IP Library › Granted Patent US 10,129,243
Granted Patent B2
US 10,129,243 · App. 14/141,798 · Granted Nov 13, 2018

Controlling access to traversal using relays around network address translation (TURN) servers using trusted single-use credentials

Inventors: John H. Yoakum (Cary, NC); Kundan Singh (San Francisco, CA); Joel Ezell (Broomfield, CO); Alan B. Johnston (St. Louis, MO)
Assignee: Avaya Inc.
H04L63/083H04L61/2589
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,129,243
App. No.
14/141,798
Granted
Nov 13, 2018
Kind
B2
Abstract

Embodiments disclosed provide access to Traversal Using Relays around Network Address Translation (TURN) servers using trusted single-use credentials, and related methods, systems, and computer-readable media. In one embodiment, a method comprises receiving, by a TURN authentication agent, a request for a TURN server credential. Responsive to determining that the request is authorized, the agent generates a trusted single-use credential and transmits it to the requestor. Using this trusted single-use credential allows untrusted clients to access a TURN server without exposing a userid/password combination. In another embodiment, a method comprises receiving, by the TURN server, a request for a TURN service. The server challenges the request, and receives a userid and a password. Responsive to determining that the userid and the password constitute a trusted single-use credential and responsive to determining that the request is authorized, the server provides the TURN service for the requestor.

Claims (37)

1. A method for controlling access to a Traversal Using Relays around Network Address Translation (TURN) server, the method comprising:

receiving, by the TURN server, a request from a Web Real-Time Communications (WebRTC) client for a TURN service;

challenging, by the TURN server, the request for the TURN service;

receiving, by the TURN server, a userid comprising an authorized domain identifier and a password comprising an encrypted authentication token from the WebRTC client, wherein the authentication token comprises enterprise policy instructions, wherein the authentication token was generated by a TURN authentication agent executing on a computing device in response to a determination by the TURN authentication agent to authorize a request for a TURN server credential from the WebRTC client;

determining, by the TURN server, whether the userid comprises an authorized single-use credential by determining if the userid comprises the authorized domain identifier;

determining, by the TURN server, whether to authorize the request for the TURN service by decrypting the password to obtain the authentication token using a key based on the authorized domain identifier, wherein the authentication token comprises enterprise policy instructions; and

responsive to determining whether to authorize the request for the TURN service, providing, by the TURN authentication agent, the TURN service for the WebRTC client according to the enterprise policy instructions.

2. The method of claim 1 , further comprising determining that the request originated from an authorized requestor.

3. The method of claim 2 , wherein determining that the request originated from the authorized requestor comprises examining an origin header of the request.

4. The method of claim 1 , wherein the authentication token comprises a value selected from the group consisting of: a domain address; a nonce value; a signature; and the enterprise policy instructions.

5. The method of claim 1 , wherein the authentication token was encrypted using a shared secret.

6. The method of claim 1 , wherein the authentication token was encrypted using an asymmetric key.

7. A system for controlling access to a Traversal Using Relays around Network Address Translation (TURN) server, the system comprising:

a TURN server configured to:

receive a request from a Web Real-Time Communications (WebRTC) client for a TURN service;

challenge the request for the TURN service;

receive a userid comprising an authorized domain identifier and a password comprising an encrypted authentication token from the WebRTC client, wherein the authentication token comprises enterprise policy instructions, wherein the authentication token was generated by a TURN authentication agent executing on a computing device in response to a determination by the TURN authentication agent to authorize a request for a TURN server credential from the WebRTC client;

determine whether the userid comprises an authorized single-use credential by determining if the userid comprises the authorized domain identifier;

determine whether to authorize the request for the TURN by decrypting the password to obtain the authentication token using a key based on the authorized domain identifier, wherein the authentication token comprises enterprise policy instructions; and

responsive to determining whether to authorize the request for the TURN service, provide the TURN service for the WebRTC client according to the enterprise policy instructions.

8. The system of claim 7 , wherein the authentication token comprises a value selected from the group consisting of: a domain address; a nonce value; a signature; and enterprise policy instructions.

9. The method of claim 7 , further comprising determining that the request originated from an authorized requestor.

10. The method of claim 9 , wherein determining that the request originated from the authorized requestor comprises examining an origin header of the request.

11. A non-transitory computer-readable medium storing one or more programs, the one or more programs comprising instructions, which when executed by an electronic device cause the electronic device to implement a method for controlling access to a Traversal Using Relays around Network Address Translation (TURN) server, the method comprising:

receiving, by the TURN server, a request from a Web Real-Time Communications (WebRTC) client for a TURN service;

challenging, by the TURN server, the request for the TURN service;

receiving, by the TURN server, a userid comprising an authorized domain identifier and a password comprising an encrypted authentication token from the WebRTC client, wherein the authentication token comprises enterprise policy instructions, wherein the authentication token was generated by a TURN authentication agent executing on a computing device in response to a determination by the TURN authentication agent to authorize a request for a TURN server credential from the WebRTC client;

determining, by the TURN server, whether the userid comprises an authorized single-use credential by determining if the userid comprises the authorized domain identifier;

determining, by the TURN server, whether to authorize the request for the TURN service by decrypting the password to obtain the authentication token using a key based on the authorized domain identifier, wherein the authentication token comprises enterprise policy instructions; and

responsive to determining whether to authorize the request for the TURN service, providing, by the TURN authentication agent, the TURN service for the WebRTC client according to the enterprise policy instructions.

12. The non-transitory computer-readable medium of claim 11 , wherein the authentication token was encrypted using a shared secret.

13. The non-transitory computer-readable medium of claim 11 , wherein the authentication token was encrypted using an asymmetric key.

14. The system of claim 7 , wherein the authentication token was encrypted using a shared secret.

15. The method of claim 7 , wherein the authentication token was encrypted using an asymmetric key.

16. The non-transitory computer-readable medium of claim 11 , wherein the authentication token comprises a value selected from the group consisting of: a domain address; a nonce value; a signature; and enterprise policy instructions.

17. The non-transitory computer-readable medium of claim 11 , further comprising determining that the request originated from an authorized requestor.

18. The non-transitory computer-readable medium of claim 17 , wherein determining that the request originated from the authorized requestor comprises examining an origin header of the request.

Assignments (14)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 6, 2014
From: YOAKUM, JOHN H.; SINGH, KUNDAN; EZELL, JOEL; JOHNSTON, ALAN B.
To: AVAYA INC.
Reel/Frame 031894/0926 →
Continuity (1)
Related Publication 20150188902A1 · Jul 2, 2015