Encapsulation, compression, and encryption of pcm data
Abstract
Systems and methods for secure access through an untrusted public exchange telephone network (116) are described. This system and method can be initiated by a security policy that defines actions, including making a call in secure mode that should be taken based on at least one detected attribute of the call.
Term
Term ended
Projected expiry passed 9 November 2021, 4.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
10 claims: 2 independent, 8 dependent
- 1第1の企業ロケーション内の1つ以上のエンドユーザー局間の通話を公衆交換電話ネットワークを通して第2の企業ロケーション内の1つ以上のエンドユーザー局へ安全にトランスポートするための仮想的パーソナル交換電話ネットワークシステムであって、該システムが前記1つ以上のエンドユーザー局と前記公衆交換電話ネットワークへのそれぞれの回路との間に位置しており、該仮想的パーソナル交換電話ネットワークシステムが、少なくとも1つのセキュリティ規則を含むデータベースを備え、前記少なくとも1つのセキュリティ規則が着信通話および発信通話時に、または選択された着信通話および発信通話時に、回線上の前記着信通話または発信通話の少なくとも1つの属性に基づいてとるべき少なくとも1つの処置を指定しており、前記少なくとも1つの処置が安全モードで着信通話または発信通話を行うことを含み、前記少なくとも1つの属性が前記企業ロケーション内で決定され、前記第1企業ロケーション内および前記第2企業ロケーション内に設けられた少なくとも1つの電話装置を備え、前記少なくとも1つの電話装置が前記少なくとも1つの属性を決定すると共に、すべての着信通話および発信通話時に、または所定の着信通話および発信通話時に、前記少なくとも1つのセキュリティ規則に従って前記着信通話および発信通話の前記少なくとも1つの属性に基づいて、前記少なくとも1つの処置を実行するための手段を含む、仮想的パーソナル交換電話ネットワークシステム。
- 2通話の前記少なくとも1つの属性が、通話方向、入通話ソース番号、出通話ソース番号、入通話宛て先番号、出通話宛て先番号、回線識別、通話タイプ、通話日、通話時刻、通話内容および通話期間を含む群から選択されたものである、請求項1記載の仮想的パーソナル交換電話ネットワークシステム。
- 3前記着信通話および発信通話の前記所定の通話タイプが、音声、ファックスおよびデータ送信(モデム)のうちの少なくとも1つを含む、請求項2記載の仮想的パーソナル交換電話ネットワークシステム。
- 4前記少なくとも1つのセキュリティ規則が、通話の許可または拒否、トーンまたはメッセージの送信、通話内容のモニタ、通話のログ、レポートの発生および警告をすることのうちの1つ以上を含む追加処置を指定し、前記警告が電子メール通知、ページャーダイヤリング、コンソールメッセージングまたは簡単なネットワーク管理プロトコル(SNMP)トラップを介することを含む群から選択されたものである、請求項1記載の仮想的パーソナル交換電話ネットワークシステム。
- 5前記電話装置が前記電話装置にプログラムされているか、または管理サーバーからプログラムされている、請求項1記載の仮想的パーソナル交換電話ネットワークシステム。
- 6前記発生されたレポートが事象の分析またはバッチ分析を含む、請求項4記載の仮想的パーソナル交換電話ネットワークシステム。
- 7第1の企業ロケーション内の1つ以上のエンドユーザー局間の通話を公衆交換電話ネットワークを通して第2の企業ロケーション内の1つ以上のエンドユーザー局へ安全にトランスポートするための方法であって、このシステムが前記1つ以上のエンドユーザー局と前記公衆交換電話ネットワークへのそれぞれの回路との間に位置しており、この方法が、企業ロケーション内のエンドユーザー局の各々に対し、前記第1企業ロケーションおよび前記第2企業ロケーションの双方内に少なくとも1つのセキュリティ規則を定める工程を備え、前記少なくとも1つのセキュリティ規則が安全モードで着信通話および発信通話を実行すること、すべての着信通話および発信通話時に、または前記少なくとも1つのセキュリティ規則に含まれ、回線上の通話の少なくとも1つの属性に基づき選択された着信通話および発信通話時に、前記少なくとも1つの処置を実行することを含む群から選択された少なくとも1つの処置を指定し、通話の前記少なくとも1つの属性を決定するよう、通話のアクティビティを検出し、かつ分析する工程を備え、通話の前記少なくとも1つの属性が、通話方向、入通話ソース番号、出通話ソース番号、入通話宛て先番号、出通話宛て先番号、回線識別、通話タイプ、通話日、通話時刻、通話内容および通話期間を含む群から選択された少なくとも1つの属性を含み、前記検出し、分析する工程が企業のロケーション内で行われ、前記少なくとも1つのセキュリティ規則に従い、前記少なくとも1つの属性に基づき、選択された着信通話または発信通話時に前記少なくとも1つの処置を実行する工程を備える、通話の安全なトランスポートを行うための方法。
- 8前記少なくとも1つのセキュリティ規則が、通話の許可または拒否、トーンまたはメッセージの送信、通話内容のモニタ、通話のログ、レポートの発生および警告をすることのうちの1つ以上を含む追加処置を指定し、前記警告が電子メール通知、ページャーダイヤリング、コンソールメッセージングまたは簡単なネットワーク管理プロトコル(SNMP)トラップを介することを含む群から選択されたものである、請求項7記載の方法。
- 9前記着信通話および発信通話の前記所定の通話タイプが、音声、ファックスおよびデータ送信(モデム)のうちの少なくとも1つを含む、請求項7記載の方法。
- 10安全モードでの通話を行うことが、安全な通話データの交換と同時に第1の企業と第2の企業との間でのメッセージを連続して交換することを含む、請求項7記載の方法。
Independent claims10
195 paragraphs, as filed
【0001】
(Cross-reference with related applications) This application is a partial continuation of U.S. Patent Application No. 09 / 210,347 with the title of the invention "Telephone Security System" filed on December 11, 1998, and is currently in the United States. U.S. Patent Application No. 09, in connection with Patent No. 6,249,575B1 and further filed on December 8, 1999, with the title of the invention "a highly integrated collaborative communication firewall and scanner with dispersive capacity". / 457,494, which is currently an application related to US Pat. No. 6,226,372B1, both of which have been transferred to the applicant of the present application, both of which are incorporated herein by reference.
