Communication network, method for providing safe transmission on the network, method for processing communication connection request and communication system
Abstract
[Task] To be able to alert the user if a transmission is intercepted due to the passage of an unsafe node in the communication network.
Solution.Methods for determining the security level associated with a transmission in a telecommunications network include means of alerting the parties to the security status of the transmission. If the route connecting the parties contains an unsafe link, an alert is provided so that the parties are aware of the unsafe nature of the call before the communication is initiated. Alternatively, the parties may choose to reject or modify the content of the communication in order to maintain completeness.

Term
Term ended
Projected expiry passed 27 June 2020, 6.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
20 claims: 4 independent, 16 dependent
- 1【特許請求の範囲】 【請求項1】 少なくとも1つの他のネットワークエレメントを介して着信システムに接続される発信システムと、 送信が不安全なリンクを介して受信されたことを示すメッセージを着信システムに送信するためのプロセッサを備えたネットワークエレメントとを有することを特徴とする通信ネットワーク。
- 2【請求項2】 前記着信システムは、前記不安全メッセージの受信により、送信の不安全な性質を被呼局に警報することを特徴とする請求項1記載の通信ネットワーク。
- 3【請求項3】 前記発信システムは、発信者に前記不安全なリンクを警報することを特徴とする請求項1記載の通信ネットワーク。
- 4【請求項4】 送信者から受け手へのルートを確立するステップと、 前記ルートの少なくとも一部が不安全なリンクを含むかどうかを決定するステップと、 前記ルートが不安全なリンクを含むという決定により、前記送信の不安全な性質の警報を提供するステップとを有することを特徴とする通信ネットワークにおける安全な送信を提供するための方法。
- 5【請求項5】 前記警報が提供された後に、呼びを接続するステップをさらに含むことを特徴とする請求項4記載の方法。
- 6【請求項6】 前記警報を提供するステップは、受け手の局において別個のリングを出すステップを含むことを特徴とする請求項4記載の方法。
- 7【請求項7】 前記警報を提供するステップは、アイデンティフィケーションディスプレイ上にメッセージを出すステップを含むことを特徴とする請求項4記載の方法。
- 8【請求項8】 前記受け手への接続に先立って、送信者が不安全なリンク警告を受信するステップをさらに含むことを特徴とする請求項4記載の方法。
- 9【請求項9】 前記警報は前記発信者に提供されることを特徴とする請求項4記載の方法。
- 10【請求項10】 前記警報を提供するステップは、可聴音声メッセージを提供するステップを含むことを特徴とする請求項4記載の方法。
- 11【請求項11】 前記警報を提供するステップは、可聴トーンを使用するステップを含むことを特徴とする請求項4記載の方法。
- 12【請求項12】 前記警報を提供するステップは、周期的な警報を提供するステップを含むことを特徴とする請求項10または11記載の方法。
- 13【請求項13】 以前の安全なルートが不安全になった場合、警報を出すステップをさらに含むことを特徴とする請求項4記載の方法。
- 14【請求項14】 前記警報を提供するステップが、パーソナルコンピュータ上の質問スクリーンを含むことを特徴とする請求項4記載の方法。
- 15【請求項15】 当事者間でルートの一部を確立するために、セキュリティプロトコルを含む要求を受信するステップと、 前記ルートが不安全なリンクを含むかどうかを決定するステップと、 不安全なリンクが存在するという決定により、セキュリティ警報メッセージを送るステップとを有することを特徴とする通信接続のための要求を処理するための方法。
- 16【請求項16】 セキュリティ警報メッセージを送ることなしに、ルートの一部を確立するステップをさらに含むことを特徴とする請求項15記載の方法。
- 17【請求項17】 セキュリティステータス要求を送るステップをさらに含むことを特徴とする請求項15記載の方法。
- 18【請求項18】 発呼者を被呼者に接続するための手段と、 少なくとも1つの不安全なリンクを使用して呼びパスが確立される場合、前記発呼者または被呼者に警報するための手段とを有することを特徴とする通信システム。
- 19【請求項19】 前記呼びパスがパケットデータネットワークを通過することを特徴とする請求項18記載の通信システム。
- 20【請求項20】 不安全なリンクが通過されたかどうかを決定するための手段をさらに含むことを特徴とする請求項18記載の通信システム。
Independent claims20
91 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to communication networks and, in particular, relates to confirming and displaying information about the security status of transmissions in such communication networks.
