Securing VoIP Transmissions via Payload Alteration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
VoIP transmissions face significant security challenges due to the inability to fully control or inspect data channels, making it difficult to detect and prevent unauthorized data smuggling, which can lead to data theft and system damage.
Innovation Solution
A method that alters network transmissions to interfere with unauthorized data within VoIP packets, rendering it invalid at the receiving end without inspecting the packets, using middleboxes like firewalls and intrusion detection systems to manipulate payload data without degrading the media stream quality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If deep packet inspection is performed to detect hidden data in VoIP transmissions, then security detection capability is improved, but transmission delay increases and real-time performance deteriorates
Solution Approach 1:
The patent extracts only the essential security verification elements (timing information, packet sequence numbers, payload size) from the full packet inspection process, allowing security checks to be performed on these extracted features without inspecting the entire packet content, thus minimizing delay while maintaining detection capability
Solution Approach 2:
Instead of performing complete deep packet inspection of all transmission data, the patent applies partial inspection only to critical security parameters (timing, sequence numbers, payload characteristics), achieving sufficient security detection with minimal processing overhead and transmission delay
2Reliability
If transmission channel access is fully controlled and blocked for security, then security against unauthorized data is improved, but operational usability and compatibility with current telephony deteriorates
Solution Approach 1:
The patent applies different levels of security control to different aspects of transmission: full control on timing and sequencing parameters while allowing free flow of legitimate media content, creating localized security measures that protect against data smuggling without blocking operational communication
Solution Approach 2:
The system introduces intermediary security checks that monitor transmission characteristics (timing, sequence, payload patterns) without directly blocking or controlling the data flow, acting as a mediator that detects unauthorized data while maintaining normal operational compatibility
3Reliability
If conventional detection methods similar to virus detection are used, then detection capability is improved, but difficulty in distinguishing between voice, video, and data information increases
Solution Approach 1:
The patent changes the detection parameters from content-based analysis (which struggles to distinguish data types) to structural and temporal parameter analysis (timing, sequence numbers, packet size patterns), making it easier to identify unauthorized data regardless of its content type
Data Source
AI summary
A method of securing against an unauthorized transmission within an authorized multimedia transmission from a sending data processor to a receiving data processor. The method includes altering the network transmission to interfere with the unauthorized transmission and render the unauthorized transmission invalid to the receiving data processor while not noticeably interfering with the streaming multimedia transmission. Monitoring for retransmissions or retransmission requests also serves as an indicator to an administrator that an unauthorized transmission is occurring. The method of this invention can be implemented by network administrator middleboxes such as firewalls.


