Enterprise Voice Encryption via Network Server Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing telecommunication systems fail to securely facilitate voice communications between external devices, such as mobile devices, and telephony devices within an enterprise network, particularly when communications traverse insecure external networks like the Internet.

Innovation Solution

A method and system that utilize a network server to detect incoming calls, route them securely between external devices and telephony devices, and manage encryption keys to ensure encrypted voice communications, even when external devices are not directly connected to the enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If voice communications are transmitted over external networks (Internet, cellular networks), then communication accessibility and flexibility are improved, but security and confidentiality deteriorate due to potential interception by third parties

Engineering Contradiction:
Improvecommunication accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption system that mediates between external devices and enterprise telephony devices. Encryption modules are deployed on external devices, network servers, and telephony devices to create secure tunnels through the public network, allowing accessible communication while maintaining security through multiple encryption layers and key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different security measures to different parts of the communication system. External devices use client-side encryption with public key infrastructure, network servers implement transport-layer encryption, and enterprise devices use server-side decryption. This localized application of security measures allows each component to operate optimally while collectively ensuring end-to-end security.

Inventive Principle:
Principle #3Local quality

2Object-affected harmful factors

If encryption is implemented for voice communications between external devices and enterprise devices, then security is improved, but system complexity increases due to key management and encryption/decryption processes

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent performs preliminary key exchange and encryption setup before actual voice communication begins. Public keys are distributed in advance, encryption modules are pre-configured on external devices, and security policies are established beforehand. This preliminary action reduces the complexity during active communication, as the encryption infrastructure is already in place and operational.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption system is designed to be self-managing through automated key distribution, automatic encryption/decryption processes, and self-configuring security policies. The system reduces manual intervention by implementing automated certificate management, dynamic key generation, and self-healing security protocols, thereby managing complexity through automation rather than reduction.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If multiple external devices are integrated with the enterprise network, then communication versatility is improved, but network security control deteriorates as these devices operate outside the enterprise's controlled network environment

Engineering Contradiction:
Improvecommunication versatilityVSAvoidnetwork security control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a network server as an intermediary that bridges external devices and the enterprise network. This server implements security policies, manages authentication, and controls access without requiring external devices to physically join the internal network. The server acts as a secure gateway that maintains enterprise control while enabling external communication versatility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a universal security framework that works across multiple device types and network environments. The encryption modules and security protocols are designed to function consistently whether the external device is a mobile phone, laptop, or tablet, regardless of the underlying network (cellular, WiFi, wired). This universal approach maintains security control while supporting diverse communication scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2224668B1System and method for enabling encrypted voice communications between an external device and telephony devices associated with an enterprise network
Publication Date: 2014.05.14 BLACKBERRY LTD
  • EP2224668B1 patent drawingFigure 1
  • EP2224668B1 patent drawingFigure 2
  • EP2224668B1 patent drawingFigure 3

AI summary

A telecommunication system that can selectively establish communications with one of a plurality of telephony devices associated with a particular telephone number for a device in an enterprise network. More particularly, the system is configured to route an incoming telephone call received from an external device, such as a mobile device for example, to one or more of a plurality of telephony devices associated with the telephone number. The plurality of telephony devices may include personal digital assistants and other remote devices. In one embodiment, the system comprises a network server configured to connect the incoming telephone call from an external device to a telephony device, where voice communications are encrypted for transmission by the network server to the external device from which the incoming telephone call is received, and encrypted voice communications received from the external device can be decrypted, re-encrypted and/or stored by the network server if required.