SIP Out-of-Dialog REFER Handoff for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing conferencing systems lack a secure mechanism for authenticating endpoint devices with conference services during handoff from a voice user interface (VUI) to a conference service, especially when these services are split across different network servers, leading to potential security vulnerabilities.

Innovation Solution

The implementation of an out-of-dialog SIP REFER with an embedded Replaces header is used to hand off users from the VUI service to the conference service, ensuring secure authentication and authorization without requiring a new call, utilizing a trusted relationship between services and secure communication protocols like TLS or S/MIME.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a basic SIP REFER message is used for handoff from VUI to conference service, then the handoff can be implemented without a new call being placed, but the mechanism lacks security for authenticating the endpoint device with the conference service

Engineering Contradiction:
Improvehandoff operationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent embeds authentication credentials and authorization tokens within the SIP REFER message body, creating a nested structure where the REFER message contains embedded authentication data. This allows the handoff operation to carry security credentials without requiring a separate authentication exchange, resolving the contradiction between ease of handoff and authentication security.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The VUI server acts as an intermediary that collects authentication information from the endpoint, verifies credentials, and then embeds the authorization token in the REFER message to the conference service. This intermediary role enables secure authentication to be conveyed through the REFER mechanism without requiring the endpoint to directly authenticate with the conference service.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the VUI server collects and verifies authentication information from the user endpoint device, then authorization can be verified, but a secure method for conveying authorization information to the endpoint and then to the conference server must be included in the REFER

Engineering Contradiction:
Improveauthorization verificationVSAvoidsecure communication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the authorization verification process by changing the parameter representation from raw credentials to an authorization token that is embedded in the REFER message body. This parameter transformation allows the VUI server to convey authorization status without exposing sensitive credentials, reducing the complexity of secure communication while maintaining reliability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts the essential authorization information from the complex authentication process and embeds only the necessary token in the REFER message. This extraction approach allows authorization verification to be maintained while simplifying the communication mechanism by removing unnecessary cryptographic overhead from the REFER transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If some endpoints are unable to provide secure conveyance of authorization information, then security is compromised, but requiring all endpoints to support complex security mechanisms increases device complexity

Engineering Contradiction:
Improvesecure conveyanceVSAvoidendpoint capability requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The VUI server serves as a trusted intermediary that performs the complex authentication and authorization operations, then embeds the results in the REFER message. This approach transfers the security burden from the endpoint device to the server infrastructure, allowing endpoints with limited capabilities to participate securely without requiring complex security mechanisms at the device level.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication where the endpoint device provides credentials to the VUI server, which then handles the complex verification and token generation autonomously. The endpoint only needs to support basic credential submission, while the server performs the heavy lifting of secure authentication, reducing endpoint complexity requirements while maintaining security reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7872994B2SIP out-of-dialog REFER mechanism for handoff between front-end and back-end services
Publication Date: 2011.01.18 CISCO TECHNOLOGY INC
  • US7872994B2 patent drawing
  • US7872994B2 patent drawing
  • US7872994B2 patent drawing

AI summary

In one embodiment, a method includes steps of verifying, by a first server, that a user associated with an endpoint is authorized to access a service provided by a second server. The first server then sends a Session Initiation Protocol (SIP) out-of-dialog REFER with a Replaces header to the second server. A dialog identification ID of a session between the endpoint and the first server is embedded within the Replaces header. The SIP out-of-dialog REFER causes the second server to send a SIP INVITE with the Replaces header to the endpoint to establish a new session between the endpoint and the second server. It is emphasized that this abstract is provided to comply with the rules requiring an abstract that will allow a searcher or other reader to quickly ascertain the subject matter of the technical disclosure.