Trusted Node Media Stream Convergence for Firewall Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems face significant time delays and increased costs due to the need for multiplexing and de-multiplexing of video streams in video communication, especially when using firewalls with multiple ports for isolation between internal and external networks, which compromises security and real-time demands.
Innovation Solution
A network security system that includes a firewall with a trusted node between the internal and external networks, using a media-stream receiving port to converge data, thereby eliminating the need for multiplexing and de-multiplexing, reducing time delays, and enhancing security by only allowing communication through the trusted node, thus minimizing port openings and system complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network proxies are introduced to multiplex and de-multiplex video streams, then network security is improved, but time delay increases
Solution Approach 1:
The patent extracts the network proxy function from the data path, placing it only in the signaling path. The trusted node handles stream convergence without multiplexing/de-multiplexing operations, eliminating the time delay associated with these operations while maintaining security through the firewall and proxy architecture.
Solution Approach 2:
The patent introduces a trusted node as an intermediary between the internal network and external network. This trusted node converges multiple media streams into a single stream without requiring multiplexing/de-multiplexing, thereby maintaining security while reducing time delay compared to the prior art using network proxies.
2Reliability
If multiple network proxies are introduced for stream multiplexing, then security is improved, but system cost increases
Solution Approach 1:
The patent removes the need for multiple network proxies by extracting the multiplexing function and replacing it with a trusted node that performs stream convergence. This reduces system complexity and cost while maintaining security through the firewall and single trusted node architecture.
Solution Approach 2:
The patent merges multiple media streams into a single converged stream at the trusted node, eliminating the need for separate network proxies for each stream. This consolidation reduces the number of components required, thereby reducing system cost and complexity while maintaining security.
3Adaptability or versatility
If multiple ports are opened on firewall for video communication, then communication capability is improved, but security isolation is degraded
Solution Approach 1:
The patent makes the trusted node a universal convergence point for all video streams, allowing multiple communication capabilities to be achieved through a single port on the firewall. This maintains security isolation by limiting firewall port openings while enabling versatile video communication through the trusted node's stream convergence capability.
Data Source
AI summary
The present invention discloses a network security system including a firewall arranged between the internal network and the external network, and a trusted node arranged between the firewall and the external network, which is used to provide a data channel between the internal network and the external network, and forward the data transported between the internal network and the external network; the firewall includes a first port configured at the internal network oriented side of the firewall and a second port configured at the external network oriented side of the firewall; and the trusted node includes a media-stream receiving port used to converge the data from the second port. The present invention also discloses a network security method.


