Communication system and method
Abstract
A method and system for communicating packetized audio or audio-visual communications over a data communications network is disclosed. Packets meeting a predetermined criterion are identified and bypass integrity protection. Integrity protection is applied to all other packets

Term
Projected expiry 16 July 2028.
- Priority
- Filed
- Published
- Today
- Projected expiry
16 claims: 5 independent, 11 dependent
- 1A packetized audio or audio-visual communications system including an integrity protection system for protecting integrity of packets during transmission over a data communications network, wherein the communications system is arranged to identify packets meeting a predetermined criterion and is arranged to bypass operation of the integrity protection system for said packets.
- 9A method of communicating packetized audio or audio-visual communications over a data communications network comprising:identifying packets meeting a predetermined criterion and bypassing integrity protection for said packets;and applying integrity protection for all other packets.
- 13A method according to any of claims 9 to 12, further comprising:operating a client system at each of a first and second node, the first and second nodes being connected to the data communications network, monitoring a packet reception buffer at each client system for packets received from the data communications network meeting the predetermined criterion;bypassing the integrity protection for said packets;and, applying, at the respective client system, integrity protection to all other packets in the reception buffer.
- 14A method according to any of claims 9 to 13, further comprising:operating a client system at each of a first and second node, the first and second nodes being connected to the data communications network, monitoring a packet transmission buffer at each client system for packets to be transmitted that meet the predetermined criterion;bypassing the integrity protection for said packets;and, applying, at the respective client system, integrity protection to all other packets in the packet transmission buffer prior to transmission.
Independent claims5
40 paragraphs, as filed
Field of the Invention
0001The present invention relates to a method and system implementing a security protocol that is particularly applicable to secure voice communication over packetized data networks.
Background to the Invention
0002There exist many security protocols for data communications. Each of these derives from the basic framework proposed by, amongst others, Bruce Schneier in his book "Applied Cryptography" and "Practical Cryptography".
0003A security protocol includes the following features: <ul id="ul0001" list-style="bullet" compact="compact"><li>Authentication - identification of the other party/parties to the communication session;</li><li>Confidentiality - taking steps such that data from the communication session is only available to the authenticated parties.</li><li>Integrity - ensuring that data received by a party as part of the communication session has not been changed and that all data has been received.</li></ul>
0004Security protocols create a significant overhead on the load of a data communications network. Indeed the size of secured packets can easily be double that of unsecured packets.
0005Whilst most data communication sessions have at least a degree of resilience in respect of latency and can therefore accommodate the overhead that an increase in packet size inevitably produces, there are increasingly types of communication systems that cannot tolerate such latency.
0006This is particularly the case with voice based data communication systems such as VOIP (voice over IP) which require packet delivery in substantially real time.
0007Even on the most advanced networks offering unlimited bandwidth, a defined quality of service and preferential routing for real time protocols, actually achieving real-time delivery of protected packets protected by a security protocol is a challenge for network operators. Where quality of service and preferential routing is not available or where there may be limited bandwidth, use of security protocols for real-time packets whilst maintaining real-time delivery is almost impossible.
0008To achieve almost real-time service, voice frames should be sent at a rate of around 50 per second. Traditionally each voice frame is integrity protected. The size of each voice frame in common applications is 12 bytes. Integrity protection can take up to 32 extra bytes per frame almost tripling the bandwidth requirements. A common technique to reduce this overhead is to combine frames and protect them using a single integrity checksum. (e.g. putting 6 voice frames (6 * 12 = 72 byte) into 1 packet and protecting this with a 32 byte integrity checksum). However, this still adds a 40% overhead to the communication traffic.
Statement of Invention
0009According to an aspect of the present invention there is provided a packetized audio or audio-visual communications system including an integrity protection system for protecting integrity of packets during transmission over a data communications network, wherein the communications system is arranged to identify packets meeting a predetermined criterion and is arranged to bypass operation of the integrity protection system for said packets.
0010The packetized audio or audio-visual communications system is preferably arranged to bypass the integrity protection system for received packets meeting the predetermined criterion.
0011The packetized audio or audio-visual communications system is preferably arranged to bypass the integrity protection system for packets to be transmitted that meet the predetermined criterion.
0012The predetermined criterion may comprise one or more criteria selected from a group including: <ul id="ul0002" list-style="none" compact="compact"><li>protocol type of the packet matching a predetermined protocol type; a flag or other tag embedded or associated with the packet; routing mechanism under which the packet is to be transmitted or has been received; network from which the packet is to be transmitted or has been received; and,. parameters on the network from which the packet is to be transmitted or has been received.</li></ul>
0013The system may further comprise a client system at each of a first and second node, the first and second nodes being connected to the data communications network, wherein each of the client systems includes the integrity protection system and a packet reception buffer, each of the client systems being arranged to monitor their respective packet reception buffer for packets received from the data communications network meeting the predetermined criterion and to bypass the respective integrity protection for said packets.
