Secure Voice Session Handling via Intermediary Subsystem
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional call-encryption techniques for packet-switched telephone calls are inefficient and inconvenient, often lacking mobility and requiring burdensome registration signaling, which hampers secure voice communication over packet-switched networks.
Innovation Solution
A system and method for handling secure voice communication sessions using a secure-application subsystem that establishes and manages secure sessions between voice-communication devices, leveraging a base network for call-management tasks such as mobility, presence, and call-control, while employing secure protocols like SRTP for encryption, allowing for seamless mobility and reduced registration burdens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional call-encryption techniques are used, then security is provided, but mobility is limited and registration signaling becomes burdensome
Solution Approach 1:
The patent introduces a secure application subsystem as an intermediary component that mediates between the base network and voice communication devices. This subsystem handles security functions separately, allowing the base network to manage mobility and call control without being burdened by encryption overhead, thus enabling both security and mobility simultaneously
Solution Approach 2:
The patent segments the call management functions by separating security-related operations (handled by the secure application subsystem) from mobility and call control operations (handled by the base network). This segmentation allows each component to optimize its specific function without interfering with others, resolving the contradiction between security and mobility
2Reliability
If traditional call-encryption techniques are used, then security is provided, but registration signaling becomes frequent and burdensome
Solution Approach 1:
The patent merges the registration and call control functions into a single integrated process handled by the base network. The secure application subsystem establishes security contexts once during initial registration, and subsequent calls inherit this security context without requiring repeated registration signaling, thus reducing time loss while maintaining security
Solution Approach 2:
The patent performs security context establishment as a preliminary action during the initial registration process. By pre-establishing security contexts before actual voice communication begins, the system avoids the need for frequent re-registration during the call, reducing signaling overhead and time loss
3Reliability
If secure voice communication is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The secure application subsystem acts as an intermediary that handles complex security processing centrally. Voice communication devices only need to establish basic connections with this subsystem, while the subsystem manages encryption, key exchange, and security context management, thereby reducing device complexity while improving security
Solution Approach 2:
The base network is designed to provide multiple functions including mobility management, call control, and security context management through a single integrated architecture. This multi-functionality eliminates the need for separate dedicated security processing components in each device, reducing overall system complexity while maintaining robust security
Data Source
AI summary
An exemplary computing system may receive a first request from a first voice-communication device to establish a secure-voice-communication session with a second voice-communication device. The computing system may also receive a second request from the second voice-communication device to establish the secure-voice-communication session with the first voice-communication device. The computing system may establish the secure-voice-communication session between the first and second voice-communication devices. Corresponding methods, apparatus, and computer-readable media are also disclosed.


