Proxy Servers for Secure Interdomain VoIP Traversal
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IP telephony systems face challenges in interdomain communication due to network address translation (NAT) and firewall constraints, leading to isolated 'IP islands' that hinder seamless communication across different domains, and security concerns impede widespread deployment.
Innovation Solution
A method and system for providing packetized voice call processing that includes determining a network address for communication between endpoints across different domains, establishing a media path, and securing the session using cryptographic protocols, employing STUN and TURN servers, and proxy servers to traverse NAT and firewalls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network address translation (NAT) and firewall constraints are applied to protect security, then security is improved, but interdomain communication capability deteriorates
Solution Approach 1:
The patent introduces intermediary components including a NAT traversal server, proxy servers, and signaling servers that mediate between endpoints in different domains. These intermediaries enable communication by relaying signaling and media traffic through the NAT/firewall boundaries without compromising the security of the internal networks.
Solution Approach 2:
The patent segments the communication system into distinct functional components: endpoint devices, NAT traversal servers, proxy servers, and signaling servers. Each segment operates independently with specific functions, allowing the system to maintain security boundaries while enabling interdomain communication through coordinated interaction between segments.
2Reliability
If encrypted sessions are established through proxy servers, then security is improved, but system complexity increases
Solution Approach 1:
Proxy servers act as intermediaries that handle encrypted session establishment and management. They perform cryptographic operations, certificate verification, and session key management, thereby protecting endpoint devices from the complexity of direct encrypted communication while maintaining strong security.
Solution Approach 2:
The patent replaces manual configuration and management of encrypted sessions with automated cryptographic protocols and procedures. The system automatically establishes TLS/SSL connections, manages certificates, and handles key exchange without requiring manual intervention, thereby reducing operational complexity while maintaining security.
3Adaptability or versatility
If STUN and TURN servers are deployed to traverse NAT and firewalls, then communication capability is improved, but device complexity and deployment difficulty increase
Solution Approach 1:
The patent combines STUN and TURN server functionalities into a unified NAT traversal infrastructure that serves multiple purposes: discovering public IP addresses, determining NAT types, establishing direct peer-to-peer connections when possible, and providing relay services when direct connections fail. This multi-functional approach reduces the need for separate specialized components.
Solution Approach 2:
The STUN servers enable endpoints to self-discover their public addresses and NAT characteristics without requiring manual configuration. The system automatically performs address discovery, NAT type detection, and connection establishment attempts, reducing deployment complexity and enabling automatic adaptation to different network environments.
Data Source
AI summary
An approach provides interdomain traversal to support packetized voice transmissions. A request is received and specifies a directory number for establishing a communication session from a first endpoint to a second endpoint. The first endpoint is behind a first network address translator of a first domain, and the second endpoint is within a second domain. A service provider network is accessed to determine a network address for communicating with the second endpoint based on the directory number, to determine existence of a second network address translator within the second domain, and to establish, if the network address can be determined, a media path between the first endpoint and the second endpoint based on the network address to support the communication session. An encrypted session is established with a proxy server according to a cryptographic protocol to support the media path. The proxy server resides within the second domain.