【0002】
The present invention generally relates to a communication access control system, and more particularly to a system and method for autonomously constructing a virtual personal exchange communication network between at least two inline devices.
【0003】
(Background of the Invention) Historically, governments and business institutions have relied on confidential information transmitted by telephone, fax or modem, and have to monitor or eavesdrop on their plans and strategies. I am reasonably convinced. This is no longer true. In the last few years, as interception and intrusion techniques have become more abundant, information assets have become surprisingly vulnerable to interception when transferring information between parties intended for use.
【0004】
A wide range of communications, from communications related to military, government and law enforcement to contract negotiations, legal action and personal issues, are all sensitive to new product development, strategic plans, financial transactions or other competition. Require a secret when communicating with. These secrets often have to be communicated via telephone, fax, video conferencing (VTC), data (modem) transmission and other electronic communications. As the business world became increasingly dependent on communication systems, these communication systems sent ever-increasing amounts of information, much of which was proprietary, and this information was extremely useful to competitors. It is a thing.
【0005】
It is not the business competitors that the company must be interested in. The risk is especially high for companies operating outside the United States. Many countries have defined their security as economic security and are also spying on their intelligence agencies for industrial and economic business. As a result, some foreign intelligence agencies are actively and aggressively espionage against businesses to gather technical and proprietary information.
【0006】
The widespread use of digital communication systems has led to the widespread use of digital encryption systems by governments and businesses interested in communication security. These systems take various forms, from virtual personal networks (VPNs) of data to secure voice / data terminals.
【0007】
Communication and computer systems move vast amounts of information quickly and regularly. Enterprises communicate using voice, fax, data and video signals through the unreliable public switched telephone network (PSTN). Unfortunately, data VPNs protect information sent over the Internet, but data VPNs are not designed to protect voice, fax, modem and video calls over untrusted PSTNs.
【0008】
Internet Protocol (IP) -based VPN technology is automated and widely available, but the solution for creating secure tunnels through the PSTN is primarily manual, to secure calls. Users must participate on both sides. This is the case when using secure voice / data terminals such as secure telephone units (STU-III), secure telephone equipment (STE) and handheld telephone encryption devices.
【0009】
With secure voice / data terminals, these terminals effectively protect secret voice and data calls. However, these designs and typical installations can be self-defensive. For example, to enter secure mode on an STU-III or STE device, both parties look up the physical encryption key from the secure storage location and make an individual STU-III each time they make or receive a call. Or you have to insert the key into the STE device. Moreover, due to the high cost of these STU-III and STE devices, they are generally installed in a special or central location within the installation center or work center rather than at each of these work stations. If the STU-III or STE call is not scheduled in advance, the caller may have to wait while the callee answers the locked phone.
【0010】
If a secure voice / data terminal is installed on the analog line, the transmission speed and the quality of voice recognition are poor. Low speeds can be tolerated for secure data transfer, but slow transmission speeds can make voice communication difficult and frustrating. Good speed and sound quality can be obtained with integrated services digital network (ISDN) or trunk level 1 (T1) spans, but analog line installations are expensive and many organizations want to continue using current equipment. ..
【0011】
The inconvenience, frustration and poor sound quality of using a manually activated secure voice / data terminal can motivate individuals to speak secrets on unsafe phones. Confidential information is not spoken directly, but these obscure conversations can be put together to obtain the correct idea of the information that is presumed to be protected. Although policies can force the use of secure voice / data terminals to transmit confidential information, there is currently no way to properly enforce such conditions.
【0012】
In addition, a secure voice / data terminal can only secure one end-user station per device. Since these terminals are point-to-point devices, secure voice / data terminals cannot protect the majority of calls made between users who do not have access to the device. In addition, there is a policy that specifically prohibits this, but it is possible to improperly discuss confidential data on an insecure phone and thus spread this data through an insecure PSTN.
【0013】
A secure voice / data terminal cannot implement a company-wide multi-tiered policy-based implementation of a company's security policy that establishes a basic security structure around the company commanded from top to bottom of the hierarchy. Voice / data terminals cannot be secure, nor can they provide enterprise-wide, multi-tiered policy-based implementation of selective event logging and integrated reporting that should be relayed to the tier. ..
【0014】
A secure voice / data terminal cannot provide the ability to see live all secure call activity performed by the device.
【0015】
Finally, secure voice / data terminals cannot provide call event logs detailing information about secure calls. Therefore, it is not possible to produce a detailed and summarized report that integrates call event logs for use by security personnel and administrators in assessing an organization's security attitudes.
【0016】
Through untrusted PSTN through telephone resources that can be initiated by a security policy that defines actions to be taken based on at least one attribute of the call, which provides execution capability based on a multi-tiered policy and visibility into security events. There is a clear need for systems and methods for secure access.
【0017】
(Outline of the Invention) Next, a system and a method for providing secure access through an unreliable PSTN will be described. This system and method utilizes telephone resources that can be initiated by a security policy similar to that described in US Pat. Nos. 6,249,575B1 and 6,226,372B1. Predetermined action is taken based on execution capability and visibility into security events based on one attribute and multi-tiered policy.
【0018】
The main features of the systems and methods disclosed herein are: (1) Being transparent to the operator, that is, the actions taken by the parties to make a secure call to enable and implement secure communication through security policies. Is not required, (2) by installing a point device at each end user station in a span from the central station (CO), to a large number of end user stations (ie all calls on the span) (For) Secure communication, (3) Make all calls in safe mode, allow or deny selective calls, and take other measures if the call cannot be made in safe mode A security policy that specifies what to do, such as sending a tone or message, monitoring the content of a call, logging a call, sending a notification, can be implemented and enforced, (4) at least one designation of the call. Specifying to make a selective call in safe mode based on the attributes given, allowing or denying the call, and taking other actions if the call cannot be made in safe mode, eg Sending tones or messages, monitoring call content, implementing and enforcing security policies to log or send notifications, (5) allow or deny selective calls, and Other actions can be taken based on why the call cannot be made in secure mode, (6) voice, fax and modem calls can be safely transported, and (7) transcoding-unaffected communication is secure. Can be transported to, (8) Secure call data and message channel can be separated, messages and secure calls can be sent at the same time, (9) Security policy can be automatically enforced, (10) Call attributes For example, the security policy is realized and implemented based on the call direction, incoming call source, outgoing call source, incoming call destination, outgoing call destination, call type, call content, call date, call time, call period, etc.What can be done, (11) the ability to implement and implement basic security structures and policies across the enterprise ordered downwards from the top of the hierarchy, and (12) log and integrated reporting of selective events to be relayed to the hierarchy. It is possible to realize and implement the company-scale policy of.
