Secure Voice Encryption via Relay Server and TrustChip
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure voice solutions for Blackberry PDA/cellular devices are expensive, cumbersome, and easily identifiable, lacking effective implementation of end-to-end encryption technology, which is crucial for secure communication in government and commercial environments.
Innovation Solution
One Vault Voice, a hardware and software combination using a proprietary communication application with a hardened encryption module, TrustChip, enables secure voice communications by encrypting voice data as UDP/IP packets, allowing seamless encryption over various data paths like cellular, WiFi, or Bluetooth, and utilizing existing encryption technologies like KOOLSPAN's TrustChip for secure key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secure voice solutions are implemented for Blackberry devices, then security is improved, but cost and device complexity increase
Solution Approach 1:
The patent introduces a relay server as an intermediary component that handles the complex encryption and decryption operations externally. The Blackberry device itself remains relatively simple, while the relay server performs the heavy cryptographic processing using FIPS 140-2 validated algorithms, thus improving security without significantly increasing device complexity
Solution Approach 2:
The patent replaces traditional hardware-based secure voice solutions with a software-based encryption system that runs on standard Blackberry devices. By using software encryption libraries and network-based relay servers, the system achieves high security without requiring specialized hardware modifications to the devices
2Reliability
If end-to-end encryption is implemented for voice communications, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent implements automatic key exchange and encryption initialization between communicating parties. The system automatically establishes secure sessions, manages cryptographic keys, and handles encryption/decryption without requiring user intervention. Users simply initiate normal voice calls, and the encryption infrastructure operates transparently in the background
Solution Approach 2:
The relay server acts as an intermediary that automatically manages the complex encryption handshake and key exchange processes. This mediation eliminates the need for users to manually configure security settings, making the encrypted communication as easy to use as traditional voice calls
3Reliability
If FIPS 140-2 validated encryption is used, then security is improved, but processing speed deteriorates
Solution Approach 1:
The patent applies different levels of encryption to different parts of the communication system. FIPS 140-2 validated encryption is used for the most sensitive portions (voice data transmission through the relay server), while less critical data (signaling, metadata) uses standard encryption. This selective application of high-security encryption minimizes the impact on overall processing speed while maintaining security for the most important data
4Reliability
If secure voice calling is made discreet and indistinguishable from regular calls, then operational security is improved, but ease of detection and measurement deteriorates
Solution Approach 1:
The patent makes the encrypted voice calls appear identical to regular voice calls in terms of user interface and communication flow. The encryption process is transparent and does not change the visual or auditory characteristics of the call experience, making it indistinguishable from unencrypted calls to observers who are not aware of the encryption infrastructure
Solution Approach 2:
The relay server mediates the encryption process in a way that maintains the appearance of direct peer-to-peer communication. To external observers, the calls appear as normal voice traffic, while the intermediary server transparently applies encryption and decryption without altering the fundamental nature of the communication
Data Source
AI summary
A secure voice solution for a PDA-type device is provided. Voice data is received from the user using the device microphone and built- in media player software in the device. This data is encrypted and sent as an IP packet. The device then receives, as IP packets, encrypted voice communication from the other party in the encrypted call, which in turn are decrypted in the device and played back on a second media player running on the device. The present invention takes advantage of the device's ability to run two media players simultaneously to in effect, simulate a cellular telephone call. As a result, an encrypted call can be made with PDA-type devices such as the Blackberry® and also such calls can be made using different data paths (cellular, WiFi, Bluetooth) as the calls are made by sending and receiving data over the Internet, not as traditional cellular data signals.