【0002】
[Conventional technology]
A modern communication network is a web of various nodes for delivering information from a sender to a receiver. In the traditional public switched telephone network (PSTN), these nodes are circuit-switched connections, perhaps for relaying information along secure, well-established routes. A relatively new phenomenon in communication is the emergence of packet data networks. The transmission route in the packet data network is dynamic and allows flexibility in the information flow so that the data is transmitted along the most efficient path for delivery. Indeed, the Hallmark of a packet data network is its routing method that guarantees greater bandwidth for the delivery of information.
【0003】
The problem associated with all communication transmissions, but due to the more unpredictable nature of packet transmission routes, a more assertive problem in packet data networks is the security of the nodes through which the information passes. This is because, at many points along the route, unauthorized interception of transmission is possible using relatively unsophisticated equipment. Secure transmission is essential in some applications such as military or corporate communications. With the increasing concentration of packet data and circuit-switched networks, the potential for transmitted information over network nodes that are intercepted is quite high.
【0004】
[Problems to be Solved by the Invention]
Therefore, traditional assumptions about the security of communication networks or the nodes they contain are no longer guaranteed.
【0005】
[Means for solving problems]
It is recognized that most users of communication services expect some degree of privacy when transmitting information over a network. There is a need to alert the user if the transmission is intercepted due to its passage of an unsafe node in the communication network.
【0006】
By alerting the sender or receiver whenever information passes through at least one unsafe node in a telecommunications network, this need is resolved and technological advances in the field of telecommunications are achieved. Upon receiving the security status of the node, the parties can choose to continue communication or reject transmission. A node is considered unsafe if it does not have the ability to send or receive private or encrypted information, or if it passes through equipment that is not absolutely controlled by the network provider. Circuit-switched transmissions are private, but usually unencrypted.
【0007】
In particular, the outgoing system identifies the path to the final destination. If any part of the path contains an unsafe link or node, the intended recipient of the transmission is alerted. The recipient can then choose to accept or reject the call with a warning that the confidential matter will not be leaked. Alternatively, each unsafe node in the transmit network sends a signal indicating its unsafe status. The caller or called party can then choose to abort the transmission.
【0008】
Various mechanisms are available to alert the caller or receiver to the unsafe nature of the call. For example, unsafe transmissions can be indicated by special messages, separate ringing, audible messages or periodic audible tones on the caller identification display. Fortunately, all parties involved in the transmission are actually informed of the security level of the network that supports the transmission so that intelligent decisions about the content can be made.
【0009】
BEST MODE FOR CARRYING OUT THE INVENTION
FIG. 1 is a simplified block diagram of the communication network 100, where the communication network 100 is via links 121, 139 and 177, respectively, via an Internet Service Provider (ISP) access server 120, a cable modem termination system 130, and a first. Includes a packet (cell) network backbone 110 interconnected to a voice gateway 140, a second voice gateway 150 and a mobile exchange center 160. In this figure, unsafe links 121, 139 and 177 are indicated by dashed lines.
【0010】
Among the components known in the art, the packet network backbone 110 includes a processor 111 for performing data transmission procedures and the security maintenance protocols set forth herein. The ISP access server 120 includes a digital signal processor 124 for security maintenance protocols, as described below. The ISP access server 120 serves the personal computer 126 via the established link 125.
【0011】
In this embodiment, the personal computer 126 includes a digital signal processing capable unit 128. The packet network backbone 110 is interconnected to the cable modem termination system 130 by a secure link 131. The cable modem termination system 130 includes a digital signal processor 132 for security maintenance protocols.
