Trusted Routing Point Firewall Traversal Using Cryptographic Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Firewalls in computer networks face challenges in authenticating and authorizing media flows across different source and destination addresses, leading to performance issues and latency when using Trusted Routing Points (TRPs) for firewall traversal, especially under high network traffic conditions.

Innovation Solution

The use of a signaling message with a first indicator and a second indicator, along with a cryptographic acceptance token (CAT) generated using a one-way hash function, allows firewalls to authenticate and authorize media flows even when source addresses differ, eliminating the need for TRPs to terminate and re-originate media flows, thereby reducing latency and performance bottlenecks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TRPs terminate and re-originate media flows to authenticate firewall traversal, then firewall security is maintained, but latency increases and performance degrades under high network traffic

Engineering Contradiction:
Improvefirewall securityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-generating cryptographic acceptance tokens (CATs) that contain authentication credentials before media flows need to traverse the firewall. These tokens are embedded in signaling messages ahead of time, allowing firewalls to authenticate flows without requiring TRPs to terminate and re-originate them, thus maintaining security while reducing latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces cryptographic acceptance tokens as an intermediary mechanism that carries authentication information through the firewall without requiring TRP intervention. The tokens act as mediators between the signaling system and firewall authentication, enabling seamless traversal while maintaining security credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If TRPs terminate and re-originate media flows for authentication, then firewall traversal is authorized, but device complexity and processing overhead increase

Engineering Contradiction:
ImproveauthorizationVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from the TRP termination process by embedding cryptographic acceptance tokens directly in signaling messages. This separates the authentication credential generation from the media flow termination, allowing firewalls to verify tokens independently without requiring complex TRP mediation for each flow.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses cryptographic acceptance tokens as copies of authentication credentials that can be verified by firewalls without requiring the original TRP to be involved in the media flow path. The tokens contain sufficient authentication information to be validated independently, reducing processing overhead at TRPs.

Inventive Principle:
Principle #26Copying

3Reliability

If firewalls require strict source address matching for authentication, then security is maintained, but adaptability to NAT and address translation scenarios is reduced

Engineering Contradiction:
Improveauthentication securityVSAvoidNAT compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent changes the authentication parameter from strict source address matching to cryptographic token verification. The cryptographic acceptance tokens contain authentication credentials that are independent of IP address matching, allowing firewalls to authenticate flows even when source addresses have been translated by NAT devices, thus maintaining security while improving adaptability.

Inventive Principle:
Principle #35Parameter changes

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enables secure and efficient traversal of firewalls for real-time media flows by authenticating tokens without requiring TRPs to split media flows, thus reducing latency and performance issues, even under high network traffic.

Implementation Method 1

a cryptographic acceptance token (CAT) generated using a one-way hash function

Methodology Applied
Scientific EffectOne-way hash function:

Data Source

PatentUS9094373B2Method and apparatus to scale authenticated firewall traversal using trusted routing point
Publication Date: 2015.07.28 CISCO TECHNOLOGY INC
  • US9094373B2 patent drawing
  • US9094373B2 patent drawing
  • US9094373B2 patent drawing

AI summary

A Trusted Routing Point (TROP) generates a signaling message that includes an authorization token used to authorize a firewall to open a pinhole. The signaling message contains a first indicator that indicates whether a data field in the signaling message represents a source address of a media flow. The signaling message also includes a second indicator that indicates whether the firewall should derive the source address of the media flow from the data field. The authorization token is generated using a one-way hash function over information that may be included in the signaling message, including the first indicator and the second indicator.