【0019】
The second advantage of the systems and methods disclosed in this document is that (1) a new key is created for each session, eliminating the need for a static private key, and (2) a key is automatically created for each session. Control and status messages that eliminate the need for a manual key, (3) keep the message channel active for the duration of the call, and allow this message channel to start or interrupt safe mode transmission while the call is in progress. To send, (4) evaluate the line result as part of the safe mode call setting, and if the line condition cannot support secure communication, interrupt the secure call setting, and (5) sound quality. Is equal to the quality of toll calls, that is, the quality of uncompressed pulse code modulated digital signal level 0 channels at 64000 bps.
【0020】
Therefore, the objects, features and advantages of the present invention will be apparent to those skilled in the art by referring to the accompanying drawings and reading the following description and claims according to the outline so far.
【0021】
The accompanying drawings will give you a good understanding of the systems and methods for autonomously building a virtual personal exchange communication network between at least two in-line devices.
【0022】
(Detailed Description of Preferred Examples) The present invention will be described with reference to the following examples. However, it can be seen that the examples below do not necessarily limit the invention and are used to illustrate examples of typical operations.
【0023】
FIG. 1A is a block schematic of an example of the Virtual Personal Exchange Communication Network (VPSTN) 100 of the present invention, which is shown in U.S. Patent Application No. 09 / 210,347 (currently U.S. Pat. No. 6,249,575B1). It is similar to the communication firewall implemented as described. The VPSTN100 can simultaneously act as an integrated VPSTN100 and firewall, or can be combined with a communication firewall to be an example consisting of a combination of capabilities of each device.
【0024】
VPSTN100 at least two inline devices, such as a telephone instrumentation and location (TA) 102 and 104, the management server 106 and 108, and a client 110 and 112, which are to interact as described below either the transmission Control Protocol / Internet Protocol Based on TCP / IP, they are interconnected by a local area network (LAN), wide area network (WAN), or the Internet (all of which are indicated by number 113 in this document). As a person skilled in the art, the functions of the present invention described herein may be performed by TA 104, management server 108 and client 112 as well as by TA 102, management server 106 and client 110. Let's understand.
【0025】
The VPSTN100 provides secure communication between two geographically separated, globally distributed locations. The TA102 or TA104 is installed in-line in a digital signal level 1 (DS-1) circuit. The capacitance on the DS-1 circuit (ie, the amount and speed of channels) varies with respect to the global location. For example, the T1 or J1 used in North America and Japan, respectively, operate at 1,544,000 bits per second (bps) and carry 24 time-division-multiplexed (TDM) digital signal level 0 (DS-0) channels. In addition, in North America, the main rate interface (ISDN PRI) span of line services digital networks carries either 23 TDN DS-0 channels and one signal channel, or 24 TDN DS-0 channels. it can. In Europe, the E1 span operates at 2,048,000 bps and sails 30 TDN DS-0 channels in addition to the two signal channels. One DS-0 channel operates at 64,000 bps. Another change to global location is the difference in the form of PCM coding.
【0026】
The standard commonly used in North American and Japanese telephone networks is the Mu standard, and the standard used in public exchange telephone networks in Europe and most other countries is the A standard. Transcoding, or changing, transcoding the data stream from the Mu standard to the A standard so that the data stream can be carried through different networks can change the PCM value. The spans such as T1, J1, ISDN PRI, E1 that support the DS1 circuit between the VPSTN100 and the PSTN are the same on both sides of the PSTN (ie, from the T1 span that can occur in calls made within the North America) through the PSTN. Call regardless of whether it is (to the T1 span) or some combination of span types (from the T1 span to the E1 span via the PSTN as it occurs in international calls between North America and Europe). All operations are transparent to the person making the call and the person receiving the call (ie, which party of the call does not have to take any special action to initiate or make a secure call).
【0027】
Similar to the connectivity of inline devices described in US Pat. No. 6,249,575B1 and US Pat. No. 6,226,372B1, between or at the end between the Public Branch Exchange (PBX) 114 and the Public Switched Telephone Network (PSTN) 116. The TA102 is installed in series on the DS-1 circuit 103 between the user station 136 and the PSTN116 (see Figure 1B). Similarly, the TA104 is installed in series with the DS-1 circuit 105 between the PSTN116 and the PBX118. The TA102 has two input ports and two output ports. More specifically, it has a PBX input port 120, a PSTN output port 122, a PSTN input port 124, and a PBX output port 126. Similarly, the TA104 has two input ports and two output ports. Specifically, it has a PSTN input port 128, a PBX output port 130, a PBX input port 132, and a PSTN output port 134.
【0028】
Clients 110 and 112 configure security policies to display and view real-time alerts, view real-time event logs, system administrators to print event logs and integrated reports, and others on the BPSTN100. It is the point of the user interface for the operational functions of.
【0029】
A security policy is a sequential rule that determines whether to allow, deny (hang), run in safe mode, monitor conflicts, and log certain calls to and from the end-user station. It's a list. This security policy sends tones or messages to the calling party to indicate whether the call can or cannot be made in secure mode, email notifications, pager alerts, console messages or simple network management. It also determines if other actions such as sending notifications, such as protocol (SNMP) trap notifications, are needed.
【0030】
Management servers 106 and 108 receive security policies from clients 110 and 112 and send copies of the security policies to TA 102 and 104, respectively. The TA102 and 104 receive a security policy, monitor incoming and outgoing calls when appropriate, and all follow the security policy and are in secure mode based on at least one call attribute (eg call type, voice, fax, modem, VTC, etc.). Allow, deny, or otherwise perform a call, including making a call. Management servers 106 and 108 are connected to TA 102 and 104 for reporting and call log consolidation and management, respectively. Call history logging and archiving according to a given security policy can be done on a local management server or stored via a network accessible log server (not shown).
【0031】
The TA102 and 104 are microprocessor controllers, access control logic and call interrupt circuits to provide call progress monitoring, caller ID (CND) and / or automatic number identification (ANI) decoding, to achieve the desired VPSPN functionality. Digital line protocol reception, decryption, demodulation, pulse dial detection, dual tone multi-frequency (DTMF) and multi-frequency (MF) tone detection, compression, encryption, decryption and decompression can be combined.