【0012】
The cable set-top box 134 includes its own digital signal processor 136 and serves the telephone 138. The cable set-top box is interconnected with the cable modem termination system 130 by an unsafe link 139. The first voice gateway 140 is interconnected with the PSTN 180 via link 143 and the second voice gateway 150 is interconnected with the PSTN via link 153. PSTN serves subscribers to traditional circuit-switched network services.
【0013】
Voice gateways 140 and 150 allow these subscribers to communicate with cable subscribers, such as packet network backbone service subscribers or subscribers using telephone 138. The first voice gateway 140 and the second voice gateway 150 are interconnected with the packet network backbone by secure links 141 and 151, respectively. It is well known that while the network topology of circuit-switched connections enhances security, packet transmission is more vulnerable to interception.
【0014】
The mobile switch center 140, including the digital signal processor 162, serves base station 170 by an established link 165. Base station 170 serves mobile terminal 174 via unsafe air interface 177. Mobile terminal 174 includes its own digital signal processor 176 for security maintenance protocols.
【0015】
Every secure node has a digital signal processor capable of encrypting or decrypting information. In this example, all digital signal processors have the ability to send information about node security status to other network nodes.
【0016】
FIG. 2 shows the steps performed in the communication network 100 according to an embodiment of the present invention. Although this example shows a voice call, those skilled in the art will appreciate that any form of communication connection is applicable. The process begins at step 200, where a calling system, such as the cable set-top box 134, receives a dialed number that identifies the called party (eg, the user serviced by the personal computer 126). In step 202, the calling system establishes a call path to the called party. In this case, the call path is assumed to include links 139,131,121 and 125.
【0017】
In decision step 204, it is determined whether the call path contains an unsafe link. If the result of decision step 204 is a "no" decision, the process proceeds to step 205, where the call is complete. If the result of decision step 204 is a "yes" decision, as in this case, the process proceeds to step 206, where in step 206 the outgoing system decides whether it has cryptographic capabilities and is the final destination. Send a question to the incoming system to determine if it is capable of decrypting.
【0018】
In this case, the cable set-top box has no encryption capability. Therefore, it does not matter whether the final destination has decoding ability. However, to illustrate this step, assume that the set-top box asks the ISP access server 122 to determine if the personal computer 126 includes a digital signal processor 128 for encryption of transmissions. .. In this example, the digital signal processor 128 is capable of decoding. If the outgoing system does not have cryptographic capabilities, you will probably use the process shown in Figure 4, that is, the process of finding a completely secure path.
【0019】
The process proceeds to decision step 208, where it is determined whether the final destination system can process the encrypted message. In this example, the IPS access server 120 asks the personal computer digital signal processor 128 to determine if it has decoding capabilities. If the result of decision step 208 is a "no" decision, the process proceeds to step 210 and the calling system issues an unsafe transmit alert to the caller using phone 138.
【0020】
In decision step 212, the calling system determines whether the caller wishes to continue the call. If the result of decision step 212 is a "no" decision, the process ends at step 214. If the result of decision step 212 is a "yes" decision, the process proceeds to step 213, where an unsafe transmission warning is served by personal computer 126 prior to making a call connection. Issued to the caller. If the result of decision step 208 is a "yes" decision, the process proceeds to step 216, where in step 216 the calling system establishes an encrypted transmission, if it is possible. Send to the called person via the pass.
【0021】
In this example, the outgoing system is unable to encrypt the message and the transmission is sent with a warning. At step 218, the called party receives the encrypted transmission and, where applicable, applies the decryption software. In step 220, the call completes with normal processing after the received transmission has been decrypted. Of course, if both the outgoing and incoming systems are capable of encryption, all transmissions between the parties are encrypted and secure.
【0022】
FIG. 3 is a flowchart showing a system executed in the communication network 100 from the viewpoint of an unsafe network node. Figure 3 should be referenced with Figure 4.