0014The system further comprise a client system at each of a first and second node, the first and second nodes being connected to the data communications network, wherein each of the client systems includes the integrity protection system and a packet transmission buffer, each of the client systems being arranged to monitor its respective packet transmission buffer for packets to be transmitted that meet the predetermined criterion and to bypass the respective integrity protection for said packets.
0015The integrity protection system may include a hashing system arranged to append a hash of a packet to a packet to be transmitted, upon bypassing the integrity protection system the packet is transmitted without the hash being appended.
0016The integrity protection system may include a hashing system arranged to generate a hash of a packet received to compare the generated hash to a hash appended to the packet prior to transmission and to reject a packet where the generated hash does not match the appended hash, upon bypassing the integrity protection system the packet is accepted irrespective of any hash appended to the packet.
0017According to another aspect of the present invention, there is provided a method of communicating packetized audio or audio-visual communications over a data communications network comprising: <ul id="ul0003" list-style="none" compact="compact"><li>identifying packets meeting a predetermined criterion and bypassing integrity protection for said packets; and</li><li>applying integrity protection for all other packets.</li></ul>
0018The identifying step may include bypassing the integrity protection for received packets meeting the predetermined criterion. The identifying step may include bypassing the integrity protection for packets to be transmitted that meet the predetermined criterion.
0019The predetermined criterion may comprise one or more criteria selected from a group including: <ul id="ul0004" list-style="none" compact="compact"><li>protocol type of the packet matching a predetermined protocol type; a flag or other tag embedded or associated with the packet; routing mechanism under which the packet is to be transmitted or has been received; network from which the packet is to be transmitted or has been received; and,. parameters on the network from which the packet is to be transmitted or has been received.</li></ul>
0020The method may further comprise: <ul id="ul0005" list-style="none" compact="compact"><li>operating a client system at each of a first and second node, the first and second nodes being connected to the data communications network,</li><li>monitoring a packet reception buffer at each client system for packets received from the data communications network meeting the predetermined criterion;</li><li>bypassing the integrity protection for said packets; and,</li><li>applying, at the respective client system, integrity protection to all other packets in the reception buffer.</li></ul>
0021The method may further comprise: <ul id="ul0006" list-style="none" compact="compact"><li>operating a client system at each of a first and second node, the first and second nodes being connected to the data communications network,</li><li>monitoring a packet transmission buffer at each client system for packets to be transmitted that meet the predetermined criterion;</li><li>bypassing the integrity protection for said packets; and,</li><li>applying, at the respective client system, integrity protection to all other packets in the packet transmission buffer prior to transmission.</li></ul>
0022The step of applying integrity protection may include: <ul id="ul0007" list-style="none" compact="compact"><li>generating hash system of a packet received;</li><li>comparing the generated hash to a hash appended to the packet prior to transmission; and,</li><li>rejecting the packet if the generated hash does not match the appended hash.</li></ul>
0023According to another aspect of the present invention, there is provided a computer-readable medium encoded with a computer program for communicating packetized audio or audio-visual communications over a data communications network, the computer program comprising: <ul id="ul0008" list-style="none" compact="compact"><li>computer program code for identifying packets meeting a predetermined criterion and bypassing integrity protection for said packets; and</li><li>computer program code for applying integrity protection for all other packets.</li></ul>
0024The computer program code for identifying packets may include: <ul id="ul0009" list-style="none" compact="compact"><li>computer program code for bypassing the integrity protection for received packets meeting the predetermined criterion. The computer program code for identifying packets may include: <ul id="ul0010" list-style="none" compact="compact"><li>computer program code for bypassing the integrity protection for packets to be transmitted that meet the predetermined criterion.</li></ul></li></ul>
0025The computer-readable medium may further comprise: <ul id="ul0011" list-style="none" compact="compact"><li>computer program code for operating a client system at each of a first and second node, the first and second nodes being connected to the data communications network,</li><li>computer program code for monitoring a packet reception buffer at each client system for packets received from the data communications network meeting the predetermined criterion;</li><li>computer program code for causing the client system to bypass the integrity protection for said packets; and,</li><li>computer program code for causing the respective client system to apply integrity protection to all other packets in the reception buffer.</li></ul>
0026The computer-readable medium may further comprise: <ul id="ul0012" list-style="none" compact="compact"><li>computer program code for operating a client system at each of a first and second node, the first and second nodes being connected to the data communications network,</li><li>computer program code for monitoring a packet transmission buffer at each client system for packets to be transmitted that meet the predetermined criterion;</li><li>computer program code for causing the client system to bypass the integrity protection for said packets; and,</li><li>computer program code for causing the respective client system to apply integrity protection to all other packets in the transmission buffer prior to transmission.</li></ul>
0027A traditional security protocol would discard the message if the integrity checksum is wrong and optionally ask the sender to retransmit the packet. However, in a real-time protocol, such as VOIP, there is no time to request retransmission of a wrongly received packet. Any packet wrongly or not received is not played through the speaker.
