Port Demultiplexing via Payload Protocol Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The scarcity and difficulty in obtaining and reserving port numbers for network communications, coupled with the need for frequent reconfiguration of firewall devices to allow new port numbers, limits the utilization of services in network environments.
Innovation Solution
A method and system that allow multiple protocols to share a single port number, enabling increased service utilization without requiring extensive port number allocation and reducing the need for firewall reconfiguration, by using a service selection module to demultiplex services over ports based on protocol identification within incoming network traffic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If multiple protocols use different port numbers, then protocol identification is straightforward, but port number scarcity and firewall reconfiguration burden increase
Solution Approach 1:
The patent combines multiple protocol services onto a single port number, allowing TCP/IP stack to handle demultiplexing based on payload inspection. This merging approach reduces the total number of port numbers needed while maintaining clear protocol identification through content-based routing.
Solution Approach 2:
The patent introduces an intermediary layer (TCP/IP stack or service selection module) that inspects packet payloads to determine protocol type. This intermediary enables protocol identification without relying on port numbers alone, resolving the contradiction between simple identification and port scarcity.
2Adaptability or versatility
If new port numbers are allocated for new services, then service differentiation is achieved, but firewall reconfiguration complexity increases
Solution Approach 1:
The patent makes the single port number universal for multiple protocols, allowing the firewall to maintain a static configuration while the TCP/IP stack handles protocol-specific routing. This multi-functionality approach eliminates the need for firewall reconfiguration when adding new services.
Solution Approach 2:
The system enables self-service by allowing the TCP/IP stack to automatically inspect payloads and route traffic appropriately without requiring manual firewall configuration. New services can be added without administrative intervention for firewall reconfiguration.
3Stability of the object's composition
If port numbers are reserved by IANA, then standardization is achieved, but acquisition cost and time increase
Solution Approach 1:
The patent copies the functionality of port number differentiation into payload inspection mechanisms. Instead of relying on IANA-allocated port numbers, the system copies the routing decision-making process into the TCP/IP stack, enabling immediate service deployment without time-consuming port allocation.
Solution Approach 2:
The patent changes the parameter used for service differentiation from port number (external parameter) to payload content (internal parameter). This parameter change eliminates dependency on IANA allocation processes while maintaining standardized protocol identification through content-based routing.
Data Source
AI summary
Methods, non-transitory machine readable media, and computing devices that facilitate demultiplexing services over ports are disclosed. With this technology, a request is received via a connection over one or more communication networks. The request includes payload data and a port number. At least a portion of the payload data is analyzed to determine one of a set of protocols associated with the port number. A service is then bound to the connection based on the determined one of the set of protocols. The service is configured to interpret the request. This technology advantageously allows the use of multiple protocols for a port number in a manner that is compatible with existing protocols and does not require any client-side code or coordination.