【0032】
As described in U.S. Pat. No. 6,249,575B1 and U.S. Pat. No. 6,226,372B1 and described herein for clarity, security policy rules are based on at least one attribute of a call and of an individual call or call. Define actions related to the group. The rule criteria are any Boolean combination of specified call attributes, such as call direction, call source number, call destination number, call type, call content, call date, call duration and call time (AND, OR, NOT). Can be. Evaluate rules for sequential call events until one of the rules is met or none of the rules meet the call attributes. For each end-user station 136 connected through the TA102, the TA102 captures and analyzes call activity. This aspect of call activity concerns the distinction between fax, modem and voice call types. TA102 takes action based on the call attributes detected according to the security policy. The VPSTN100 can operate within a continuous processing loop that includes detecting call attributes and analyzing call activity, while taking appropriate action (eg, initiating and executing a call in secure mode) according to the rules in the established security policy. )It can be performed. Management servers 106 and 108 are connected to TA 102 and 104 for reporting and call log integration and management, respectively. For a call, the attributes of the call, such as line (extension); call number (incoming source number or destination number); call direction (inbound, outbound); call type; date and time; call duration; And a call log is generated that specifies a description of the call event (for example, a secure incoming modem call to a modem group that can be received daily). Examples of reporting options include post-event analysis or batch analysis (trending) reports, and warning options include email notifications, pager warnings, console messages and SMNP trap notifications. It can be seen that the VPSTN100 can communicate with various host computers within the corporate network to perform reporting and alerting functions. A set of rules can be implemented by software instructions within TA102, which may be programmed or modified, for example, at TA102 or management server 106 and client 110 located near it, or at a location very far from the server within the enterprise. be able to.
【0033】
Further, as will be described later, the functions of the invention performed by the present invention can be realized by commercially available parts so that those skilled in the art can understand. Although not shown, TA102 and 104 are controlled by computer program instructions stored in the memory within these TA102 and 104. These program instructions may be stored in memory in other components of the VPSTN100 connected to the TA102 and 104.
【0034】
Also in Figure 1A, numbers 136 and 138 indicate end-user stations, such as one or more modems 140 and 142, fax machines 144 and 146, telephones 148 and 150, and VTC stations 149 and 151. These can send and receive calls through the VPSTN100. Modems 140 and 142 can support, for example, desktop or portable personal computers. Extensions 152 and 154 of the individual stations connect end-user stations 136 and 138 to PBX 114 and 118, respectively, or to central station (CO) 166 in the PSTN (see Figure 1B).
【0035】
For clarity and brevity, Figure 1A and subsequent figures show the complete DS-1 circuit connected between TA102 and PSTN116 and TA104, especially all 32 DS-0 channels on the E1 span. Is shown. Although common, the DS-0 channels that make up the DS-1 circuit can be exchanged separately by PSTN116 to different locations that correspond to the destination. Although all of the DS-0 circuits on the DS-1 circuit are shown herein to be processed using VPSTN100, at least one call attribute, eg call direction (inward, outbound); call Security policies can be configured to selectively apply VPSTN100 to calls based on source number; call destination number; call type; call content, date; time, call duration, and so on. Further, although voice is the medium to be transported in the examples described, the present invention can also provide secure transport for multiple media in addition to voice, including faxes, modems and VTCs. The functions of the invention described herein, such as those performed by TA102, are performed similarly by TA104.
【0036】
In addition, the system and method support the enforcement of security policies based on multi-tiered policies, as detailed in US Pat. No. 6,226,372B1. For example, a security policy mandated by a company contains basic rules for a database of security rules. These rules fall into either "required rules" or "optional rules". The required rules must have each level of the hierarchical environment, but each level can be selected to ignore the optional rules. Each level of the hierarchy can make those local rules and the rules for the hierarchy below them more stringent than the rules governed by the company, but these rules cannot be looser. In this way, the basic security structure is guaranteed throughout the enterprise.
【0037】
The security policy mandated by the company includes a basic security rule, which stipulates that any information should be reported upwards and that visibility should be provided only to the most important local security events at the company level. When sending security guidelines where company-ordered rules can be more stringent when sent up, security policies make information filters more selective when routing emails, logs, reports, etc. To configure. Company-controlled rules that are important at the local level but not at the higher level are also filtered if the task in the Track column should route notifications of satisfied rules up the hierarchy. Is specified to be. All logging is real-time, both at the top level of the organization and may or may not require event notification according to the location where the event occurs and the security policy.
【0038】
FIG. 1B is a block schematic of some 160 of the VPSTN100 example of FIG. 1A. Numbers 162 and 164 are configured to provide TA102 (and TA104) connectivity, including any combination of one or more TA162s (on the direct line from CO166) and TA164s (on the trunk side of the PBX114). Shown. TA162 and 164, management server 106 and client 110 are connected by LAN, WAN or Internet 113.
【0039】
FIG. 2 is a block schematic of the VPSTN DS-0 channel sample 1100 of the present invention. The DS-0 channel is the atomic level (minimum level) of a standard telephone call, whether the call is voice, fax, modem or VTC. As mentioned above, the DS-0 channel operates at 64000bps. The present invention is VPSTN The DS-0 channel sample 1100 is subdivided into three subrate channels. The reason for using the term subrate is that each of the three channels operates at a rate lower than the full DS-0 channel rate of 64000bps. These three subrate channels include bearer (packet payload) channel 1102, encrypted packet (EP) boundary channel 1104, and message channel 1106. Packet payload channel 1102 operates at 40000 bps DS-0 channel subrate (5 bits per sample). Each of EP boundary channel 1104 and message channel 1106 operates at a subrate of 8000 bps (1 bit per sample). These three subrate channels have increased to a rate of 56 (40 + 8 + 8) Kbps. The remaining 8 Kbps is used for the least significant bit (LSB) 1108 position. This LSB1108 is set to a high level during transmission and discarded after reception.
【0040】
The three subrate channels are assigned bit positions in sample 1100 for each VPSTN DS-0 channel, and packet payload channels 1102 are assigned bit positions 3, 4, 5, 6 and 7. Bit position 2 is assigned to EP boundary channel 1104, and bit position 1 is assigned to message channel 1106.
