Proxy Server Interdomain Voice Traversal via STUN and TURN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IP telephony systems face challenges in interdomain communication due to firewall and NAT constraints, leading to isolated 'IP islands' and security vulnerabilities, hindering widespread deployment and compatibility among service providers.
Innovation Solution
A network-based method for packetized voice call processing that involves proxy servers to convert directory numbers to network addresses, authenticate endpoints, and relay media streams across domains, using ENUM, STUN, and TURN protocols to traverse firewalls and NATs, ensuring secure and compatible IP telephony services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If enterprises implement IP telephony systems to create closed communities, then security is improved and internal communication is facilitated, but interdomain communication capability deteriorates and IP islands become isolated
Solution Approach 1:
The patent introduces border elements (border gateways, border servers) as intermediaries between isolated IP domains. These border elements enable secure interdomain communication by acting as controlled access points that mediate signaling and media traffic between domains while maintaining internal security boundaries. The border gateway specifically serves as an intermediary device that facilitates traversal of firewall and NAT barriers without compromising domain security.
Solution Approach 2:
The patent segments the communication system into distinct functional components: internal domain elements, border elements, and external network elements. This segmentation allows each component to perform specialized functions - internal elements maintain security policies, border elements handle interdomain traversal, and external elements provide network services. The segmentation enables independent optimization of security and interoperability concerns.
2Reliability
If firewall and NAT are deployed to protect IP telephony networks, then security is improved, but media stream transmission capability deteriorates due to traversal barriers
Solution Approach 1:
The patent implements preliminary actions by having endpoints perform authentication and obtain traversal assistance information before initiating media stream transmission. The border gateway pre-establishes traversal parameters and credentials, and the authentication server pre-validators endpoint identities. This preliminary setup enables seamless media transmission through firewall and NAT barriers without real-time intervention.
Solution Approach 2:
The border gateway serves as an intermediary that assists endpoints in traversing firewall and NAT barriers. It provides traversal assistance information including alternative communication paths, port mappings, and relay server locations. The border element mediates between the secure internal network and the external network, enabling media streams to pass through barriers without compromising security.
3Adaptability or versatility
If diverse addressing schemes are used in IP telephony devices, then device flexibility is improved, but compatibility and reachability deteriorate across different domains
Solution Approach 1:
The patent implements a universal addressing and identification mechanism that works across diverse IP telephony devices and domains. The border gateway and authentication server recognize and translate various addressing schemes (E.164 numbers, SIP URIs, other identifiers) into a unified format for routing and identification. This universal approach maintains device flexibility while ensuring cross-domain compatibility and reachability.
Data Source
AI summary
An approach provides interdomain traversal to support packetized voice transmissions. A signaling message is received for establishing a voice call from a first endpoint associated with a first domain to a second endpoint associated with a second domain. The first endpoint queries a STUN (Simple Traversal of UDP (User Datagram Protocol)) server to determine information relating to a firewall and network address translator that the first endpoint is behind, and to log into a TURN (Traversal Using Relay NAT (Network Address Translation)) server configured to establish a media path between the first endpoint and the second endpoint. A first proxy server serving the first endpoint communicates with an ENUM (Electronic Number) server to convert a directory number corresponding to the second endpoint to a network address. The first proxy server communicates with a second proxy server serving the second endpoint to establish the voice call. The STUN server, the TURN server and the ENUM server are maintained by service provider. The first endpoint is authenticated to permit exchange of a media stream over the media path. The media stream is relayed, if the first endpoint is successfully authenticated.


