Trusted Node Media Stream Convergence for Firewall Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems face significant time delays and increased costs due to the need for multiplexing and de-multiplexing of video streams in video communication, especially when using firewalls with multiple ports for isolation between internal and external networks, which compromises security and real-time demands.

Innovation Solution

A network security system that includes a firewall with a trusted node between the internal and external networks, using a media-stream receiving port to converge data, thereby eliminating the need for multiplexing and de-multiplexing, reducing time delays, and enhancing security by only allowing communication through the trusted node, thus minimizing port openings and system complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network proxies are introduced to multiplex and de-multiplex video streams, then network security is improved, but time delay increases

Engineering Contradiction:
Improvenetwork securityVSAvoidtime delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the network proxy function from the data path, placing it only in the signaling path. The trusted node handles stream convergence without multiplexing/de-multiplexing operations, eliminating the time delay associated with these operations while maintaining security through the firewall and proxy architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted node as an intermediary between the internal network and external network. This trusted node converges multiple media streams into a single stream without requiring multiplexing/de-multiplexing, thereby maintaining security while reducing time delay compared to the prior art using network proxies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple network proxies are introduced for stream multiplexing, then security is improved, but system cost increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the need for multiple network proxies by extracting the multiplexing function and replacing it with a trusted node that performs stream convergence. This reduces system complexity and cost while maintaining security through the firewall and single trusted node architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges multiple media streams into a single converged stream at the trusted node, eliminating the need for separate network proxies for each stream. This consolidation reduces the number of components required, thereby reducing system cost and complexity while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple ports are opened on firewall for video communication, then communication capability is improved, but security isolation is degraded

Engineering Contradiction:
Improvecommunication capabilityVSAvoidsecurity isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent makes the trusted node a universal convergence point for all video streams, allowing multiple communication capabilities to be achieved through a single port on the firewall. This maintains security isolation by limiting firewall port openings while enabling versatile video communication through the trusted node's stream convergence capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8032934B2Network security system and the method thereof
Publication Date: 2011.10.04 HUAWEI TECH CO LTD
  • US8032934B2 patent drawing
  • US8032934B2 patent drawing
  • US8032934B2 patent drawing

AI summary

The present invention discloses a network security system including a firewall arranged between the internal network and the external network, and a trusted node arranged between the firewall and the external network, which is used to provide a data channel between the internal network and the external network, and forward the data transported between the internal network and the external network; the firewall includes a first port configured at the internal network oriented side of the firewall and a second port configured at the external network oriented side of the firewall; and the trusted node includes a media-stream receiving port used to converge the data from the second port. The present invention also discloses a network security method.