发明名称 Method and apparatus to scale authenticated firewall traversal using trusted routing point
摘要 A Trusted Routing Point (TROP) generates a signaling message that includes an authorization token used to authorize a firewall to open a pinhole. The signaling message contains a first indicator that indicates whether a data field in the signaling message represents a source address of a media flow. The signaling message also includes a second indicator that indicates whether the firewall should derive the source address of the media flow from the data field. The authorization token is generated using a one-way hash function over information that may be included in the signaling message, including the first indicator and the second indicator.
申请公布号 US9094373(B2) 申请公布日期 2015.07.28
申请号 US201414317633 申请日期 2014.06.27
申请人 Cisco Technology, Inc. 发明人 Ravindranath Ram Mohan;Perumal Muthu Arul Mozhi
分类号 H04L29/06;H04L29/12;H04L9/32 主分类号 H04L29/06
代理机构 代理人
主权项 1. A method comprising: receiving, with a first network device from a second network device, a signaling message to open a pinhole that, when open, allows a media flow originating from a source endpoint to pass through the first network device toward a destination endpoint, the signaling message comprising: a data field that identifies a source transport address of the source endpoint; a first indicator; and a second indicator; determining, with the first network device, that when the pinhole is open, to allow the media flow originating from the source endpoint to pass through toward the destination endpoint when the media flow identifies the source transport address of the source endpoint instead of a source transport address of the second network device that sent the signaling message in response to the first indicator indicating that the data field represents the source transport address of the source endpoint and the second indicator indicating that the first network device should determine a media flow source transport address for the media flow from the data field; receiving, with the first network device, the media flow identifying the source transport address of the source endpoint instead of the source transport address of the second network device; and when the pinhole is open, sending, with the first network device, the media flow identifying the source transport address of the source endpoint toward the destination endpoint.
地址 San Jose CA US
您可能感兴趣的专利