Method and system for providing secure media gateways to support interdomain traversal
    3.
    发明申请
    Method and system for providing secure media gateways to support interdomain traversal 有权
    提供安全媒体网关以支持域间遍历的方法和系统

    公开(公告)号:US20070019623A1

    公开(公告)日:2007-01-25

    申请号:US11324039

    申请日:2005-12-30

    申请人: Wade Alt Kiwan Bae

    发明人: Wade Alt Kiwan Bae

    IPC分类号: H04L12/66

    摘要: An approach provides interdomain traversal to support packetized voice transmissions. A signaling message is received for establishing a voice call from a first endpoint associated with a first domain to a second endpoint associated with a second domain. The first endpoint queries a STUN (Simple Traversal of UDP (User Datagram Protocol)) server to determine information relating to a firewall and network address translator that the first endpoint is behind, and to log into a TURN (Traversal Using Relay NAT (Network Address Translation)) server configured to establish a media path between the first endpoint and the second endpoint. A first proxy server serving the first endpoint communicates with an ENUM (Electronic Number) server to convert a directory number corresponding to the second endpoint to a network address. The first proxy server communicates with a second proxy server serving the second endpoint to establish the voice call. The STUN server, the TURN server and the ENUM server are maintained by service provider. The first endpoint is authenticated to permit exchange of a media stream over the media path. The media stream is relayed, if the first endpoint is successfully authenticated.

    摘要翻译: 一种方法提供跨域遍历来支持分组化语音传输。 接收到用于从与第一域相关联的第一端点到与第二域相关联的第二端点建立语音呼叫的信令消息。 第一个端点查询STUN(简单遍历UDP(用户数据报协议))服务器,以确定与第一个端点在后面的防火墙和网络地址转换器有关的信息,并登录到TURN(遍历使用中继NAT(网络地址 翻译))服务器,其被配置为在第一端点和第二端点之间建立媒体路径。 服务于第一端点的第一代理服务器与ENUM(电子号码)服务器进行通信,以将与第二端点相对应的目录号码转换为网络地址。 第一代理服务器与服务于第二端点的第二代理服务器通信以建立语音呼叫。 STUN服务器,TURN服务器和ENUM服务器由服务提供商维护。 第一个端点被认证,以允许通过媒体路径交换媒体流。 媒体流被中继,如果第一个端点被成功认证。

    Method and system for securing real-time media streams in support of interdomain traversal
    4.
    发明申请
    Method and system for securing real-time media streams in support of interdomain traversal 有权
    用于保护实时媒体流以支持域间遍历的方法和系统

    公开(公告)号:US20070019545A1

    公开(公告)日:2007-01-25

    申请号:US11324049

    申请日:2005-12-30

    申请人: Wade Alt Kiwan Bae

    发明人: Wade Alt Kiwan Bae

    IPC分类号: H04L12/26

    摘要: An approach provides interdomain traversal packetized voice transmissions. A request is received from a first endpoint of a first domain for establishing a communication session with a second endpoint of a second domain. A tunnel is established by a TURN (Traversal Using Relay NAT (Network Address Translation)) server to support the communication session. The TURN server is controlled by a service provider as part of a managed communication service. The tunnel traverses a first firewall and a first network address translator of the first domain and a second firewall and a second network address translator of the second domain to reach the second endpoint, wherein the communication session is encrypted and transported via the tunnel.

    摘要翻译: 一种方法提供域间穿越分组语音传输。 从第一域的第一端点接收到用于建立与第二域的第二端点的通信会话的请求。 隧道由TURN(穿越使用中继NAT(网络地址转换))服务器建立,以支持通信会话。 TURN服务器由服务提供商控制,作为托管通信服务的一部分。 隧道穿过第一域的第一防火墙和第一网络地址转换器,第二域的第二防火墙和第二网络地址转换器到达第二端点,其中通信隧道经过加密和传输。

    Method and system for providing secure communications between proxy servers in support of interdomain traversal
    5.
    发明申请
    Method and system for providing secure communications between proxy servers in support of interdomain traversal 有权
    用于在代理服务器之间提供安全通信以支持域间遍历的方法和系统

    公开(公告)号:US20070019622A1

    公开(公告)日:2007-01-25

    申请号:US11323863

    申请日:2005-12-30

    申请人: Wade Alt Kiwan Bae

    发明人: Wade Alt Kiwan Bae

    IPC分类号: H04L12/66

    摘要: An approach provides interdomain traversal to support packetized voice transmissions. A request is received and specifies a directory number for establishing a communication session from a first endpoint to a second endpoint. The first endpoint is behind a first network address translator of a first domain, and the second endpoint is within a second domain. A service provider network is accessed to determine a network address for communicating with the second endpoint based on the directory number, to determine existence of a second network address translator within the second domain, and to establish, if the network address can be determined, a media path between the first endpoint and the second endpoint based on the network address to support the communication session. An encrypted session is established with a proxy server according to a cryptographic protocol to support the media path. The proxy server resides within the second domain.

    摘要翻译: 一种方法提供跨域遍历来支持分组化语音传输。 接收到请求并指定用于建立从第一端点到第二端点的通信会话的目录号码。 第一端点在第一域的第一网络地址转换器之后,并且第二端点在第二域内。 访问服务提供商网络以基于目录号码确定用于与第二端点通信的网络地址,以确定第二域内的第二网络地址转换器的存在,并且如果可以确定网络地址,则建立 基于网络地址的第一端点和第二端点之间的媒体路径以支持通信会话。 根据密码协议与代理服务器建立加密会话以支持媒体路径。 代理服务器位于第二个域内。

    Method and system for providing secure credential storage to support interdomain traversal
    6.
    发明申请
    Method and system for providing secure credential storage to support interdomain traversal 审中-公开
    提供安全凭证存储以支持域间遍历的方法和系统

    公开(公告)号:US20070022289A1

    公开(公告)日:2007-01-25

    申请号:US11323513

    申请日:2005-12-30

    申请人: Wade Alt Kiwan Bae

    发明人: Wade Alt Kiwan Bae

    IPC分类号: H04L9/00

    摘要: An approach provides interdomain traversal to support packetized voice transmissions. A request is received from a first endpoint of a first domain for establishing a communication session with a second endpoint of a second domain. Encrypted user credential information is retrieved from a credentials database resident within the first domain, wherein the encrypted user credential includes a password associated with a user associated with the first endpoint. Further, the encrypted user credential information is transmitted to a tunneling server in response to the request, wherein the tunneling server is configured to selectively setup a tunnel to support the communication session based on the encrypted user credential information. The tunnel traverses a first firewall and a first network address translator of the first domain and a second firewall and a second network address translator of the second domain to reach the second endpoint.

    摘要翻译: 一种方法提供跨域遍历来支持分组化语音传输。 从第一域的第一端点接收到用于建立与第二域的第二端点的通信会话的请求。 从驻留在第一域内的证书数据库检索加密的用户凭证信息,其中加密的用户证书包括与与第一端点相关联的用户相关联的密码。 此外,响应于该请求,将加密的用户凭证信息发送到隧道服务器,其中隧道服务器被配置为基于加密的用户凭证信息选择性地建立隧道以支持通信会话。 隧道穿过第一域的第一防火墙和第一网络地址转换器,第二域的第二防火墙和第二网络地址转换器到达第二端点。