SIP Firewall Path Maintenance via Hash Identifier Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Session Initiated Protocol (SIP) communication networks, in-path security devices like SIP firewalls are excluded from the signaling path after session initiation, posing a challenge for maintaining network security and ensuring that these devices remain engaged throughout the communication session.

Innovation Solution

A method and apparatus that modify SIP signaling messages by generating and storing hash identifiers for network devices, ensuring they remain in the signaling path by mapping these identifiers to endpoint addresses, allowing subsequent messages to flow through designated security devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If SIP signaling flows directly between endpoints after session initiation, then communication efficiency is improved, but in-path security devices are excluded from the signaling path

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidnetwork security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism by modifying the Contact field in SIP messages to include a hash identifier that represents the in-path security device. This allows the security device to remain in the signaling path indirectly, where the hash identifier acts as a mediator that enables the security device to intercept and inspect signaling messages without breaking the direct endpoint-to-endpoint communication flow.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If in-path security devices remain in the signaling path throughout the session, then network security is improved, but signaling message complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsignaling message complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the parameter representation in the Contact field from a direct endpoint address to a hash identifier. This parameter transformation allows the signaling messages to maintain a standardized format while enabling security devices to track and control the signaling path. The hash identifier serves as a compact representation that reduces the complexity burden compared to maintaining multiple address fields.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If hash identifiers are generated and mapped to endpoint addresses, then in-path device engagement is improved, but processing overhead increases

Engineering Contradiction:
Improvein-path device engagementVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by generating and storing the hash identifier mapping during the initial registration phase, before actual communication occurs. The mapping between endpoint addresses and hash identifiers is established in advance and cached, so that during the communication session, security devices can quickly look up the hash identifier without performing complex real-time calculations, significantly reducing processing overhead during active sessions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9749296B1Method and apparatus for modifying address information in signaling messages to ensure in-path devices remain in signaling path between endpoints
Publication Date: 2017.08.29 PULSELINK SYSTEMS LLC
  • US9749296B1 patent drawing
  • US9749296B1 patent drawing
  • US9749296B1 patent drawing

AI summary

Contact information in SIP signaling messages is modified at each in-path network device during the signaling process (along with storage of mapping information) to allow the in-path network devices (and proxy server) to identify the next (or previous) hop device in the path, and thus, maintain the path taken by signaling messages early on during the signaling process. Subsequent request and response signaling messages transmitted during the session follow this path, which ensures that the in-path network devices remain in the SIP signaling path.