IP Library Granted Patent US 7,372,840
Granted Patent B2
US 7,372,840 · App. 10/822,874 · Granted May 13, 2008

Filtering of dynamic flows

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,372,840
App. No.
10/822,874
Granted
May 13, 2008
Kind
B2
Abstract

Methods and correspondent nodes to filter IP communications through firewalls in scenarios where dynamic pinholes are created to ensure an appropriate level of security is disclosed. The invention is based on creating a secure and authorized anchor for communications where all the communications are routed through before a firewall performs the packet filtering. A Translator Gateway (TrGW) switches addresses in the header according to a stored Mapping Table and an interface between a CPS (or a SIP proxy) and the TrGW. This interface allows the CPS to request the TrGW to provide bindings data between IP addresses upon session initiation, the TrGW to provide the bindings data to the CPS and the CPS to release the bindings at session release. The firewall accepts incoming packets whose IP address belongs to the pool of addresses of the TrGW. Thus any incoming packet that does not correspond to an existing call will be dropped at the TrGW, and a valid packet will go through the firewall which will verify that the packet is not a malformed message or other attack.

Claims (77)

1. A method, comprising:

configuring an anchor node in a communication network, wherein the configuring comprises:

first requesting to initiate a communication session for a first terminal via a communication management node of said communication network,

first establishing, at an anchor node, a binding for the first terminal upon request by said communication management node,

forwarding said first requesting to initiate from said communication management node based on the established binding towards a second terminal,

acknowledging said first requesting to initiate by said second terminal to said communication management node, and

second establishing, at said anchor node, a binding for the second terminal upon request by said communication management node; and

communicating data in the communication session between the first terminal and the second terminal, wherein the communicating comprises:

transmitting the data to be communicated from the first terminal to the anchor node, the anchor node configured to store a table of respective bindings for the terminals, and

relaying the data to be communicated from the anchor node towards a filtering node of said network using the configured bindings for the terminals, wherein the said filtering node filters said data to be communicated based on the bindings for said terminals.

2. A method according to claim 1 , wherein said requesting to initiate comprises:

indicating to said communication management node, at least the addresses of the terminals to be involved in the communication session.

3. A method according to claim 2 , wherein said indicating further comprises:

informing a port number for said communication session of said first terminal.

4. A method according to claim 1 , wherein each of said first and second establishings of the bindings comprise:

associating an alias to said respective terminal.

5. A method according to claim 4 , wherein each of said first and second establishings of the bindings further comprise:

storing the associated alias for the respective terminal at said anchor node.

6. A method according to claim 1 , wherein said acknowledging further comprises:

informing a port number for said communication session of said second terminal.

7. A method according to claim 1 , further comprising:

notifying said first terminal of the initiation of the session using the binding for said second terminal.

8. A method according to claim 1 , further comprising:

second requesting to terminate the communication session for the first terminal via the communication management node of said communication network,

forwarding said second requesting to terminate from said communication management node based on the established binding towards the second terminal,

acknowledging said second requesting to terminate by said second terminal to said communication management node,

first releasing, at the anchor node, the binding for the first terminal upon request by said communication management node, and

second releasing, at said anchor node, the binding for the second terminal upon request by said communication management node.

9. A method according to claim 8 , wherein each of said first and second releasings:

deleting the associated alias for the respective terminal at said anchor node.

10. A method according to claim 1 , wherein said filtering further comprises:

passing said data to be communicated through said filtering node onwards to the second terminal based on the binding, if such binding exists among the configured bindings.

11. A method according to claim 1 , wherein said filtering further comprises:

blocking said data from being communicated through said filtering node to the second terminal based on the binding, if such binding does not exist among the configured bindings.

12. An apparatus, comprising:

a receiver configured to receive a first binding request for establishing a first binding for a first terminal requesting a communication session initiation from a communication management node, and

configured to receive a second binding request for establishing a second binding for a second terminal to be involved in the communication session from the communication management node;

a processor configured to establish the first binding for said first terminal in response to said received binding request and returning said binding to said communication management node and configured to establish the second binding for the second terminal upon request by said communication management node; and

a memory configured to store a table of respective configured bindings for the terminals,

wherein the receiver is further configured to receive data to be communicated from the first terminal to the second terminal, and

wherein the processor is further configured to relay the data to be communicated towards a filtering node of said network using the configured bindings for the terminals.

13. An apparatus according to claim 12 , wherein

said processor comprises an allocating device configured to associate an alias to said respective terminal when establishing the binding.

14. An apparatus according to claim 13 , further comprising;

a second memory configured to store the associated alias for the respective terminal.

15. A method according to claim 1 , wherein said relaying comprises performing an address translation based on the configured bindings.

16. An apparatus according to claim 12 , wherein said processor comprises an address translator configured to perform an address translation based on the configured bindings.