【0023】
The process is initiated in step 300, where the outgoing system refers to the subscriber security profile for the caller and, if the caller subscribes to enhanced security services, from the outgoing system to the incoming system. Sends a send to the final destination with a request for the security status of each node in the root of. Security status requests are loaded on packet data and identify the address of the outgoing system.
【0024】
Security status messages are returned to the outgoing system according to the security maintenance protocol stored in the node. The security status protocol is based on a customer-specific security profile stored in the outgoing system processor or external database. Various parameters can be established based on the subscriber features. For example, a customer can identify a given transmission that does not require a security check (eg, a transmission after 5:00 p.m.).
【0025】
The process proceeds to step 302, where an unsecured node in the network receives an unencrypted transmission from the outgoing system. In decision step 304, the node determines whether the transmission contains a security status request. If the result of decision step 304 is a "no" decision, the process proceeds to step 305, where normal steps are taken to connect the transmission. If the result of decision step 304 is a "yes" decision, the process proceeds to step 306, where the node sends a security alert message to the outgoing system and waits for further instructions from the system. The processing of security alert messages is shown in Figure 4.
【0026】
In decision step 308, the node that sent the security alert message determines whether the transmission should continue based on the instructions received from the outgoing system. If the result of decision step 308 is a "yes" decision, the process returns to step 305, where normal procedures are used to connect the transmissions. If the result of decision step 308 is a "no" decision, the process ends at step 310, where transmission is abandoned and all applications are terminated.
【0027】
FIG. 4 shows the steps performed in the communication network 100 from the perspective of the outgoing system.
【0028】
The process is initiated in step 400, where the outgoing system sends transmissions along a route across the packet data network. The transmission includes a request for security status confirmation. In decision step 402, the calling system determines if the transmission route is pre-established. If the result of decision step 402 is a "yes" decision, the outgoing system determines if the pre-established route is completely secure.
【0029】
If the result of decision step 404 is a "yes" decision, the process proceeds to step 406, where the normal transmission procedure takes place. In certain cases, a route originally identified as safe is the area of another service provider, such as a route change at the last moment (eg, transiting the worldwide web for routing efficiency) or a roaming mobile terminal. Entry into is unsafe.
【0030】
Therefore, in some embodiments, the calling system sends a transmission route to a security alert signal so that the caller and the callee can be notified whether the previously safe route becomes unsafe. To monitor. If the result of decision step 402 is a "no" decision, the process proceeds to step 408, where the outgoing system waits for a security status alert message after sending the send. The processing of security status requests is illustrated in Figure 3.
【0031】
In decision step 410, the outgoing system determines if any security alert message has been received. If the result of decision step 410 is a "no" decision, the process proceeds to step 411, where the outgoing system assumes that the transmission was completed without a security compromise.
【0032】
If the result of decision step 410 is a "yes" decision, the process proceeds to step 412, where the calling system is received by sending an unsafe send warning to the sender and the proposed recipient of the send. Respond to security alert messages. The unsafe message display can take the form of an audible tone, an audible message, a visible display or a question screen on a personal computer. Also, audible tones can be periodically inserted throughout the call to remind the parties of the unsafe nature of the connection.
【0033】
In decision step 414, the caller determines whether one party wishes to try another transmission route based on an unsafe transmission warning. If the result of decision step 414 is a "yes" decision, the process proceeds to step 415, where the transmission system attempts to locate a secure transmission route. In decision step 416, the transmission system determines if a secure transmission route has been found.
【0034】
If the result of decision step 416 is a "yes" decision, the process returns to step 406. If the result of decision step 416 is a "no" decision, the process proceeds to decision step 418, where the calling system decides whether the parties wish to continue transmission. If the result of decision step 418 is a "no" decision, the process proceeds to step 419, where the transmission is abandoned and the application is terminated. If the result of decision step 418 is a "yes" decision, the process returns to step 406.
