Providing telephony services to terminals behind a firewall and /or network address translator
Abstract
A method and apparatus is provided to allow telephony or other types of media communications and services to be provided for a device having a private network address that resides behind a firewall and network address and port translation (NAPT) module (which is not aware of the underlying protocol for the communications and services). Examples of the underlying protocol includes the Session Initiation Protocol (SIP) and Real-Time Protocol (RTP). A path through the firewall and NAPT module is defined by use of keep-alive messages communicated through the firewall and network address translator. Addresses that are allocated by the firewall and NATP module are associated with the device for both signaling and media communications. A feature of the firewall that enables the provision of telephony and media communications through the firewall that is protocol-unaware is that the firewall allows responses to messages initiated by the device back through the firewall.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for use in communications involving a first terminal that is coupled to one side of a firewall and network address translator, the method comprising:
sending, by the first terminal, a message identifying the first terminal to a node on another side of the firewall and network address translator; receiving, by the first terminal, another message from the node, wherein the messages between the first terminal and the node causes creation of a path through the firewall and network address translator; and repeatedly sending keep-alive messages to maintain the path through the firewall and network address translator.
2 . The method of claim 1 , further comprising receiving a call request, by the first terminal, from the node over the path maintained through the firewall and network address translator.
3 . The method of claim 1 , wherein repeatedly sending the keep-alive messages is based on a timer in the first terminal.
4 . The method of claim 1 , wherein sending the identifying message comprises sending a registration message to register the first terminal with the node.
5 . The method of claim 4 , wherein sending the registration message comprises sending a Session Initiation Protocol REGISTER message.
6 . The method of claim 5 , wherein sending the registration message comprises sending the registration message to a Session Initiation Protocol proxy, the node comprising the Session Initiation Protocol proxy.
7 . The method of claim 1 , further comprising exchanging messages, by the first terminal, with the node over the path maintained through the firewall and network address translator to establish a call session.
8 . A system for use in communications between a first terminal and a second terminal, the first terminal coupled to a remote network address translator, the system comprising:
a storage module to store network address translation information for the first terminal; and a controller adapted to partially create the network address translation information during setup of a communications session between the first and second terminals and to wait for a media packet originated by the first terminal after the communications session has been set up to complete the network address translation information.
9 . The system of claim 8 , wherein the media packet contains a source address, the source address comprising a public address that is allocated to the first terminal by the remote network address translator.
10 . The system of claim 9 , wherein the public address of the first terminal is unknown to the controller until after the media packet has been received.
11 . The system of claim 10 , wherein the controller is adapted to further exchange control packets with a device containing the remote network address translator to set up the communications session between the first and second terminals.
12 . The system of claim 11 , wherein at least one of the control packets from the device contains an identifier to identify a private address of the first terminal that is to be used for communications of media packets.
13 . The system of claim 12 , wherein the controller is adapted to ignore the private address of the first terminal for communicating media packets between the first and second terminals.
14 . The system of claim 11 , wherein the control packets comprise Session Initiation Protocol control packets.
15 . The system of claim 14 , wherein the media packet contain Real-Time Protocol data.
16 . The system of claim 14 , wherein the media packet contains at least one of the following types of data: file transfer data, interactive electronic gaming data, and whiteboarding data.
17 . The system of claim 8 , wherein the network address translation information comprises information to map a network address of the first terminal to an alias address of the first terminal.
18 . The system of claim 17 , wherein the network address translation information further comprises information to map a network address of the second terminal to an alias address of the second terminal.
19 . The system of claim 17 , wherein the controller is adapted to transmit media packets originated by the first terminal to the second terminal, each media packet containing the first terminal alias address as a source address.
20 . The system of claim 8 , wherein the controller comprises plural modules, the plural modules comprising a first module adapted to exchange call control signaling and a second module adapted to exchange media packets between the first and second terminals.
21 . An article comprising at least one storage medium containing instructions for establishing communications between a first terminal and a second terminal, the instructions when executed causing a system to:
store network address translation information for the first terminal that resides behind a remote network address translator; partially create the network address translation information during setup of a communications session between the first terminal and the second terminal; and wait for a media packet originated by the first terminal after the communications session has been set up to complete the network address translation information.
22 . The article of claim 21 , wherein the instructions when executed cause the system to store network address translation information containing fields to map an address of the first terminal to a first alias address and to map an address of the second terminal to a second alias address.
23 . The article of claim 22 , wherein the instructions when executed cause the system to further:
communicate, through the system, media packets between the first and second terminals, each media packet containing a source address and a destination address; and translate, for each media packet, both the source and destination addresses.
24 . The article of claim 21 , wherein the media packet from the first terminal contains a source address, the source address comprising a public address that is allocated to the first terminal by the remote network address translator, the public address of the first terminal being unknown to the system until after the media packet has been received.
25 . A device capable of being used in communications through a firewall and network address translator, the device comprising:
an interface adapted to exchange messages with a node on another side of the firewall and network address translator, the exchange of messages with the node to create a path through the firewall and network address translator; and a controller adapted to repeatedly send keep-alive messages to maintain the path through the firewall and network address translator.
26 . The device of claim 25 , further comprising a timer to determine timing of the keep-alive messages.Join the waitlist — get patent alerts
Track US2003009561A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.