Home/Platform/Sharing across networks

Screen sharing across guest Wi-Fi, VLANs, and networks set apart.

Subnets, VLANs, guest Wi-Fi, LTE, the building across the town: one workspace, no VPN, no UC call, no cables. This is the capability that setteth Polaris apart.

Polaris sessions on a rotating wireframe globe An orthographic wireframe Earth, drawn as a coastline and a fifteen-degree graticule, which can be dragged to rotate. Marked on it are sharing devices, meeting-room displays and Polaris Cloud signaling regions. Sessions play in a loop: both ends of a share open an outbound connection to a signaling region, the region introduces them, and the content itself then travels along a single direct arc between the two endpoints while the signaling links go idle. In the last session of the loop the two ends sit behind a network that will not allow a direct path, the direct arc breaks at a marked obstruction, and the encrypted content instead takes one extra hop through a relay before reaching the display. EU WESTDENVERLONDON
Every session here doth cross a network

A guest on LTE in London shareth unto a boardroom in Denver. Both ends call out; the media goeth direct.

signalling — outbound TLS 443, both ends call out media — direct betwixt the two endpoints relayed media — the fallback, one hop more a NAT that no direct path may cross
GUEST DEVICEguest Wi-Fi / LTEPOLARIS CLOUDsignaling brokerPOLARIS PODdisplay · AV VLAN1 · DIAL OUT · TLS 4431 · DIAL OUT · TLS 443both connections start inside the network: no inbound rules, no open ports2 · SCREEN KEY · K7RM2XKEY RESOLVES TO THIS ROOM3 · SDP · ICE EXCHANGED3 · SDP · ICE EXCHANGEDeach side learns a direct path to the other4 · DIRECT MEDIA · ENCRYPTED · DTLS-SRTPEPHEMERAL UDP · PEER-TO-PEER · SOLICITED FLOW PASSES THE STATEFUL FWCLOUD IDLE · OUT OF THE MEDIA PATH5 · UNSOLICITED PACKET✕DROPPED · NO RULE MATCHESSTATEFUL FW · OUTBOUND ONLYSTATEFUL FW · OUTBOUND ONLYCNX-01 · CROSS-NETWORK DATA PATH · TIME RUNS DOWNWARD · CLOUD = SIGNALING ONLYSHEET 1/1 · REV C1 · NO ROUTEGuest Wi-Fi and the display’s VLANhave no route between them.DISPLAY · AV VLANGUEST DEVICE✕2 · THE HANDSHAKEBoth sides dial out to Polaris Cloud:TLS 443, signaling only.POLARIS CLOUDSDP · ICE3 · DIRECT MEDIAThe cloud introduces them, then steps away.Media flows device-to-device, encrypted.CLOUD · OUT OF THE MEDIA PATHENCRYPTED · P2P
1. A guest on LTE seeketh to reach the display directly. No route existeth, and none shall be made.2. The share leaveth their browser instead: outbound TLS signalling on TCP 443 unto webrtc.mersive.com.3. The cloud presenteth the two endpoints; they negotiate a direct, encrypted WebRTC connection. Naught is routed through Mersive; naught is bridged.4. Content floweth from device to display over that direct connection. Signalling is outbound only on both sides: no inbound firewall rules.
thin dashes: signalling to the cloud, outbound TLSbold lines: media, direct betwixt endpointsthe guest shareth from the browser, no apphatched walls: routes that never exist; openings: negotiated flows alone
The fallback, told in full

When no direct path may be formed, the media taketh one relayed hop.

The globe above endeth one session in four after this fashion. Here is that hop, message by message — what the relay is asked for, what it is suffered to forward, and what it may see.