【0041】
Packet payload channel 1102 carries the audio signal in a compressed format. Adaptive differential pulse code modulation (ADPCM) in 5-bit mode recommended by ITU-T G.726 is used to compress the audio signal. In 5-bit mode (operating at 40Kbps), the sound quality is equal to the sound quality of the uncompressed pulse code modulation (PCM) DS-0 channel at 60Kbps (ie, toll sound quality). The 5-bit ADPCM mode is specifically designed to allow you to use ADPCM to transport voice band data modem calls at modem speeds higher than 4800 baud. The ITU has conducted extensive testing and found that the 5-bit ADPCM G.726 can operate voice band data modems for speeds up to 19200 baud. Therefore, with VPSTN100, V.90 or V.34 modems can be connected at slower speeds than was possible with DS-0 channels without VPSTN100. In addition, G3 fax transmission operates at speeds lower than 19200 baud, so using VPSTN100 should not affect fax transmission speed.
【0042】
EP boundary channel 1104 is used to create a cryptographic packet consisting of five 64-bit words (blocks). The 64-bit block size allows a 64-bit encryption / decryption engine to handle 64-bit blocks. Five 64-bit blocks of encrypted packets are 8 milliseconds long (1/125 of a second). EP boundaries are not relative to framing, eg D3 / D4 framing or extended superframe (ESF) formats.
【0043】
Message channel 1106, which is formed as a result of compressing the signal on packet payload channel 1102, is used to send messages between TA102 and 104. An extensible protocol is used to send message packets over the 8000bps channel, consistent with the encrypted packet boundaries set for packet payload channel 1102. Messages are used to set up secure calls, exchange TA capabilities, negotiate, exchange encryption keys, report errors, and control call sessions. Message channel 1106 remains active for the entire duration of the call, and this message channel is used to enter or interrupt secure mode while the call is in progress. 64-bit message packets can be subdivided into multiple fields. These fields can include packet headers, TA identification, message sequence numbers, time stamps, checksums, and so on.
【0044】
VPSTN DS-0 channel sample 1100 LSB1108 is discarded on the receive channel and set to high level (1) on the transmit channel. During transport, LSB1108 data is not used as PSTN116 may change the value of some LSB1108s. Changes in the value of LSB1108 can be caused by stolen bit signaling, transcoding (from mu rule to mu rule via A rule) or digital packet assembler / deassembler (PAD) circuits and other signal attenuation circuits. ..
【0045】
FIG. 3 is a flowchart showing the VPSTN process 1200 that makes a voice call in safe mode. Consider the following example. The president of a bank in the United States calls the Board of Audit of a bank branch in "Country X" from telephone 148, and the Board of Audit receives a call by telephone 150. The company security policy held by TA102 states the following rules: "That is, all outgoing voices, faxes, modems and VTC traffic from all extensions to destination numbers within the X country group at any time on any day. Includes the rule "encrypt, allow a call if the call cannot be secured, execute a warning message, generate an email notification, and log the call." It is necessary to follow this rule. The inability to secure a call is an indication of security attitude and is important to the upper chain of command. If the notification that a secure call cannot be made is made at each upper level of the hierarchy, the system logs the event for the occurrence of the report, but filters out the task of email notification from the upper level. The system generates an email notification that the call could not be secured and sends it only to local and country X security personnel (call source and destination).
【0046】
The VPSTN100 autonomously sets up and executes transparent and secure voice calls to both the president who initiated the call and the audit officer who received the call, in accordance with the security policy. The VPSTN100 also logs events according to its security policy and issues warnings or notifications.
【0047】
Then refer to Figure 3 (also see the elements in Figure 1A for this example). At step 1202, PSTN116 uses the usual insecure communication process for connecting the two terminals (telephones 148 and 150). When a security policy rule that requires secure communication with a country X phone number is met, the TA102 contacts the TA104 to see under what conditions a call between the two locations can be made in secure mode. ..
【0048】
At step 1204, exchange the session private key between TA102 and TA104. A unique private key generated per session by the originating TA is exchanged and used between both TA102 and TA104 for encryption and decryption of packet payload channel 1102 in each direction. This session private key exchange is done using public key exchange (PKE) on message channel 1106. Steps 1202 and 1204 take less than 3 seconds. During this time, the TA102 may send a tone or other audio message to the phone, which will be heard by both parties involved in the call.
【0049】
At step 1206, the PBX input port 120 receives unsafe DS-1 circuit data from the PBX 114. The TA102 manipulates this insecure data bitstream, compresses and encrypts it, thus producing a sample 1100 bitstream of the secure VPSTN DS-0 channel. The PSTN output port 122 sends secure DS-1 circuit data to the PSTN116, where the data is switched to the PBX118.
【0050】
At step 1208, PSTN input port 128 receives secure DS-1 circuit data from PSTN116. The TA104 manipulates a secure data stream, decrypts it, decompresses it, and thus recovers the encrypted, insecure DS-1 circuit data that was previously compressed in step 1206. The PBX output port 130 sends an unsafe DS-1 circuit data stream to the PBX 118, which sends the signal to the phone 150.
【0051】
Although not shown, the VPSTN100 operates in a continuous loop and can handle both receiving and transmitting DS-0 channel data streams at the same time. This process loop continues until the call is "hung up". PSTN116 tears down the call (lowers the hierarchy) using the normal communication process for disconnecting the two phones 148 and 150, as shown in steps 1210 and 1212.
【0052】
At step 1214, log the call event and take any other action required by the security policy, such as the occurrence of a notification.
【0053】
Figures 4A and 4B provide a comprehensive flow chart for the secure call setup process 1202 in Figure 3 to establish a secure mode function between the call source and destination prior to exchanging the session's private key. Shown (see also the elements in Figure 1A for this flowchart). In step 1302, the usual insecure method used to connect two phones through PSTN116 establishes an audio connection between phone 148, PBX114, PSTN116, PBX118, and phone 150. .. Once this audio connection is established, two insecure DS-0 channel data streams flow in full duplex between the two phones.
【0054】
The decision in step 1304 is similar to the process described in US Pat. No. 6,249,575B1 and US Pat. No. 6,226,372B1. These US patents use TA102 to detect, analyze, and compare call attributes with the rules contained in the security policy. The rule is met if all the criteria in the rule match certain attributes of the call. If the met security rules do not require the call to be made in secure mode, the call will continue to be executed in the usual unsafe way used by PSTN116 in step 1306. If at step 1304 a security rule is met that requires at least one call attribute (eg, source number, destination number, call type, call duration, etc.) to make a call in secure mode, therefore TA102 is described below. Respond to set up a secure call with the TA104 to do so.
