Key Generating Agent for Secure IP Telephony Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current H.225.0 RAS protocol for securing communications between H.323 terminals and gatekeepers relies on weak PIN-based authentication, which is insecure and does not ensure data integrity and privacy, especially for packet-switched devices communicating over packet-switched networks.

Innovation Solution

A system and method for securing communications between packet-switched devices and application servers using a key generating agent that provides unique, strong symmetric keys for authentication, eliminating the need for pre-administered shared-secret keys and ensuring secure communication channels without relying on public key cryptography.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If PIN-based authentication is used for H.323 terminal registration, then the authentication process is simple and easy to implement, but the security level is weak and vulnerable to attacks

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A key generating agent is introduced as an intermediary component between the H.323 terminal and the application server. This agent automatically generates strong symmetric keys for the terminal and manages key distribution, eliminating the need for manual PIN configuration while providing robust cryptographic security. The intermediary handles the complexity of key management transparently to the end user.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If pre-administered shared-secret keys are used for securing communications, then the key exchange process is straightforward, but the system requires public key cryptography which increases complexity

Engineering Contradiction:
Improvecryptography system complexityVSAvoidcommunication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts the public key cryptography requirement from the key exchange process by using a key generating agent that provides symmetric keys through a simplified distribution mechanism. The complex public key infrastructure is replaced with a more straightforward symmetric key distribution model managed by the agent, reducing cryptographic complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The key generating agent enables terminals to self-configure with strong cryptographic keys without requiring manual pre-administration or complex key exchange protocols. The agent automatically generates, distributes, and manages keys for multiple terminals, allowing the system to secure communications through symmetric cryptography without the overhead of public key infrastructure.

Inventive Principle:
Principle #25Self-service

3Productivity

If weak PIN-based authentication is used, then the registration process is fast and requires minimal resources, but data integrity and privacy cannot be ensured

Engineering Contradiction:
Improveregistration process speedVSAvoiddata integrity and privacy
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

Strong symmetric keys are generated and distributed to terminals in advance by the key generating agent before the actual communication begins. This preliminary key distribution enables fast authentication and secure communications from the outset, eliminating the need for slow, iterative security checks while ensuring data integrity and privacy are protected from the start.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7353388B1Key server for securing IP telephony registration, control, and maintenance
Publication Date: 2008.04.01 AVAYA INC
  • US7353388B1 patent drawing
  • US7353388B1 patent drawing
  • US7353388B1 patent drawing

AI summary

A packet-switched communications device in an enterprise network is provided. The packet-switched communications device has a corresponding unique identifier, such as an address or extension. The device includes a processor operable to (a) establish a secure communications session with a key generating agent in the enterprise network; (b) provide, to the key generating agent through the session, the unique identifier of the communications device; and (c) receive, from the key generating agent through the session, a secret key and a key identifier. An application server authenticates the packet switched device using the secret key. After authentication is successful, secure communications is established between the packet switched device and the application server.