SHARING DEVICEbehind symmetric NATTURN RELAYpublic address, no NATPOLARIS PODdisplay · AV VLAN1 · SYMMETRIC NAT · A DIFFERENT EXTERNAL PORT FOR EVERY DESTINATIONoutbound, succeeds — mapped to 203.0.113.7:51000the display answers to 203.0.113.7:51000✕that mapping is valid only for traffic to the region that opened it — so the check is dropped, and no candidate pair succeeds2 · ALLOCATE · THE DEVICE ASKS THE RELAY FOR AN ADDRESS OF ITS OWNAllocate401 Unauthorized · realm + nonceAllocate · USERNAME · MESSAGE-INTEGRITYSuccess · XOR-RELAYED-ADDRESS · LIFETIME 600 s198.51.100.20:49200a public address that belongs to the device but lives on the relay. One NAT mapping, one destination — which is the thing symmetric NAT does not break3 · CREATEPERMISSION · THE RELAY IS TOLD WHO MAY REACH ITCreatePermission · XOR-PEER-ADDRESS · 300 sthe relay forwards from that one peer address and drops everything else — it is an allocation, not an open reflector4 · CHANNELBIND · 36 BYTES OF PER-PACKET OVERHEAD BECOME 4ChannelBind · channel number · 600 s5 · RELAYED MEDIA · ENCRYPTED · ONE EXTRA HOPDTLS-SRTP END TO END · THE RELAY FORWARDS CIPHERTEXT IT HOLDS NO KEY FORSYMMETRIC NATSTATEFUL FWCNX-02 · RELAYED FALLBACK · TIME RUNS DOWNWARD · RFC 8656 MECHANICS · RFC 5737 ADDRESSESSHEET 1/1 · REV A1 · NO DIRECT PATHA symmetric NAT uses a differentexternal port for every destination.DEVICEDISPLAY✕2 · ALLOCATEThe device asks a relay for a publicaddress of its own, and authenticates.TURN RELAY198.51.100.20:49200LIFETIME 600 s · ONE PEER PERMITTED3 · RELAYED MEDIAOne extra hop. The relay forwardsciphertext it holds no key for.DTLS-SRTP · END TO END

A symmetric NAT giveth every destination a different external port, so the address the display was handed is not the address whence packets would arrive.

the device and its NATthe relay's control messages, then relayed mediaencryption the relay standeth outside ofhatched walls: the NAT and the firewall, neither of which is opened
Where this saveth the day

Three rooms that confound a system bound to the LAN.

The guest who presenteth

A member of the board walketh in upon LTE. No sign-up for guest Wi-Fi, no VPN token, no dongle. They join the workspace from a browser and present in less than a minute, with no access whatsoever to thy network.

Try it in thy boardroom →

The enterprise divided

Corp, guest, AV, and OT networks that by policy must never route one unto another. Polaris keepeth the isolation whole and still bringeth every source to the selfsame display.

The enterprise's tale →

The campus of many buildings

Engineering in Building C shareth unto the war room in Building A, across VLANs and fibre, without raising a UC call merely to move pixels.

At the scale of a campus →
How signalling across networks doth work

Whither thy content truly goeth

Polaris Cloud presenteth the two ends of a share. It beareth them not.

When a source and a display sit upon different networks, the signalling service at webrtc.mersive.com exchangeth the details of connection between the sharing device and the display, and the twain negotiate a direct, encrypted WebRTC connection betwixt themselves. Thy content travelleth from the device unto the display. It passeth not through Mersive.

  • What reacheth our cloud: the session's signalling, the details of connection the two endpoints need to find each other. Not thy screen.
  • What abideth on thy network: when a source and a display are already upon the same network, the connection is negotiated with local addresses alone and never leaveth the LAN.
  • What never cometh to pass: no inbound firewall rules, no bridging of thy networks. All cloud traffic is outbound TLS on TCP 443 from both sides. A guest device getteth no access whatsoever to thy network; the workspace is the only surface shared.
The matter in brief

The union of capability across networks without a VPN, the workspace, and parity in meetings, with a composed workspace to be had in a web browser, setteth Polaris apart.

✓ No VPN✓ No UC call✓ No holes inbound✓ The guest getteth no network access✓ Every Polaris tier

Consult the matrix → The reading on security →

Behold the platform live.

Hardware trials ship for every ware, direct from Mersive. When the rooms have proved it, we shall present thy regional partner for the rollout.

Begin a trial Watch upon YouTube ↗