VoIP Call Routing Across Multiple Security Zones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional firewalls and network address translators (NATs) struggle to facilitate successful VoIP sessions across multiple security zones due to the dynamic and unpredictable nature of addressing information within VoIP packet payloads, leading to denied media passage and failed connections.

Innovation Solution

Implementing an advanced firewall with application-level gateway (ALG) logic that dynamically identifies and modifies VoIP messages to create pinholes across multiple security zones, enabling traffic flow between VoIP parties by translating both header and payload information, and managing VoIP traffic between TRUST, UNTRUST, and DMZ zones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional firewalls and NATs are used to protect network security, then security is improved, but VoIP media passage is blocked and connections fail

Engineering Contradiction:
Improvenetwork securityVSAvoidVoIP connection success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an Application Level Gateway (ALG) as an intermediary component between the firewall/NAT and VoIP traffic. The ALG inspects VoIP packets at the application layer, understands the protocol semantics, and dynamically modifies packet contents (especially in payload sections) to create appropriate pinholes in the firewall while maintaining security policies. This mediator resolves the contradiction by enabling VoIP traffic to pass through security boundaries without compromising network security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent dynamically changes firewall parameters (pinhole configurations) based on VoIP session requirements. The ALG monitors VoIP call states and adjusts firewall rules in real-time, opening pinholes only when needed and closing them when sessions end. This dynamic parameter adjustment allows the system to maintain high security while permitting legitimate VoIP traffic, resolving the contradiction between security and connectivity.

Inventive Principle:
Principle #35Parameter changes

2Stability of the object's composition

If addressing information in VoIP packet payloads is not translated, then packet integrity is maintained, but firewall pinholes cannot be created and media flow is blocked

Engineering Contradiction:
Improvepacket integrityVSAvoidfirewall pinhole creation
Core Design Contradiction:
Stability of the object's compositionVSEase of operation

Solution Approach 1:

The ALG acts as an intermediary that sits between the raw VoIP packets and the firewall mechanism. It extracts addressing information from packet payloads, uses this information to create pinholes, and then allows the original packets to pass through unchanged. This approach maintains packet integrity while enabling firewall operation, as the ALG translates payload addressing info into firewall-compliant pinhole specifications without modifying the actual VoIP packets.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary translation of addressing information in packet payloads before the packets reach the firewall. The ALG pre-processes VoIP packets to extract and translate addressing data into pinhole configurations, so that when packets arrive at the firewall, the necessary pinholes are already in place. This preliminary action resolves the contradiction by preparing the firewall rules in advance based on payload information, enabling both packet integrity and pinhole creation.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple security zones are implemented, then network security is enhanced, but VoIP traffic routing becomes complex and difficult to manage

Engineering Contradiction:
Improvenetwork securityVSAvoidVoIP traffic routing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where the ALG continuously monitors VoIP session states across multiple security zones and dynamically adjusts routing decisions. The system receives feedback about call setup progress, media flow requirements, and session termination events, using this information to automatically manage pinhole creation and deletion across zone boundaries. This feedback-driven approach simplifies multi-zone routing complexity by automating decision-making based on real-time session information.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The ALG is designed as a universal component that can handle VoIP traffic routing across any number of security zones with a single unified architecture. Rather than requiring separate routing logic for each zone combination, the ALG provides multi-functional capability to inspect, translate, and forward VoIP packets through arbitrary zone configurations. This universal approach reduces overall system complexity despite the presence of multiple security zones.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8200827B1Routing VoIP calls through multiple security zones
Publication Date: 2012.06.12 JUNIPER NETWORKS INC
  • US8200827B1 patent drawing
  • US8200827B1 patent drawing
  • US8200827B1 patent drawing

AI summary

Call setup signaling is performed across at least a first security zone, a second security zone, and a third security zone to set up a call. At least one gate is then established between the first security zone and the third security zone to enable traffic flow for the call between the first security zone and the third security zone.