【0055】
At step 1307, TA102 disables the PSTN echo suppressor. This echo suppressor interferes with the full-duplex transmission of data and must be disabled. Full-duplex transmission is required to send and receive encrypted data blocks synchronously by both TA102 and 104. The TA102 sends a message packet to the TA104 over the DS-0 channel (generally equal to 2025Hz) during the next x seconds to indicate that an echo suppressor disabling tone is occurring. When the TA102 receives the receipt confirmation message from the TA104, the TA102 generates a disabling tone.
【0056】
At step 1308, shortly after the improved audio settings between the two phones 148 and 150, the TA102 sends an "invitation" message packet through message channel 1106 and waits for a response. This invitation message indicates that TA102 is attempting to initiate a secure call with TA104. This invitation also displays TA102 features such as compression and encryption options.
【0057】
At step 1310, if the TA104 does not have VPSTN capability, or the destination does not have the TA104, the TA102 times out while waiting for a receipt confirmation message from the TA104. If the TA102 times out in step 1310, the TA102 interrupts the secure call setup process 1202 and responds to the failure to configure the secure call in step 1312 in accordance with the security policy.
【0058】
If the secure call setup process 1202 is interrupted, the security policy in step 1312 may require one or more of the following responses by TA102 and Management Server 106: That is, ending the call as an answer, allowing the call to continue in an unsafe mode, providing a warning tone or message to the caller to indicate that the call is unsafe, monitoring the content of the call, events. May require either logging or sending a notification to a designated individual.
【0059】
If the TA104 has VPSTN capability, this TA receives an invitation message through message channel 1106 and sends a "receipt confirmation" message, which is received by the TA102 in step 1310.
【0060】
In step 1314, additional message packets are exchanged to coordinate features such as encryption and compression algorithms that must be used for this session.
【0061】
In step 1314, TA102 and TA104 exchange messages to determine that there is a defect in the lines of the two DS-0 channels flowing between these TA102 and TA104. TA102 sends "known" frames whose contents are known to both TA102 and TA104 through packet payload channel 1102. For example, this known frame can consist of sequential counts from 0 to 63. The TA104 compares known frames received with known frames that have not changed, and did a line defect change some of the "known" frame bit values of the packet payload channel during transmission of frames from TA102 to TA104? Judge whether or not.
【0062】
If, at step 1320, TA104 determines that the bit has changed value during transmission, packet payload channel 1102 cannot support VPSTN process 1200. If this is true, TA104 sends a message packet informing TA102 that the secure call setup process 1202 will be interrupted in step 1322.
【0063】
TA102 and Management Server 106 respond to the failure to execute a call in secure mode when receiving a suspend message in accordance with the security policy in step 1312 (end call, allow call, provide alert tone or message, Monitor call content, log events, send notifications, etc.).
【0064】
If the TA104 determines in step 1320 that the bit value has not changed during transmission, a line defect check is performed on the return DS-0 channel. At step 1324, TA104 sends a "known" frame to TA102 through packet payload channel 1102. The TA102 compares the received "known" frame with the unchanged known frame to determine if the bit value has changed.
【0065】
If the TA102 determines that the bit value has changed during transmission, the TA102 interrupts the secure call setup process 1202 in step 1326. In step 1312, TA102 and Management Server 106 respond to the failure to execute a call in secure mode according to the security policy (end call, allow call, provide warning tone or message, monitor call content, log event). , Send notifications, etc.). If TA102 determines that the bit value has not changed, TA102 and 104 exchange the call session private key in step 1204.
【0066】
Figures 5A and 5B provide a comprehensive flow chart of the compression and encryption process 1206 for processing insecure DS-1 circuit data for secure transport to PSTN116. At step 1500, the TA102 receives unsafe DS-1 circuit data from the PBX114.
【0067】
In step 1502, data signals, frame signals and clock signals are extracted from the serial data stream and these signals are placed on the TDM highway. The TDM highway has 32 time slot channels clocked at 2.048 Mbps, which consists of data signals, frame signals and bit clock signals. The data signal carries a DS-0 channel data bitstream. The frame signal indicates the start of the first 8-bit time slot, sets the boundaries of the 8-bit time slot, and operates at 8 KHz. The bit clock signal synchronizes the DS-0 channel data bitstream and operates at 2.048 MHz. If the PBX input link is T1 span or J1 span, time slots 0-23 will contain 24 DS-0 channel data bitstreams, while the remaining 8 time slots will remain empty (a value). Is set to). If the PBX input link is an E1 span, each time slot will contain 30 DS-0 channel data bitstreams, while time slots 0 and 16 are reserved for signaling.
【0068】
In step 1504, the data signal serial bitstream is converted to an 8-bit wordstream. An 8-bit sample is output 256,000 times per second (once every 3.9 microseconds). In step 1506, the 8-bit word stream is compressed into a 5-bit ADPCM word stream. In step 1508, the 5-bit ADPCM word stream is demultiplexed into individual non-TDM 5-bit ADPCM word streams for each DS-0 channel (0-31).
【0069】
In step 1510, for each DS-0 channel, 64 5-bit ADPCM words are formatted into 5 64-bit plaintext blocks as required by the encryption algorithm. At step 1512, five 64-bit plaintext blocks are encrypted and output as five 64-bit encrypted text (encrypted) blocks.
【0070】
It can be seen that 625 (5 x 125) 64-bit plaintext blocks per second are encrypted / decrypted for each DS-0 channel data bitstream that requires encryption. If all of the DS-0 channel data bitstreams in the T1 or J1 span require secure communication, 15000 (24 x 625) 64-bit plaintext blocks per second are encrypted / decrypted. This rate means that one 664-bit plaintext block is encrypted / decrypted in less than 66.7 microseconds. If all of the DS-0 channel data bitstreams in the E1 span require secure communication, 18750 (30 x 5 x 125) 64-bit plaintext blocks per second are encrypted / decrypted. This rate means that one 64-bit plaintext block is encrypted / decrypted in less than 53.3 microseconds. In addition, if the TA102 handles four E1 spans and any DS-0 channel data bitstream must be secure, 75,000 (4 x 18750) 64-bit plaintext blocks per second will be encrypted / decrypted at this speed. Is equivalent to one block being encrypted / decrypted every 13.3 microseconds.