17. A system comprising:

first requesting circuitry configured to first request to initiate a communication session for a first terminal via a communication management node of a communication network;

first establishing circuitry configured to first establish, at an anchor node, a binding for the first terminal upon request by said communication management node;

forwarding circuitry configured to forward said first requesting to initiate from said communication management node based on the established binding towards a second terminal;

first acknowledging circuitry configured to acknowledge said first requesting to initiate by said second terminal to said communication management node;

second establishing circuitry configured to second establish, at said anchor node, a binding for the second terminal upon request by said communication management node;

a transmitter configured to transmit the data to be communicated from the first terminal to an anchor node, the anchor node configured to store a table of respective bindings for the terminals;

relaying circuitry configured to relay the data to be communicated from the anchor node towards a filtering node of said network using the configured bindings for the terminals; and

filtering circuitry configured to filter, at said filtering node, said data to be communicated based on the bindings for said terminals.

18. The system according to claim 17 , further comprising:

second requesting circuitry configured to second request to terminate the communication session for the first terminal via the communication management node of said communication network;

forwarding circuitry configured to forward said second requesting to terminate from said communication management node based on the established binding towards the second terminal;

second acknowledging circuitry configured to acknowledge said second requesting to terminate by said second terminal to said communication management node;

first releasing circuitry configured to first release, at the anchor node, the binding for the first terminal upon request by said communication management node; and

second releasing circuitry configured to second release, at said anchor node, the binding for the second terminal upon request by said communication management node.

19. A system, comprising:

first requesting means for first requesting to initiate a communication session for a first terminal via a communication management node of a communication network;

first establishing means for first establishing at an anchor node, a binding for the first terminal upon request by said communication management node;

forwarding means for forwarding said first requesting to initiate from said communication management node based on the established binding towards a second terminal;

acknowledging means for acknowledging said first requesting to initiate by said second terminal to said communication management node;

second establishing means for second establishing at said anchor node, a binding for the second terminal upon request by said communication management node;

transmitting means for transmitting the data to be communicated from the first terminal to an anchor node, the anchor node configured to store a table of respective bindings for the terminals;

relaying means for relaying the data to be communicated from the anchor node towards a filtering node of said network using the configured bindings for the terminals; and

filtering means for filtering, at said filtering node, said data to be communicated based on the bindings for said terminals.

20. The system according to claim 19 , further comprising:

second requesting means for second requesting to terminate the communication session for the first terminal via the communication management node of said communication network;

forwarding means for forwarding said second requesting to terminate from said communication management node based on the established binding towards the second terminal;

acknowledging means for acknowledging said second requesting to terminate by said second terminal to said communication management node;

first releasing means for first releasing, at the anchor node, the binding for the first terminal upon request by said communication management node; and

second releasing means, at said anchor node, the binding for the second terminal upon request by said communication management node.

Assignments (12)
PATENT SECURITY AGREEMENT Recorded Aug 6, 2024
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 068328/0674 →
RELEASE OF LIEN ON PATENTS Recorded Aug 5, 2024
From: BARINGS FINANCE LLC
To: RPX CORPORATION
Reel/Frame 068328/0278 →
PATENT SECURITY AGREEMENT Recorded Apr 22, 2023
From: RPX CORPORATION
To: BARINGS FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 063429/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 28, 2021
From: PROVENANCE ASSET GROUP LLC
To: RPX CORPORATION
Reel/Frame 059352/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: NOKIA US HOLDINGS INC.
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058363/0723 →
RELEASE OF SECURITY INTEREST Recorded Nov 30, 2021
From: CORTLAND CAPITAL MARKETS SERVICES LLC
To: PROVENANCE ASSET GROUP HOLDINGS LLC; PROVENANCE ASSET GROUP LLC
Reel/Frame 058983/0104 →
ASSIGNMENT AND ASSUMPTION AGREEMENT Recorded Feb 14, 2019
From: NOKIA USA INC.
To: NOKIA US HOLDINGS INC.
Reel/Frame 048370/0682 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2017
From: NOKIA TECHNOLOGIES OY; NOKIA SOLUTIONS AND NETWORKS BV; ALCATEL LUCENT SAS
To: PROVENANCE ASSET GROUP LLC
Reel/Frame 043877/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP LLC
To: NOKIA USA INC.
Reel/Frame 043879/0001 →
SECURITY INTEREST Recorded Sep 13, 2017
From: PROVENANCE ASSET GROUP HOLDINGS, LLC; PROVENANCE ASSET GROUP, LLC
To: CORTLAND CAPITAL MARKET SERVICES, LLC
Reel/Frame 043967/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 19, 2015
From: NOKIA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 035443/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2004
From: LE, FRANK; FACCIN, STEFANO
To: NOKIA CORPORATION
Reel/Frame 015218/0282 →