Communication Session Trust Status via Service Network Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unified Communication (UC) systems face challenges in authenticating and securing media flows across different networks, as existing technologies are unaware of the attributes of individual data flows, leading to security risks and potential malicious activities.

Innovation Solution

A system that determines the trust status of communication sessions by identifying attributes and sending session notifications to networks, allowing untrusted data streams to be rerouted as trusted once authentication is verified, thereby securing media flows and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If UC data flows are routed over networks that are unaware of flow attributes, then network flexibility and routing capability are improved, but security authentication and policy enforcement become difficult

Engineering Contradiction:
Improverouting capabilityVSAvoidsecurity authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary component (session border controller or network element) that acts as a mediator between the routing function and security authentication function. This intermediary maintains flow attribute information and provides it to network elements, enabling security authentication without requiring the core routing networks to be aware of flow attributes. The intermediary translates between routing requirements and security policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If networks route UC media flows without awareness of individual flow attributes, then network complexity is reduced, but the ability to enforce security policies for different networks carrying UC media flows deteriorates

Engineering Contradiction:
Improvenetwork complexityVSAvoidsecurity policy enforcement
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent segments the security authentication function from the core routing function. The core network maintains simple routing based on traditional network layers, while a separate security authentication module (intermediary) handles flow attribute-based policy enforcement. This segmentation allows the core network to remain simple while enabling sophisticated security policies through the dedicated authentication component.

Inventive Principle:
Principle #1Segmentation

3Reliability

If all communication sessions are treated as untrusted by default, then security is improved, but the productivity and user experience deteriorate due to continuous verification requirements

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary authentication where communication sessions are verified as trusted before actual media transmission begins. The session border controller or network element performs authentication and establishes trust relationships in advance. Once authenticated, the sessions are allowed to proceed without continuous verification, improving productivity while maintaining security. The preliminary action creates a trusted state that persists throughout the communication session.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10608996B2Trust status of a communication session
Publication Date: 2020.03.31 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10608996B2 patent drawing
  • US10608996B2 patent drawing
  • US10608996B2 patent drawing

AI summary

A device for operating a service network includes a processor and a memory in communication with the processor. The memory includes executable instructions that, when executed by the processor, cause the processor to control the device to perform functions of determining that a communication session is initiated between a first device connected to a first network and a second device connected to a second network, the service network connected between the first and second networks; identifying an attribute of the communication session; determining, based on the identified attribute, whether the communication is authenticated; and when it is determined that the communication is authenticated, sending, to the first or second network, a session notification indicating that the communication session is authenticated with the service network, which allows the first network to route a data stream for the communication session as a trusted data stream.