【0071】
In step 1514, five 64-bit encrypted text (encrypted) blocks for each DS-0 channel go to a 5-bit encrypted wordstream (carried on packet payload channel 1102). Formatted, 64-bit encrypted packet (EP) boundary pattern is generated and is now carried on EP boundary channel 1104), and 64-bit message packet is generated (to be carried on message channel 1106). ), The LSB serial bitstream is uploaded. The EP boundary channel is a constant 64-bit pattern that performs the crypto packet boundary function. Messages on message channel 1106 are exchanged between TA102 and TA104 as described above, setting up secure calls, exchanging TA features, negotiating, exchanging session private keys, reporting errors, etc. Do. The LSB1108 is always set to a high level to increase the density of "1" on the DS-1 circuit.
【0072】
In step 1516, for each DS-0 channel, a 5-bit encrypted wordstream, a 64-bit EP boundary pattern, a 64-bit message packet and an LSB bitstream are the serial streams of the DS-0 channel sample 1100 of VPSTN. That is, it is formatted so that it can be output as a secure DS-0 channel data bitstream).
【0073】
In step 1518, each separate secure DS-0 channel data bitstream (channels 0-31) is multiplexed into a single 2.048 Mbps TDM high weight tom slot as a secure data signal. The time slot of each encrypted DS-0 channel data bitstream on the outgoing TDM highway is the time used by the insecure DS-0 channel data bitstream on the incoming TDM highway described earlier with reference to step 1502. Same as slot. In addition to this secure data signal, frame signals and bit clock signals can also be placed on the TDM highway.
【0074】
In step 1520, the secure data signal is framed, the PSTN output port 122 sends secure DS-1 circuit data to the PSTN116, where each DS-0 channel data bitstream is destined for one or more destinations. Can be switched. Steps 1500-1520 are performed at a rate of 64000 bps.
【0075】
In most cases, 24 or 30 encrypted DS-0 channel data bitstreams in a T1, J1 or E1 span are routed to multiple locations. However, it is assumed that all T1, J1 or E1 spans (ie all DS-1 circuits) are switched between TA102 and TA104 in order to provide the following description related to the decryption and decompression process in Figures 6A and 6B. To do.
【0076】
Figures 6A and 6B comprehensively show the process flow chart of the decryption and decompression process 1208 to restore the secure DS-0 channel data bitstream to its original insecure state.
【0077】
In step 2700, TA104 receives secure DS-1 circuit data from PSTN116 on PSTN input port 128. In step 2702, secure data, frame and bit clock signals are extracted from the serial data stream and these signals are placed on the TDM highway. The TDM highway has 32 time slot channels clocked at 2.048 Mbps.
【0078】
In step 2704, the secure data signal is converted into an 8-bit encrypted word stream. This 8-bit encrypted word stream consists of an 8-bit VPSTN DS-0 channel sample 1100, which is output 256000 times per second (once every 3.9 milliseconds). In step 2706, the 8-bit encrypted word stream is demultiplexed (ie, the 32-TDM 8-bit encrypted word stream is 8 for each DS-0 channel 0-31 for each non-TDM. Separated into bit-encrypted word streams.
【0079】
In step 2708, LSB1108 of the 8-bit encrypted word stream is discarded for each channel n. Of the resulting 7-bit encrypted word stream, each of the 5 bits that make up packet payload channel 1102 is one of five 64-bit encrypted blocks for the decryption process. It is formatted in one. The single bits that make up the contents of EP Boundary Channel 1104 prove that all five of the 64-bit encrypted blocks were fully formatted and loaded for the decryption process (step 2712). To do so, it is formatted into one 64-bit block (step 2710), and the remaining final bits that make up the contents of message channel 1106 are also formatted into one 64-bit block.
【0080】
In step 2710, the 64-bit block containing the content from EP boundary channel 1104 was formatted and loaded, thus all five of the 64-bit encryption blocks were fully loaded for the decryption process. Judgment is made to prove. If the decision in step 2710 is negative, the process returns to step 2708 and continues to format and load the 7-bit word stream. If the decision in step 2710 is positive, then in step 2712 five 64-bit blocks are decrypted and thus five 64-bit plaintext (ADPCM) blocks are recovered.
【0081】
In step 2714, a 64-bit data stream that constitutes a message block is loaded into the first-in first-out (FIFO) memory buffer, and this data stream is accessed asynchronously by the TA104's host computer processing unit (CPU). In step 2716, the five 64-bit ADPCM blocks output from the decryption process are formatted into a 5-bit ADPCM word stream. In step 2718, the 5-bit ADPCM word stream from each DS-0 channel (0-31) is time-divided multiplexed into a TDM 5-bit ADPCM word stream and then converted to a TDM 8-bit Mu-law PCM word stream. ..
【0082】
In step 2720, the TDM 8-bit Mu-law PCM wordstream is converted to a TDM serial bitstream (data signal) and placed on the TDM highway along with the frame and bitclock signals. In step 2722, the data signal is framed and the PBX output port 130 sends the TDM unsafe DS-1 circuit data to the PBX 118.
【0083】
Examples that combine the operations and functions of the communication firewall shown and described in US Pat. No. 6,249,575B1 with the operations and functions of the VPSTN100 and at the same time act as a firewall with the VPSTN100 or consist of a combination of functions of each device. Can be conceived for a number of embodiments, including those described above. For example, the VPSTN100 can be captured by a computer's Telephony Integration (CTI) interface to a particular PBX114. In this other embodiment, the VPSTN100 can instruct the PBX114 (via the CTI interface) to perform the specified action on the call. In addition, the PBX 114 may provide the call attributes specified to the VPSTN100 (via the CTI interface) for use in applying a set of security rules to the call. The action commands issued to the PBX 114 and the call attributes provided by the PBX 114 follow a set of rules and are within the functionality of the PBX 114.
【0084】
Another such embodiment is similar to the integrated communications firewall and scanner implemented as described in US Pat. No. 6,226,372B1, in which the communications firewall is at least in accordance with the security policy. The VPSTN100 can be tasked with building a virtual personal exchange communication network between at least two inline devices based on one given call attribute.
【0085】
It can be understood that the present invention can take many forms and examples. It can be understood that the examples shown in the present specification are not for limiting the present invention but for explaining the present invention, and various modifications can be made without departing from the gist of the present invention. Yeah. You can set the standard for any number of different rules, for example for a security policy. Descriptions of different attributes and rules can also be conceived. The algorithms and process functions performed by the system can be configured in any number of different modules or computer programs to run on one or more processors or workstations in the system.
