Securing VoIP Transmissions via Payload Alteration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VoIP transmissions face significant security challenges due to the inability to fully control or inspect data channels, making it difficult to detect and prevent unauthorized data smuggling, which can lead to data theft and system damage.

Innovation Solution

A method that alters network transmissions to interfere with unauthorized data within VoIP packets, rendering it invalid at the receiving end without inspecting the packets, using middleboxes like firewalls and intrusion detection systems to manipulate payload data without degrading the media stream quality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep packet inspection is performed to detect hidden data in VoIP transmissions, then security detection capability is improved, but transmission delay increases and real-time performance deteriorates

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidtransmission delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts only the essential security verification elements (timing information, packet sequence numbers, payload size) from the full packet inspection process, allowing security checks to be performed on these extracted features without inspecting the entire packet content, thus minimizing delay while maintaining detection capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of performing complete deep packet inspection of all transmission data, the patent applies partial inspection only to critical security parameters (timing, sequence numbers, payload characteristics), achieving sufficient security detection with minimal processing overhead and transmission delay

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If transmission channel access is fully controlled and blocked for security, then security against unauthorized data is improved, but operational usability and compatibility with current telephony deteriorates

Engineering Contradiction:
Improvesecurity against unauthorized dataVSAvoidoperational usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different levels of security control to different aspects of transmission: full control on timing and sequencing parameters while allowing free flow of legitimate media content, creating localized security measures that protect against data smuggling without blocking operational communication

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces intermediary security checks that monitor transmission characteristics (timing, sequence, payload patterns) without directly blocking or controlling the data flow, acting as a mediator that detects unauthorized data while maintaining normal operational compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If conventional detection methods similar to virus detection are used, then detection capability is improved, but difficulty in distinguishing between voice, video, and data information increases

Engineering Contradiction:
Improvedetection capabilityVSAvoiddifficulty in distinguishing data types
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent changes the detection parameters from content-based analysis (which struggles to distinguish data types) to structural and temporal parameter analysis (timing, sequence numbers, packet size patterns), making it easier to identify unauthorized data regardless of its content type

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8453241B2Method for securing streaming multimedia network transmissions
Publication Date: 2013.05.28 ILLINOIS INSTITUTE OF TECHNOLOGY
  • US8453241B2 patent drawing
  • US8453241B2 patent drawing
  • US8453241B2 patent drawing

AI summary

A method of securing against an unauthorized transmission within an authorized multimedia transmission from a sending data processor to a receiving data processor. The method includes altering the network transmission to interfere with the unauthorized transmission and render the unauthorized transmission invalid to the receiving data processor while not noticeably interfering with the streaming multimedia transmission. Monitoring for retransmissions or retransmission requests also serves as an indicator to an administrator that an unauthorized transmission is occurring. The method of this invention can be implemented by network administrator middleboxes such as firewalls.