IP Library Granted Patent US 7,594,259
Granted Patent B1
US 7,594,259 · App. 10/941,719 · Granted Sep 22, 2009

Method and system for enabling firewall traversal

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,594,259
App. No.
10/941,719
Granted
Sep 22, 2009
Kind
B1
Abstract

A method and system for enabling firewall traversal of media communications from a client device. The firewall infers authentication or validation of the client device based upon communications between the client device and a device controller known to the firewall. The firewall monitors packets sent from the device controller to the client device. If the device controller sends packets to the client device for a sufficiently long period of time and with sufficient frequency, or if the packets are of a certain type, then the firewall deems the client device to be validated and permits the client device to send data packets through the firewall. The device controller may include a media gateway controller, a port discovery server, or similar such device controllers. The device controller and client device communicate based upon a protocol, which need not be understood by the firewall.

Claims (29)

1. A method for establishing a trust relationship with a client device so as to enable future packet communications from the client device to a remote location through a firewall, the firewall being located between the client device and a device controller, the method comprising the steps of:

associating the client device with the device controller based upon a packet exchanged between the client device and the device controller;

monitoring communications from the device controller to the client device to determine whether the client device is authorized; and

creating a firewall rule allowing the transmission of data packets from the client device to the remote location if the client device is authorized, wherein the firewall rule permits the transmission of data packets based on the fact they are sent from the client device address, and wherein the data packets are addressed to the remote location and not the device controller.

2. The method claimed in claim 1 , wherein said step of associating includes storing the client device address in association with a device controller address based upon said packet.

3. The method claimed in claim 2 , wherein said device controller address includes IP address information corresponding to a signalling port for the known device controller.

4. The method claimed in claim 1 , wherein said step of monitoring includes determining whether a time interval between packets sent from the device controller to the client device exceeds a predetermined maximum and, if so, deeming the client device to be unauthorized.

5. The method claimed in claim 4 , wherein said step of monitoring further includes determining whether a duration of association between the client device and the device controller exceeds a predetermined minimum and, if so, holding the client device to be authorized.

6. The method claimed in claim 1 , wherein said step of monitoring includes identifying a session established between the client device and the device controller, and authorizing the client device based upon said session.

7. The method claimed in claim 1 , wherein said step of monitoring includes identifying a security relationship between the client device and the device controller, and authorizing the client device based upon said security relationship.

8. The method claimed in claim 1 , wherein said firewall rule includes a restriction on permissible destination IP address and/or port.

9. The method claimed in claim 1 , further including a step, following said step of allowing, of observing communications from the device controller to the client device to determine whether the client device remains authorized.

10. The method claimed in claim 9 , further including a step of disallowing the transmission of data packets from the client device to the remote location if said step of observing determines that the client device ceases to remain authorized.

11. The method claimed in claim 1 , wherein said communications from the device controller to the client device comprise control and/or signalling packets.

12. A system for establishing a trust relationship with a client device so as to enable future packet communications from the client device to a remote location through a firewall, the firewall being located between a client device and a device controller, the system comprising:

memory storing an association between the client device and the device controller;

a processor;

a detection component for detecting a packet exchange between the client device and the device controller and, based upon said detection, storing said association in said memory, and wherein said association includes a client device address and a device controller address;

a monitoring component for monitoring packets received from the device controller and addressed to the client device and for determining if the client device is authorized based upon said received packets; and

a firewall update component responsive to said monitoring component for setting a firewall rule, said firewall rule permitting passage of data packets from said client device to the remote location,

wherein the firewall rule permits the transmission of data packets based on the fact they are sent from the client device address, and wherein the data packets are addressed to the remote location and not the device controller.

13. The system claimed in claim 12 , wherein said monitoring component includes a component for determining whether an interval between said packets received from the device controller exceeds a predetermined maximum and, if so, determining that the client device is unauthorized.

14. The system claimed in claim 13 , wherein said monitoring component further includes a component for determining whether said packets have been received over a period of time exceeding a predetermined minimum and, if so, determining that the client device is authorized.

15. The system claimed in claim 12 , wherein said monitoring component includes a component for identifying a session established between the client device and the device controller based upon said packets, and authorizing the client device based upon said session.

16. The system claimed in claim 12 , wherein said monitoring component includes a component for identifying a security relationship between the client device and the device controller based upon said packets, and authorizing the client device based upon said security relationship.

17. The system claimed in claim 12 , wherein said monitoring component continues monitoring said packets for determining whether the client device remains authorized following said setting of said firewall rule.

18. The system claimed in claim 17 , wherein said firewall update component cancels said firewall rule in response to a determination by said monitoring component that the client device ceases to be authorized.

19. The system claimed in claim 12 , wherein the device controller comprises a media gateway controller and the client device comprises a media gateway.

20. The system claimed in claim 12 , wherein the device controller comprises a port discovery server.

Assignments (7)
RELEASE (REEL 038041 / FRAME 0001) Recorded Jan 2, 2018
From: JPMORGAN CHASE BANK, N.A.
To: RPX CORPORATION; RPX CLEARINGHOUSE LLC
Reel/Frame 044970/0030 →
SECURITY AGREEMENT Recorded Mar 9, 2016
From: RPX CORPORATION; RPX CLEARINGHOUSE LLC
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 038041/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2015
From: ROCKSTAR CONSORTIUM US LP; ROCKSTAR CONSORTIUM LLC; BOCKSTAR TECHNOLOGIES LLC; CONSTELLATION TECHNOLOGIES LLC; MOBILESTAR TECHNOLOGIES LLC; NETSTAR TECHNOLOGIES LLC
To: RPX CLEARINGHOUSE LLC
Reel/Frame 034924/0779 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 6, 2014
From: ROCKSTAR CONSORTIUM US LP
To: BOCKSTAR TECHNOLOGIES LLC
Reel/Frame 032399/0116 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 7, 2014
From: ROCKSTAR BIDCO, LP
To: ROCKSTAR CONSORTIUM US LP
Reel/Frame 032168/0750 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2011
From: NORTEL NETWORKS LIMITED
To: ROCKSTAR BIDCO, LP
Reel/Frame 027164/0356 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2004
From: AUDET, FARNCOIS; AOUN, CEDRIC
To: NORTEL NETWORKS LIMITED
Reel/Frame 015805/0055 →