IP Library › Granted Patent US 11,012,437
Granted Patent B2
US 11,012,437 · App. 16/144,709 · Granted May 18, 2021

Controlling access to traversal using relays around network address translation (TURN) servers using trusted single-use credentials

Inventors: John H. Yoakum (Cary, NC); Kundan Singh (San Francisco, CA); Joel Ezell (Broomfield, CO); Alan B. Johnston (St. Louis, MO)
Assignee: Avaya Inc.
H04L63/083H04L61/2589H04L63/0281H04L63/101H04L63/123
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,012,437
App. No.
16/144,709
Granted
May 18, 2021
Kind
B2
Abstract

Embodiments disclosed provide access to Traversal Using Relays around Network Address Translation (TURN) servers using trusted single-use credentials, and related methods, systems, and computer-readable media. In one embodiment, a method comprises receiving, by a TURN authentication agent, a request for a TURN server credential. Responsive to determining that the request is authorized, the agent generates a trusted single-use credential and transmits it to the requestor. Using this trusted single-use credential allows untrusted clients to access a TURN server without exposing a userid/password combination. In another embodiment, a method comprises receiving, by the TURN server, a request for a TURN service. The server challenges the request, and receives a userid and a password. Responsive to determining that the userid and the password constitute a trusted single-use credential and responsive to determining that the request is authorized, the server provides the TURN service for the requestor.

Claims (36)

1. A method for controlling access to Traversal Using Relays around Network Address Translation (TURN) servers, the method comprising:

receiving, by a TURN authentication agent executing on a computing device, a request for a TURN server credential from a requesting Web Real-Time Communications (WebRTC) client;

determining the request for the TURN server credential is authorized;

generating a trusted single-use credential in response to determining the request is authorized, wherein the trusted single-use credential comprises an authentication token, wherein the authentication token comprises a domain address identifying an authorized domain for usage of a TURN server, and wherein generating the trusted single-use credential comprises generating the authentication token and encrypting the authentication token using a secret shared between the TURN authentication agent and the TURN server; and

transmitting the trusted single-use credential to the requesting WebRTC client, wherein the trusted single-use credential enables a TURN service for the requesting WebRTC client.

2. The method of claim 1 , wherein determining the request for the TURN server credential is authorized comprises determining the request originated from an authorized requestor.

3. The method of claim 2 , wherein determining the request originated from the authorized requestor comprises examining an origin header of the request.

4. The method of claim 1 , wherein generating the trusted single-use credential comprises generating the authentication token to include in the trusted single-use credential.

5. The method of claim 4 , wherein the authentication token further comprises a value selected from the group consisting of: an expiration time stamp; a nonce value; a signature; and enterprise policy instructions.

6. The method of claim 1 , wherein the authentication token further comprises enterprise policy instructions.

7. The method of claim 6 , wherein the TURN service is enabled according to the enterprise policy instructions.

8. A system for controlling access to Traversal Using Relays around Network Address Translation (TURN) servers, the system comprising:

a communications interface configured to communicate with a requesting Web Real-Time Communications (WebRTC) client;

a processor coupled with the communications interface; and

a computer-readable medium coupled with and readable by the processor and storing therein a set of TURN authentication agent instructions which, when executed by the processor, cause the processor to:

receive, by a TURN authentication agent executing on the system, a request for a TURN server credential from the requesting WebRTC client;

determine the request for the TURN server credential is authorized;

generate a trusted single-use credential in response to determining the request is authorized, wherein the trusted single-use credential comprises an authentication token, wherein the authentication token comprises a domain address identifying an authorized domain for usage of a TURN server, and wherein generating the trusted single-use credential comprises generating the authentication token and encrypting the authentication token using a secret shared between the TURN authentication agent and the TURN server; and

transmit the trusted single-use credential to the requesting WebRTC client, wherein the trusted single-use credential enables a TURN service for the requesting WebRTC client.

9. The system of claim 8 , wherein the authentication token to include in the trusted single-use credential further comprises a value selected from the group consisting of: an expiration time stamp; a nonce value; a signature; and

enterprise policy instructions.

10. The system of claim 8 , wherein determining the request for the TURN server credential is authorized comprises determining the request originated from an authorized requestor.

11. The system of claim 10 , wherein determining the request originated from the authorized requestor comprises examining an origin header of the request.

12. The system of claim 8 , wherein generating the trusted single-use credential comprises generating the authentication token to include in the trusted single-use credential.

13. The system of claim 8 , wherein the authentication token further comprises enterprise policy instructions.

14. The system of claim 13 , wherein the TURN service is enabled according to the enterprise policy instructions.

15. A non-transitory computer-readable medium storing one or more programs, the one or more programs comprising instructions, which when executed by an electronic device, cause the electronic device to implement a method for controlling access to Traversal Using Relays around Network Address Translation (TURN) servers, the method comprising:

receiving, by a TURN authentication agent, a request for a TURN server credential from a requesting Web Real-Time Communications (WebRTC) client;

determining the request for the TURN server credential is authorized;

generating a trusted single-use credential in response to determining the request is authorized, wherein the trusted single-use credential comprises an authentication token, wherein the authentication token comprises a domain address identifying an authorized domain for usage of a TURN server, and wherein generating the trusted single-use credential comprises generating the authentication token and encrypting the authentication token using a secret shared between the TURN authentication agent and the TURN server; and

transmitting the trusted single-use credential to the requesting WebRTC client, wherein the trusted single-use credential enables a TURN service for the requesting WebRTC client.

16. The medium of claim 15 , wherein determining the request for the TURN server credential is authorized comprises determining the request originated from an authorized requestor.

17. The medium of claim 16 , wherein determining the request originated from the authorized requestor comprises examining an origin header of the request.

18. The medium of claim 15 , wherein the authentication token further comprises a value selected from the group consisting of: an expiration time stamp; a nonce value; a signature; and enterprise policy instructions.

19. The medium of claim 15 , wherein the authentication token further comprises enterprise policy instructions.

20. The medium of claim 19 , wherein the TURN service is enabled according to the enterprise policy instructions.

Assignments (8)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2019
From: YOAKUM, JOHN H.; SINGH, KUNDAN; EZELL, JOEL; JOHNSTON, ALAN B.
To: AVAYA INC.
Reel/Frame 050369/0341 →
Continuity (2)
Continuation 14141798 · Dec 27, 2013
Related Publication 20190044937A1 · Feb 7, 2019
Cited By (1)
US 12,367,483