0028In embodiments of the present invention, instead of not playing any data associated with an incorrect integrity checksum, the integrity checksum is ignored completely. This means packets are processed faster and if they have been tampered with the user will hear (and see in the case of visual communications) white noise instead of nothing.
Brief Description of the Drawings
0029An embodiment of the present invention will now be described in detail, by way of example only, with reference to the accompanying drawings, in which: <ul id="ul0013" list-style="none" compact="compact"><li><figref idref="f0001">Figure 1</figref> is a schematic diagram of a packetised communication system for use with an embodiment of the present invention.</li></ul>
Detailed Description
0030<figref idref="f0001">Figure 1</figref> is a schematic diagram of a packetised audio or audio-visual communication system for use with an embodiment of the present invention.
0031The packetised audio or audio-visual communication system 10 includes a first node 20 and a second node 30. Each of the first node 20 and second node 30 includes a security sub-system 21, 31 that is interposed between the respective nodes 20, 30 and a communication network 40. Transmitted and received data packets pass through the security sub-system 21, 31 to be secured and checked as necessary in accordance with a pre-defined security protocol.
0032In use, a voice data packet 50 transmitted from the first node 20 passes through the node's respective security sub-system 21. The packet is encrypted using a previously agreed encryption key (normally referred to as the session key). Other forms of symmetric or asymmetric ciphers may also be used.
0033Standard security protocols would then add a hash of the encrypted message to the end of the message which would typically increase the size of the packet from 20 bytes to as much as 50 or 60 bytes. However, in an embodiment of the present invention, the packet is identified as being a packet meeting a predetermined criterion (in this case requiring substantially real time delivery) and the security sub-system 21 disables its integrity functionality. The secured packet 50' is then transmitted over the data communication network 40 to the second node 30. At the second node 30, it is identified that the packet is one of a predetermined class of packets requiring substantially real-time delivery and any standard integrity testing that is normally done by the security sub-system 31 is bypassed. The packet 50' is decrypted to obtain the data packet 50 and is then passed on to the second node 30. Similar operation happens in reverse when data packets are transmitted from the second node 30 to the first node 20.
0034The packet class may be identified based on protocol type, a flag embedded within the packet or some other predetermined criteria such as routing mechanism, network from which the packet is received, parameters (such as current bandwidth availability, latency etc) of the network or the like. Preferably, the security protocol operated by the respective security subsystems 21 and 31 provides integrity functionality for all packet classes other than those within the predetermined classes identified as needing substantially real time delivery.
0035Preferably, each of the first and second nodes include transmission and reception queues 22, 23 and 32, 33 respectively, in which received packets and packets for transmission are queued before processing by the security subsystem 21, 31. These queues are monitored by the security subsystem of the respective node and packets matching the predetermined criterion/packet class are pulled from the queue and bypass the integrity protection applied by the security subsystem.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO0105087A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US2002071432A1 | Cites | United States of America | Search report |
4 members in 3 offices; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 0713787 | United Kingdom | – | |
| 0713787 | United Kingdom | A |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| CA2637983A1 | Canada | A1 | |
| EP2018025A2This record | European Patent Office (EPO) | A2 | |
| EP2018025A3 | European Patent Office (EPO) | A3 | |
| US2009070871A1 | United States of America | A1 |
13 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | EP | |
| Designated country de not longer valid8566 | 8566 | DE | |
| Designation fees paidAKX | AKX | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Information provided on ipc code assigned before grantRIC1 | RIC1 | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 2018025
- Application
- 82750332
Titles3
- German
- Kommunikationssystem und -verfahren
- English
- Communication system and method
- French
- Système et procédé de communications
Classification
- CPC, 2
- H04L63/123
- H04L69/22
- IPC, 3
- H04L29 06
- H04L12 24
- H04L12 26
Designated states38
- Contracting states, 34
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Croatia
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
and 10 moreShow fewer
- Malta
- Netherlands (Kingdom of the)
- Norway
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
- Extension states, 4
- Albania
- Bosnia and Herzegovina
- North Macedonia
- Serbia