Intercepting File Transfers in Multi-Node SIP Topologies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Session Initiation Protocol (SIP) systems lack the capability to effectively intercept and process payloads between clients for malware scanning and data filtering, especially in scenarios where intermediate servers need to perform actions similar to those of a home server, such as scanning and forwarding data.

Innovation Solution

The system employs a mechanism where intermediate servers can be designated as intercepting servers, receiving session setup messages, establishing connections with clients, downloading and processing payloads, and forwarding them, which includes content inspection and filtering based on various factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If intermediate servers are designated as intercepting servers to scan and process payloads, then security and data filtering capabilities are improved, but server complexity and processing overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidserver complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the payload processing function by designating specific intermediate servers as intercepting servers rather than requiring all servers to perform full processing. This segmentation allows security functions to be distributed to specific nodes, reducing overall system complexity while maintaining security coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the home server selects and notifies intercepting servers of their role. This intermediary selection process simplifies the system by centralizing the decision-making logic in the home server while distributing the actual processing workload to designated intercepting servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If payloads are downloaded and processed by intercepting servers for content inspection, then data filtering capability is improved, but processing time and latency increase

Engineering Contradiction:
Improvedata filtering capabilityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by having intercepting servers inspect and filter payloads before they reach the final destination. This preliminary processing prevents malicious content from propagating through the network, reducing overall processing time by eliminating unnecessary traffic later in the transmission path.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent maintains continuity of useful action by ensuring that intercepting servers process payloads as they traverse the network path. This continuous processing approach avoids interruptions and ensures that security inspection occurs at every relevant stage without delaying the overall transmission.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If multiple intermediate servers are involved in the communication path, then network reliability is improved, but the difficulty of managing and selecting intercepting servers increases

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidserver selection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling any intermediate server to be designated as an intercepting server based on policy decisions. This multi-functional approach allows the same server infrastructure to handle both routing and security inspection functions, simplifying management while maintaining network reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback mechanisms where the home server receives identifying information from intermediate servers and uses this feedback to make informed selections about which servers should perform intercepting functions. This feedback loop simplifies management by allowing dynamic, policy-based selection based on server capabilities and network conditions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9912735B2Intercepting file transfers in multi-node topologies
Publication Date: 2018.03.06 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9912735B2 patent drawing
  • US9912735B2 patent drawing
  • US9912735B2 patent drawing

AI summary

A system and method for intercepting and processing a payload sent between clients. A home server determines the roles that are intermediate to the clients by having intermediate servers insert identity information into a message of a session setup protocol. The home server selects a role to be the intercepting role, and sends a notification and aggregate information to a server of the selected role. A server of the intercepting role intercepts and processes the payload when it is sent between the clients. Payload processing may include content inspection or filtering based on any of a number of factors.