Secure Voice Session Handling via Intermediary Subsystem

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional call-encryption techniques for packet-switched telephone calls are inefficient and inconvenient, often lacking mobility and requiring burdensome registration signaling, which hampers secure voice communication over packet-switched networks.

Innovation Solution

A system and method for handling secure voice communication sessions using a secure-application subsystem that establishes and manages secure sessions between voice-communication devices, leveraging a base network for call-management tasks such as mobility, presence, and call-control, while employing secure protocols like SRTP for encryption, allowing for seamless mobility and reduced registration burdens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional call-encryption techniques are used, then security is provided, but mobility is limited and registration signaling becomes burdensome

Engineering Contradiction:
ImprovesecurityVSAvoidmobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a secure application subsystem as an intermediary component that mediates between the base network and voice communication devices. This subsystem handles security functions separately, allowing the base network to manage mobility and call control without being burdened by encryption overhead, thus enabling both security and mobility simultaneously

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the call management functions by separating security-related operations (handled by the secure application subsystem) from mobility and call control operations (handled by the base network). This segmentation allows each component to optimize its specific function without interfering with others, resolving the contradiction between security and mobility

Inventive Principle:
Principle #1Segmentation

2Reliability

If traditional call-encryption techniques are used, then security is provided, but registration signaling becomes frequent and burdensome

Engineering Contradiction:
ImprovesecurityVSAvoidregistration signaling time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the registration and call control functions into a single integrated process handled by the base network. The secure application subsystem establishes security contexts once during initial registration, and subsequent calls inherit this security context without requiring repeated registration signaling, thus reducing time loss while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs security context establishment as a preliminary action during the initial registration process. By pre-establishing security contexts before actual voice communication begins, the system avoids the need for frequent re-registration during the call, reducing signaling overhead and time loss

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure voice communication is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcall management processing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure application subsystem acts as an intermediary that handles complex security processing centrally. Voice communication devices only need to establish basic connections with this subsystem, while the subsystem manages encryption, key exchange, and security context management, thereby reducing device complexity while improving security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The base network is designed to provide multiple functions including mobility management, call control, and security context management through a single integrated architecture. This multi-functionality eliminates the need for separate dedicated security processing components in each device, reducing overall system complexity while maintaining robust security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8942671B2Methods, systems, and apparatus for handling secure-voice-communication sessions
Publication Date: 2015.01.27 VERIZON CORP RESOURCES GROUP LLC
  • US8942671B2 patent drawing
  • US8942671B2 patent drawing
  • US8942671B2 patent drawing

AI summary

An exemplary computing system may receive a first request from a first voice-communication device to establish a secure-voice-communication session with a second voice-communication device. The computing system may also receive a second request from the second voice-communication device to establish the secure-voice-communication session with the first voice-communication device. The computing system may establish the secure-voice-communication session between the first and second voice-communication devices. Corresponding methods, apparatus, and computer-readable media are also disclosed.