SRTP Secure Media Indicator for End-to-End VoIP Call Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current VoIP systems fail to ensure end-to-end encryption of voice calls, as they only indicate local encryption, allowing calls to be decrypted when traversing unsecured networks like PSTN, leading to ambiguity in call security.

Innovation Solution

Incorporating a Secure Real-Time Transport Protocol (SRTP) encapsulated packet with a secure media indicator into the voice stream, which is periodically inserted into the SRTP voice stream between endpoints to verify end-to-end encryption, and using out-of-band signaling through SIP OPTIONS messages to set and verify secure media flags along the signaling path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Transport Level Security (TLS) or Internet Protocol Security (IPSec) is used to secure signaling channels, then local encryption is achieved, but end-to-end security cannot be guaranteed when calls traverse unsecured networks like PSTN

Engineering Contradiction:
Improvecall securityVSAvoidsecurity status accuracy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary secure media indicator packet that travels with the voice traffic to convey security status information. This intermediary element bridges the gap between local encryption capabilities and end-to-end security verification, allowing the destination endpoint to accurately determine whether the call was secured throughout its entire path or if it traversed unsecured networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the destination IP phone flags the call as secure based on the last secure leg, then the shield icon is displayed, but the call may have traversed unsecured networks earlier

Engineering Contradiction:
Improvesecurity indicationVSAvoidsecurity verification accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent implements a feedback mechanism where the secure media indicator provides continuous security status information from the source through intermediate networks to the destination. This feedback loop allows the destination endpoint to make accurate security determinations based on the actual end-to-end security status rather than making assumptions about intermediate network security.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If a phone system re-routes a PSTN call through a VoIP network, then VoIP functionality is provided, but the call traverses the PSTN unencrypted and is not secure end-to-end

Engineering Contradiction:
Improvecall routing flexibilityVSAvoidend-to-end encryption
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing security verification mechanisms before the call completes its journey. The secure media indicator is generated and propagated along the call path in advance, allowing the destination endpoint to verify end-to-end security status before displaying security indicators to the user, thus preventing misleading security representations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7852783B2Identify a secure end-to-end voice call
Publication Date: 2010.12.14 CISCO TECHNOLOGY INC
  • US7852783B2 patent drawing
  • US7852783B2 patent drawing
  • US7852783B2 patent drawing

AI summary

We describe a system embodiment comprising generating a Secure Real-Time Transport Protocol (SRTP) encapsulated packet and including a secure media indicator into the SRTP encapsulated packet. The method further comprises inserting the SRTP encapsulated packet into an SRTP voice stream associated with an active call between a source and a destination endpoint and indicating an end-to-end secure call between the source and destination endpoints responsive to the secure media indicator.And we describe a method embodiment comprising transmitting a request message from a source endpoint to a destination endpoint participating in an active call and setting a secure media flag in the request message at each node in a signaling path associated with the active call. The method further comprises returning a response message from the destination endpoint to the source endpoint responsive to the request and indicating an end-to-end secure call between the two endpoints.