while maintaining service functionality.

Inventive Principle:
Principle #26Copying

3Productivity

If standard packet protocol firewalls are used to filter telephony traffic, then network traffic control is achieved, but telephony streams are refused as unsolicited

Engineering Contradiction:
Improvenetwork traffic control efficiencyVSAvoidtelephony stream acceptance
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The firewall proxy acts as an intermediary that resolves the conflict between traffic control and stream acceptance. It terminates incoming telephony streams at the boundary and initiates new internal streams, allowing the firewall to maintain control over network traffic while enabling telephony communication through the proxy's stream transformation functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by having the firewall proxy terminate and process incoming telephony streams before they reach the internal network. The proxy performs stream transformation and initiation in advance, converting external streams into internal streams that are already authorized and controlled, thereby enabling telephony acceptance while maintaining traffic control.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7668306B2Method and apparatus for connecting packet telephony calls between secure and non-secure networks
Publication Date: 2010.02.23 TAHOE RES LTD
  • US7668306B2 patent drawing
  • US7668306B2 patent drawing
  • US7668306B2 patent drawing

AI summary

Described herein is a method and apparatus for connecting packet telephony calls between secure networks and non-secure networks.