WO0045539A1

Key management for telephone calls to protect signaling and call packets between cta's

Abstract

A system for establishing a secure communication channel between a first user (102) and a second user (112) in an IP telephony network. The first user and the second user are coupled to first (104) and second (114) telephony adapters, which in turn, are coupled to first (106) and second (116) gateway controllers, respectively, wherein the gateway controllers control user access to the IP telephony network. The telephony adapters are used to encrypt and decrypt user information exchanged over the IP telephony network. The system includes a method which begins when a request is received at the first gateway controller to establish a secure communication channel between the first user and the second user. Next, a secret key (408) is generated at the first gateway controller. A copy of the secret key is distributed to the first and second telephony adapters over previously established secure connections. Finally, the secure communication channel is established (422) between the first user and the second user by encrypting and decrypting information using the secret key.

WO0045539A1, drawing sheet 1
Sheet 1 of 5

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

10 claims: 3 independent, 7 dependent

  1. 1
    WHAT IS CLAIMED IS:L A method for establishing a secure communication channel in an IP telephony network between a first and a second user, wherein the first user and the second user are coupled to first and second telephony adapters, which in turn, are coupled to first and second gateway controllers, respectively, wherein the gateway controllers control user access to the IP telephony network, and wherein the telephony adapters encrypt and decrypt user information exchanged over the IP telephony network, the method comprising: receiving a request at the first gateway controller to establish a secure communication channel between the first user and the second user;generating a secret key at the first gateway controller;distributing the secret key to the first and second telephony adapters over previously established secure connections;and establishing the secure communication channel between the first user and the second user by encrypting and decrypting information using the secret key.
  2. 6
    An IP telephony network for establishing a secure communication channel between a first user and a second user, wherein the first user and the second user are coupled to first and second telephony adapters, which in turn, are coupled to first and second gateway controllers, respectively, wherein the gateway controllers control user access to an IP telephony backbone, and wherein the telephony adapters encrypt and decrypt user information exchanged over the IP telephony network, the IP telephony network comprising:means for receiving a request at the first gateway controller to establish a secure communication channel between the first user and the second user;means for generating a secret key at the first gateway controller;means for distributing the secret key to the first and second telephony adapters over a previously established secure connection;and means for establishing the secure communication channel between the first user and the second user by encrypting and decrypting information using the secret key.
  3. 7
    A gateway controller for establishing a secure communication channel in an IP telephony network, the gateway controller coupled between a telephony adapter and a telephony network backbone, the gateway controller comprising:a key creation module having logic to create a secret key;a key storage module coupled to the key creation module and having logic to store the secret key;and a message processor coupled to the key creation module and the key storage module, and having logic to process messages exchanged between the telephony adapter and the telephony network backbone, wherein the message processor further comprises: logic to receive a request to establish a secure communication channel between a first user and a second user, the first user couple to the telephony adapter, the second user coupled to a remote telephony adapter;logic to distributed the secret key to the telephony adapters over previously established secure connections, whereby the secure communication channel between the first user and the second user may be established by encrypting and decrypting information using the secret key.