Distributed Policy Enforcement for WebRTC Session Description Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

WebRTC's secure nature poses challenges for enterprises in applying policies to real-time communications across network boundaries, as conventional network security elements cannot deeply analyze encrypted traffic, leading to potential security risks and policy compliance issues.

Innovation Solution

A distributed policy enforcement agent is implemented on the recipient device to receive and analyze WebRTC session description objects, determining and applying enterprise policies before establishing a session, allowing in-depth analysis and compliance with enterprise policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If WebRTC uses secure network connections and encrypted peer connections, then security and privacy are improved, but the ability to apply enterprise policies and analyze traffic is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidtraffic analysis capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent applies preliminary action by inserting a policy enforcement agent that intercepts and analyzes WebRTC session description objects (SDP) before the actual encrypted peer connection is established. The agent examines the SDP contents including media types, codecs, and candidate information to enforce enterprise policies on traffic direction, application identification, and security compliance before the secure channel becomes active, thus maintaining both encryption benefits and policy control.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If conventional network security elements examine protocols at various levels including content, then fine-grained policy control is improved, but they cannot analyze encrypted WebRTC traffic, worsening policy enforcement capability

Engineering Contradiction:
Improvepolicy controlVSAvoidencrypted traffic analysis
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary policy enforcement agent that positions itself between the WebRTC endpoints and the network. This agent intercepts the SDP exchange, performs deep content analysis of the encrypted session description objects, and enforces enterprise policies without requiring decryption of the actual media streams. The agent can identify applications, control traffic direction, and ensure compliance while the underlying WebRTC communications remain encrypted.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If WebRTC establishes direct peer connections, then communication efficiency is improved, but new attack paths for virus vectors and malware are created, worsening security risks

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action by having the policy enforcement agent analyze and validate WebRTC session description objects before allowing peer connections to be established. The agent checks for malicious content, validates security parameters, and can block or modify SDP objects that contain attack vectors or malware indicators. This pre-connection security check prevents harmful factors from entering the network through WebRTC while maintaining the efficiency of direct peer-to-peer communications for legitimate traffic.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9363133B2Distributed application of enterprise policies to Web Real-Time Communications (WebRTC) interactive sessions, and related methods, systems, and computer-readable media
Publication Date: 2016.06.07 AVAYA INC
  • US9363133B2 patent drawing
  • US9363133B2 patent drawing
  • US9363133B2 patent drawing

AI summary

Distributed application of enterprise policies to WebRTC interactive sessions, and related methods, systems, and computer-readable media are disclosed. In this regard, in one embodiment, a method for applying an enterprise policy to a WebRTC interactive session comprises receiving, by a distributed policy enforcement agent of a recipient device, a WebRTC session description object directed to the recipient device originating from a sender device via a secure network connection. The method further comprises determining, by the distributed policy enforcement agent, one or more enterprise policies based on the WebRTC session description object. The method additionally comprises applying the one or more enterprise policies to the WebRTC session description object. In this manner, an enterprise may permit establishment of a WebRTC interactive session that crosses an enterprise network boundary, while at the same time ensuring that the WebRTC interactive session complies with the one or more enterprise policies.