【0035】
The embodiments described above include customer premises devices such as telephones, facsimile machines or personal computers that have a mechanism for responding to security protocols. More specifically, the customer premises device can send a signal indicating whether the call or transmission should continue or be disconnected based on the security level of the transmission. Conveniently, all embodiments allow all parties involved in the call or information exchange to ascertain the level of security associated with the communication prior to the actual transmission. In this way, the security of the exchange is enhanced by knowledge of the security level associated with the call.
【0036】
It should be understood that the above description relates to a preferred embodiment of the present invention. Numerous other configurations can be devised by one of ordinary skill in the art without leaving the scope of the invention. The present invention is limited only by those defined in the claims.
【0037】
[Effect of the invention]
As described above, according to the present invention, it is possible to alert the user when a transmission is intercepted due to the passage of an unsafe node in a communication network.
[Simple explanation of drawings]
[Figure 1]
The block diagram of the communication network where the method of this invention can be carried out.
[Figure 2]
The flowchart which shows the exemplary step performed in one Embodiment of this invention.
[Fig. 3]
The flowchart which shows the step performed in the 2nd Embodiment of this invention.
[Fig. 4]
The flowchart which shows the step performed in the 3rd Embodiment of this invention.
[Explanation of symbols]
110 packet network backbone 111 processor 120 Internet Service Provider (ISP) Access Server 126 personal computer 130 Cable Modem Termination System (CMTS) 134 Cable Set Top Box 140,150 Voice gateway 160 Mobile Exchange Center 170 base station 180 Public Switched Telephone Network (PSTN)
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
10 members in 5 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 09343823 | United States of America | – | |
| 34382399 | United States of America | A | |
| 34382399 | United States of America | A | |
| 1999343823 | – | – | – |
| US19990343823 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| CA2312592A1 | Canada | A1 | |
| EP1065871A2 | European Patent Office (EPO) | A2 | |
| JP2001069240AThis record | Japan | A | |
| EP1065871A3 | European Patent Office (EPO) | A3 | |
| EP1065871B1 | European Patent Office (EPO) | B1 | |
| DE60016840D1 | Germany | D1 | |
| CA2312592C | Canada | C | |
| US6959184B1 | United States of America | B1 | |
| DE60016840T2 | Germany | T2 | |
| JP4261033B2 | Japan | B2 |
24 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| Certificate of patent or registration of utility modelJAPANESE INTERMEDIATE CODE: R150R150 | R150 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Re-examination (zenchi) completed and case transferred to appeal boardAppealJAPANESE INTERMEDIATE CODE: A912A912 | A912 | |
| Transfer to examiner for re-examination before appeal (zenchi)AppealJAPANESE INTERMEDIATE CODE: A911A911 | A911 | |
| Written amendmentJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Decision of refusalJAPANESE INTERMEDIATE CODE: A02A02 | A02 | |
| Written permission of extension of timeJAPANESE INTERMEDIATE CODE: A602A602 | A602 | |
| Written request for extension of timeJAPANESE INTERMEDIATE CODE: A601A601 | A601 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 |
Numbers
- Publication
- 2001-69240
- Publication, DOCDB
- 2001069240
- Publication, EPODOC
- JP2001069240
- Application
- 193218
- Application, DOCDB
- 2000193218
- Application, EPODOC
- JP20000193218
Titles2
- Japanese
- 通信ネットワークおよびそれにおける安全な送信を提供するための方法および通信接続要求を処理するための方法および通信システム
- English
- INDUSTRIAL APPLICABILITY A communication network and a method and a communication system for processing a communication connection request to provide a secure transmission in the communication network.
Classification
- CPC, 6
- H04M3/2254
- H04M3/205
- H04M3/4228
- H04M7/006
- H04M2203/609
- H04M2207/20
- IPC, 6
- H04L69 40
- H04M3 00
- H04M3 20
- H04M3 22
- H04M3 42
- H04M7 00