Phone Proxy for NAT VoIP Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional phone proxies and call managers are limited in supporting multiple devices behind a remote Network Address Translation (NAT) router, failing to operate as transparent proxies and securely authenticate Voice over Internet Protocol (VoIP) phones, which hinders secure communication and device authentication.

Innovation Solution

An Adaptive Security Appliance (ASA) phone proxy is implemented, acting as a transparent proxy for TFTP and signaling transactions, providing security credential information to IP phones behind a NAT device, building a database of secure phones, and intercepting and rewriting packets to facilitate secure communication between IP phones and call managers, while managing timeouts and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If conventional phone proxies are used, then device authentication is simplified, but multiple devices behind NAT cannot be supported

Engineering Contradiction:
Improvesupport for multiple devices behind NATVSAvoidproxy system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a phone proxy as an intermediary component between IP phones behind NAT and the call manager. This proxy maintains a database of authorized phones and intercepts/rewrites packets to enable multiple devices to be authenticated and supported behind a single NAT device, resolving the contradiction between supporting multiple devices and maintaining system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If transparent proxy operation is not implemented, then security credential distribution is simpler, but connections from phones to call managers cannot be observed

Engineering Contradiction:
Improveconnection visibility and securityVSAvoidproxy operation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The phone proxy operates as a transparent intermediary that intercepts TFTP and signaling transactions between IP phones and the call manager. By rewriting packets and maintaining connection state information, it enables security credential distribution while ensuring visibility of all phone connections to the call manager, resolving the contradiction between connection visibility and operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication is not enforced, then device access is easier, but secure communication cannot be ensured

Engineering Contradiction:
Improvesecure communicationVSAvoiddevice access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The phone proxy performs preliminary authentication by maintaining a database of authorized IP phones and their credentials before allowing communication with the call manager. It intercepts authentication requests, verifies credentials against the database, and only permits authenticated devices to establish secure communication channels, resolving the contradiction between secure communication and ease of access.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8752161B1Securing and authenticating multiple devices behind a NAT device
Publication Date: 2014.06.10 CISCO TECHNOLOGY INC
  • US8752161B1 patent drawing
  • US8752161B1 patent drawing
  • US8752161B1 patent drawing

AI summary

Apparatus, methods, and other embodiments associated with securing and authenticating multiple devices behind a network address translation (NAT) device are described. One example method includes controlling a phone proxy to provide security credential information to an Internet Protocol (IP) phone located behind the NAT device. The credentials may be selectively provided in response to receiving a certificate request from the IP phone. The certificate request includes IP phone identifying addresses. The method may also include controlling the phone proxy to update an entry in a secure IP phone data store to relate together the IP phone identifying addresses, a source port associated with the IP phone, and the fact that credential information was provided to the IP phone. This entry can mark the IP phone as an authorized phone. The entry may be addressable as a function of a least a portion of the IP phone identifying addresses.