CryptAgent Proxy for T.38 Fax Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current SIP-based T.38 fax communications over IP networks lack security measures for authenticity, integrity, and confidentiality, as there is no method to secure User Datagram Protocol Transport Layer (UDPTL) packets, which are essential for fax data transmission.

Innovation Solution

The implementation of a CryptAgent system, comprising a client-side CryptAgent (BCA-CA) and a server-side CryptAgent (BCA-SE), acts as a proxy for T.38 fax servers and Session Border Controller (SBC) servers, respectively, to encrypt and decrypt application data packets, ensuring secure transmission using existing communication protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If T.38 fax communications are transmitted over IP networks using SIP and UDPTL, then real-time fax communication capability is achieved, but security (authenticity, integrity, and confidentiality) is compromised

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces CryptAgent as an intermediary component that mediates between the T.38 fax protocol and the encryption/decryption processes. The CryptAgent intercepts UDPTL packets, performs cryptographic operations, and forwards the processed packets, thereby adding security without requiring modifications to the core T.38 fax protocol or existing fax devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security function is segmented into separate modular components: client-side CryptAgent (BCA-CA) and server-side CryptAgent (BCA-SE). This segmentation allows independent deployment, configuration, and management of encryption/decryption functions at different network locations, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption is implemented for T.38 fax packets, then confidentiality is improved, but processing time and computational overhead increase

Engineering Contradiction:
ImproveconfidentialityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Encryption keys are established and cryptographic parameters are configured in advance before actual fax communication begins. The CryptAgents perform key exchange and establish secure channels proactively, so that when fax packets need to be encrypted, the cryptographic infrastructure is already in place, minimizing real-time processing delays.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system allows dynamic adjustment of encryption parameters such as key length, algorithm selection, and packet buffering strategies. By optimizing these parameters based on network conditions and security requirements, the system balances confidentiality with processing time efficiency.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If CryptAgent proxies are deployed for encryption and decryption, then security is enhanced, but network device complexity increases

Engineering Contradiction:
ImproveintegrityVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The CryptAgent is designed as a multi-functional component that can handle multiple protocols (SIP, UDPTL, T.38), perform various cryptographic operations (encryption, decryption, authentication), and operate in different deployment scenarios. This universality reduces the need for separate specialized components, thereby managing network architecture complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent employs proxy architecture where CryptAgents create virtual copies or representations of the original communication endpoints. The BCA-CA proxies the client and BCA-SE proxies the server, allowing the actual fax devices to remain unchanged while the proxies handle security functions, thus simplifying the integration of security into existing networks.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9143488B2Real-time encryption of voice and fax over IP
Publication Date: 2015.09.22 CLOUDLI COMM LTD
  • US9143488B2 patent drawing
  • US9143488B2 patent drawing
  • US9143488B2 patent drawing

AI summary

A method for encrypting application layer packets, including UDPTL data used by T.38 FOIP devices, for securing transmission of Fax communications over the Internet. In one embodiment, a client side SIPCryptAgent is provided and operably installed on the user's Fax or Voice over IP server/device. Similarly, a server side SIPCryptAgent is installed on the SBC servers at the service provider. The client side SIPCryptAgent acts as a proxy for the Fax device thereby receiving all data sent out by the Fax device and encrypting the SIP and media packets of the Fax device using a lightweight protocol before sending them to the SBC servers. Similarly, the server side acts as a proxy for the SBC servers and encrypts outgoing data and decrypts incoming data so that the exchange of data over the Internet between the client side CryptAgent and the server side CryptAgent is done in a secure, encrypted and real time manner.