AU2016269641B2

Systems and methods for conducting secure VOIP multi-party calls

Abstract

System and method for establishing secure conference calls. In one example system, a central conference call server establishes point-to-point connections with accessory devices comprising a secure element and connected to corresponding participant devices. The conference call server includes an interface to a plurality of secure elements configured to perform scrambling and unscrambling of media signals communicated to and from the accessory devices. In another example, one of the participant devices operates as the central conference call server. In other examples, participant devices communicate on a conference call via point-to-point connections between all accessory devices connected to the participant devices. The accessory devices include secure elements for decryption and encryption of media signals communicated between the accessory devices.

AU2016269641B2, drawing sheet 1
Sheet 1 of 4

Term

9.7 yearsleft in the term

Expires 27 May 2036.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

20 claims: 4 independent, 16 dependent

  1. 1
    Claims What is claimed is:1. A method comprising: each of a plurality of secure elements of a conference-call server establishing a respective cryptographic relationship with a different respective remote endpoint of a conference-call session, each such cryptographic relationship having its own security parameters, none of which are accessible to the conference-call server;each of the plurality of server-side secure elements receiving a respective encrypted audio stream sent from its respective remote endpoint during the conference-call session, decrypting the respective received encrypted audio stream using its respective security parameters, and passing the respective decrypted audio stream to the conference-call server for audio mixing;the conference-call mixing the multiple decrypted audio streams and providing an unencrypted mixed audio stream back to each of the plurality of server-side secure elements;and each of the plurality of server-side secure elements encrypting the mixed audio stream using its respective security parameters and outputting its respective encrypted mixed audio stream for transmission by the conference-call server to the respective corresponding remote endpoint.
  2. 10
    A conference-call server comprising:a communication interface configured to communicate over a data network with a plurality of remote endpoints;a plurality of server-side secure elements, each server-side secure element being configured to: establish a respective cryptographic relationship with a different respective remote endpoint of the plurality of remote endpoints of a conference-call session, each such cryptographic relationship having its own security parameters, none of which are accessible to the conference-call server;receive, via the communication interface, a respective encrypted audio stream sent from its respective remote endpoint during the conference-call session, decrypt the respective received encrypted audio stream using its respective security parameters, and pass the respective decrypted audio stream to the conference-call server for audio mixing;and an audio mixer configured to mix the multiple decrypted audio streams and provide an unencrypted mixed audio stream back to each of the plurality of server-side secure elements, wherein each server-side secure element is further configured to encrypt the mixed audio stream using its respective security parameters and output its respective encrypted mixed audio stream for transmission by the conference-call server via the communication interface to the respective corresponding remote endpoint.
  3. 14
    The conference-call server of any of claims 10 to 13, wherein the security parameters of each server-side secure element comprise a server encryption key and a server decryption key, each respective key being generated using a key-exchange method performed during establishment of the respective cryptographic relationship using key information received from the respective remote endpoint, wherein the server decryption key is used to decrypt the respective encrypted audio stream from the respective remote endpoint and the server encryption key is used to encrypt the mixed audio stream.
  4. 16
    The conference-call server of any of claims 10 to 15, further comprising a remoteendpoint-authentication module configured to authenticate a global key provided by a given remote endpoint of the plurality of remote endpoints during initiation of its respective secure media session with the conference-call server -33 2016269641 11 Nov 2019