Resource Distribution Node for Videoconference Firewall Simplification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale videoconference systems face challenges in configuring firewalls to secure external ports, which are susceptible to malicious data, especially when multiple bridges and servers are involved, leading to complexity and increased risk.

Innovation Solution

Implementing resource distribution nodes that act as intermediaries between users and conference servers, using a single external port to establish a virtual connection with operating nodes, thereby reducing the number of external ports required and simplifying firewall configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple external ports are used to connect users to operating nodes, then connection flexibility and user access capability are improved, but firewall configuration complexity and security risk increase

Engineering Contradiction:
Improveconnection flexibilityVSAvoidfirewall configuration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces resource distribution nodes as intermediary components between users and operating nodes. These nodes act as mediators that receive user connection requests through a single external port and distribute them to appropriate operating nodes internally. This intermediary layer maintains connection flexibility while reducing the number of external ports that require firewall configuration, thereby resolving the contradiction between adaptability and device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple external ports are configured on conference servers, then the number of concurrent connections and system capacity are improved, but the difficulty of detecting and measuring security threats increases

Engineering Contradiction:
Improvesystem capacityVSAvoidsecurity threat detection difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent merges multiple potential external port connections into a single external port by implementing resource distribution nodes that handle connection distribution internally. This consolidation maintains the system's capacity to handle multiple concurrent connections while simplifying the external interface to a single port, making security threat detection and monitoring significantly easier compared to managing multiple external ports.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If firewalls are configured to secure multiple external ports, then system security is improved, but the time and resources required for firewall management increase

Engineering Contradiction:
Improvesystem securityVSAvoidfirewall management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

By introducing resource distribution nodes as intermediaries, the system maintains security through a centralized single external port that requires firewall configuration. This intermediary architecture preserves system security while dramatically reducing firewall management time and resources, as administrators only need to manage one external port's security policies rather than configuring and maintaining security for multiple external ports.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9210200B1Methods, systems and program products for connecting users to operating nodes
Publication Date: 2015.12.08 IOCOM UK LTD
  • US9210200B1 patent drawing
  • US9210200B1 patent drawing
  • US9210200B1 patent drawing

AI summary

A videoconference server for use with a videoconference system in which a plurality of users communicate video and audio data to each other, including at least one server external port, at least one resource distribution node operating on the server and having at least first and second internal ports, the first internal port in communication with the server external port, at least one operating node including at least one internal port which is in communication with the resource distribution node second internal port, and wherein the resource distribution node is configured to receive a request from a user over the server external port, the request for establishing a connection with the operating node, wherein the resource distribution node is configured to pass the connection with the server external port to the operating node to thereby establish a virtual connection between the user and the operating node using the server external port for communication of videoconference related data.