Trusted Routing Point Firewall Traversal Using Cryptographic Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Firewalls in computer networks face challenges in authenticating and authorizing media flows across different source and destination addresses, leading to performance issues and latency when using Trusted Routing Points (TRPs) for firewall traversal, especially under high network traffic conditions.
Innovation Solution
The use of a signaling message with a first indicator and a second indicator, along with a cryptographic acceptance token (CAT) generated using a one-way hash function, allows firewalls to authenticate and authorize media flows even when source addresses differ, eliminating the need for TRPs to terminate and re-originate media flows, thereby reducing latency and performance bottlenecks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TRPs terminate and re-originate media flows to authenticate firewall traversal, then firewall security is maintained, but latency increases and performance degrades under high network traffic
Solution Approach 1:
The patent applies preliminary action by pre-generating cryptographic acceptance tokens (CATs) that contain authentication credentials before media flows need to traverse the firewall. These tokens are embedded in signaling messages ahead of time, allowing firewalls to authenticate flows without requiring TRPs to terminate and re-originate them, thus maintaining security while reducing latency.
Solution Approach 2:
The patent introduces cryptographic acceptance tokens as an intermediary mechanism that carries authentication information through the firewall without requiring TRP intervention. The tokens act as mediators between the signaling system and firewall authentication, enabling seamless traversal while maintaining security credentials.
2Reliability
If TRPs terminate and re-originate media flows for authentication, then firewall traversal is authorized, but device complexity and processing overhead increase
Solution Approach 1:
The patent extracts the authentication functionality from the TRP termination process by embedding cryptographic acceptance tokens directly in signaling messages. This separates the authentication credential generation from the media flow termination, allowing firewalls to verify tokens independently without requiring complex TRP mediation for each flow.
Solution Approach 2:
The patent uses cryptographic acceptance tokens as copies of authentication credentials that can be verified by firewalls without requiring the original TRP to be involved in the media flow path. The tokens contain sufficient authentication information to be validated independently, reducing processing overhead at TRPs.
3Reliability
If firewalls require strict source address matching for authentication, then security is maintained, but adaptability to NAT and address translation scenarios is reduced
Solution Approach 1:
The patent changes the authentication parameter from strict source address matching to cryptographic token verification. The cryptographic acceptance tokens contain authentication credentials that are independent of IP address matching, allowing firewalls to authenticate flows even when source addresses have been translated by NAT devices, thus maintaining security while improving adaptability.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution enables secure and efficient traversal of firewalls for real-time media flows by authenticating tokens without requiring TRPs to split media flows, thus reducing latency and performance issues, even under high network traffic.
Implementation Method 1
a cryptographic acceptance token (CAT) generated using a one-way hash function
Data Source
AI summary
A Trusted Routing Point (TROP) generates a signaling message that includes an authorization token used to authorize a firewall to open a pinhole. The signaling message contains a first indicator that indicates whether a data field in the signaling message represents a source address of a media flow. The signaling message also includes a second indicator that indicates whether the firewall should derive the source address of the media flow from the data field. The authorization token is generated using a one-way hash function over information that may be included in the signaling message, including the first indicator and the second indicator.