【0086】
You can come up with different computer and processor configurations for your system, including configurations that allow you to insert management server functionality into your system at TA. The programs used to implement the methods and processes of the system can be implemented in the appropriate programming language and can work in conjunction with hardware devices. Small businesses such as private homes or businesses with only a few lines, as well as large businesses with multiple PBX locations around the world interconnected within one or more personal or virtual personal networks You can also use this system for. It can be seen that in cases where a large number of extensions are involved, the extension may be a PBX extension or a direct extension.
【0087】
Examples have been shown and described above for the description of the present invention, but in the description so far, various encryption engines, encryption algorithms, compression algorithms, various resulting word block sizes and packet payload channels 1102, Extensive modifications, modifications and modifications, including various structures in the installation of encrypted packet boundary channels 1104 and DS-0 channel sample 1100 (ie following the payload channel, preceding the packet payload channel and sandwiching the packet payload channel). You can see that the replacement is possible. In certain cases, some features of the invention are utilized without corresponding use of another feature. Therefore, it is appropriate to consider the claims broadly and consistently with the scope of the present invention.
[Simple explanation of drawings]
[Fig. 1A]
It is a block schematic which shows an example of the virtual personal exchange communication network of this invention.
[Fig. 1B]
It is a block schematic which shows an example of the virtual personal exchange communication network of FIG. 1A.
[Figure 2]
It is a block diagram of a sample of a digital signal level 0 (DS-0) channel of a virtual personal exchange communication network.
[Fig. 3]
It is a process flowchart which shows execution of a call in a safe mode by a virtual personal exchange communication network.
[Fig. 4A]
It is a process flowchart which shows the setting for a secure call.
[Fig. 4B]
It is a process flowchart which shows the setting for a secure call.
[Fig. 5A]
A process flow chart showing compression and encryption of insecure digital signal level 1 (DS-1) circuit data for secure transport.
[Fig. 5B]
It is a process flow chart showing compression and encryption for securely transporting insecure digital signal level 1 (DS-1) circuit data.
[Fig. 6A]
A process flow chart showing cryptanalysis and decompression to restore secure digital signal level 1 (DS-1) circuit data to its original insecure state.
[Fig. 6B]
A process flow chart showing cryptanalysis and decompression to restore secure digital signal level 1 (DS-1) circuit data to its original insecure state.
52 members in 9 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 09709592 | United States of America | – | |
| 70959200 | United States of America | A | |
| 70959200 | United States of America | A | |
| 0150885 | United States of America | W | |
| 0150885 | United States of America | W | |
| 2000709592 | – | – | – |
| 200150885 | – | – | – |
| US20000709592 | – | – | – |
| WO2001US50885 | – | – | – |
Members52
| Document | Office | Kind | |
|---|---|---|---|
| CA2354149A1 | Canada | A1 | |
| WO0035172A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU6161699A | Australia | A | |
| US6226372B1 | United States of America | B1 | |
| WO0143343A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU1950301A | Australia | A | |
| US6249575B1 | United States of America | B1 | |
| US2001014150A1 | United States of America | A1 | |
| EP1138144A1 | European Patent Office (EPO) | A1 | |
| KR20010101174A | Republic of Korea | A | |
| CA2308808A1 | Canada | A1 | |
| US6320948B1 | United States of America | B1 | |
| US2002021791A1 | United States of America | A1 | |
| CA2321420A1 | Canada | A1 | |
| US2002090073A1 | United States of America | A1 | |
| CA2428472A1 | Canada | A1 | |
| WO02073945A1 | World Intellectual Property Organization (WIPO) | A1 | |
| JP2002532967A | Japan | A | |
| US2003016803A1 | United States of America | A1 | |
| WO03009573A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO03010946A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2003112940A1 | United States of America | A1 | |
| EP1332606A1 | European Patent Office (EPO) | A1 | |
| US6687353B1 | United States of America | B1 | |
| US6700964B2 | United States of America | B2 | |
| US6718024B1 | United States of America | B1 | |
| EP1415459A1 | European Patent Office (EPO) | A1 | |
| US6735291B1 | United States of America | B1 | |
| JP2004519929AThis record | Japan | A | |
| US6760420B2 | United States of America | B2 | |
| US6760421B2 | United States of America | B2 | |
| US2004161086A1 | United States of America | A1 | |
| WO2004075515A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2004218742A1 | United States of America | A1 | |
| US2004234056A1 | United States of America | A1 | |
| CA2354149C | Canada | C | |
| EP1138144A4 | European Patent Office (EPO) | A4 | |
| US2005025302A1 | United States of America | A1 | |
| CA2438976A1 | Canada | A1 | |
| US2005047570A1 | United States of America | A1 | |
| US6879671B2 | United States of America | B2 | |
| WO2004075515A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US7133511B2 | United States of America | B2 | |
| EP1415459A4 | European Patent Office (EPO) | A4 | |
| US2007127448A1 | United States of America | A1 | |
| US7231027B2 | United States of America | B2 | |
| US7440558B2 | United States of America | B2 | |
| EP1415459B1 | European Patent Office (EPO) | B1 | |
| AT471627T | Austria | T | |
| ATE471627T1 | Austria | T1 | |
| DE60236734D1 | Germany | D1 | |
| US8150013B2 | United States of America | B2 |
Numbers
- Publication
- 2004519929
- Publication, DOCDB
- 2004519929
- Publication, EPODOC
- JP2004519929
- Application
- 2002571692
- Application, DOCDB
- 2002571692
- Application, EPODOC
- JP20020571692
Titles2
- Japanese
- PCMデータのカプセル化、圧縮化および暗号化
- English
- Encapsulation, compression and encryption of PCM data
Classification
- CPC, 13
- H04L63/0218
- H04L63/0263
- H04L63/1408
- H04L63/20
- H04M3/22
- H04M3/2218
- H04M3/38
- H04M3/42314
- H04M3/436
- H04M7/0078
- H04M7/009
- H04M2203/2066
- H04M2203/609
- IPC, 8
- H04M3 42
- H04L29 06
- H04M3 00
- H04M3 22
- H04M3 38
- H04M3 436
- H04M7 00
- H04M11 00
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo