Security module for encrypting a telephone conversation
Abstract
The invention relates to a security module (SM) for encrypting a telephone conversation between one or several first telecommunication terminals (VoIP-C) in a packet oriented data network (IP-LAN) and telecommunication terminals (TDM-C) in an analog and/or digital telephone network (TDM). Said module enables the use of protocols (MIKEY; SRTP) from the LAN network to the TDM network in order to carry out an end-to-end encryption.

Term
No projected expiry on record.
- Priority
- Filed
- Published
- Today
10 claims: 7 independent, 3 dependent
- 1Claims 1. Security module for encrypting a telephone conversation between one or more first telecommunication terminals (VoIP-C) in a packet-oriented data network (LAN) and one or more second telecommunication terminals (TDM-C) in an analogue and / or digital telephone network (TDM), wherein in the packet-oriented network (LAN) data packets are transported by means of an encrypted transport protocol and the keys for the encrypted transport protocol are exchanged by means of a key exchange protocol, the packet-oriented network (LAN) and the telephone network (TDM) being connected to one another via an access computer (G), and the security module (SM) being connected to a first or second telecommunication terminal (VoIP-C; TDM-C) during a telephone conversation. can be interposed, comprising:a protocol processing device, which messages of the key exchange protocol and data packets transported by means of the encrypted transport protocol are processed, if the security module (SM) is interposed during a telephone conversation in a connection line at a first or second telecommunications terminal (VoIP-C;TDM-C), wherein the protocol processing device converts voice signals generated at the first or second telecommunication terminal (VoIP-C;TDM-C) into data packets for transport via the encrypted transport protocol and data packets arriving at the security module, which are transported via the encrypted transport protocol, converted into speech signals;a modem connection unit, which in case if the security module (SM) is interposed in a connecting line at a second telecommunication terminal (TDM-C), establishes a modem connection between the second telecommunication terminal and the access computer (G) and / or a further second telecommunication terminal (TDM-C) during a telephone conversation, wherein via the modem connection, the data packets are transported by means of the encrypted transport protocol and messages of the key exchange protocol.
- 44th Security module according to one of the preceding claims, wherein the key exchange protocol MIKEY (= Multimedia Internet Keying) is.
- 55th Security module according to one of the preceding claims, wherein the security module (SM) is configured such that in a telephone conversation messages of the key exchange protocol via the SIP protocol (SIP = Session Initiation Protocol) are transported, and the protocol processing means the SIP protocol can handle.
- 66th Security module according to one of the preceding claims, in which the telephone network (TDM) is an ISDN network.
- 88th. Security module according to one of the preceding claims, in which the packet-oriented network is an IP-based data network, in particular a LAN network (LAN = Local Area Network).
- 99th Security module according to one of the preceding claims, wherein the modem connection unit can establish a modem connection according to the V90 and / or V92 standard.
- 1010th Security module according to one of the preceding claims, which is used for telephones with a connection cable between telephone and telephone handset, wherein the security module (SM) is designed such that it is interposed in the connecting cable.
Independent claims7
31 paragraphs, as filed
p0001description
p0002Security module to encrypt a telephone conversation
p0003The invention relates to a security module for encrypting a call between one or more first telecommunication terminals in a packet-oriented data network and one or more second telecommunication terminals in an analog and / or digital telephone network.
p0004telephony in IP networks is known from the prior art. There are now standards, in which the signaling for telephony in IP networks is defined. It is to the IETF standard SIP and the ITU H.323 standard, also known as "Voice over IP" (VoIP) are designated and mainly in wired or wireless based networks are used (LAN = Local Area Network, WLAN = Wireless Local Area Network). When VoIP telephony to date safety aspects with regard to the authenticity and integrity of control and signaling were mainly considered approximate data. In future solutions in addition to pure signaling security and the security of the transmitted voice data is taken into account. To secure voice data in IP networks is for example the encrypted transport protocol (SRTP SRTP Secure Real Time Transport Protocol, see document [1]) into consideration.
p0005With the current security solutions but only a backup of voice data is ensured in packet-oriented networks. Although there are also security solutions for telephony in public telephone networks, but until today there is no possibility of telephone calls from a packet-switched network to a public telephone network is encrypted perform.
p0006The object of the invention is therefore to provide a security module to encrypt a telephone conversation, which comprising allow encryption of voice data in a heterogeneous network a packet-oriented data network and a telephone network.
p0007This object is solved by the independent claims. Further developments of the invention are defined in the dependent claims.
p0008The security module according to the invention is used to encrypt a telephone conversation between one or more first telecommunication terminals in a packet-oriented data network and one or more second telecommunication terminals in an analog and / or digital telephone network, data packets are transported via an encrypted transport protocol in the packet-oriented network and the key for the encrypted transport protocol to be replaced by a key exchange protocol. Below is understood (Public Switched Telephone Network PSTN) under a telephone network any kind of public PSTN network, which may be either an analog and a digital telephone network. The packet-switched network and the telephone network here are interconnected via an access server and the security module may be interposed in a phone call in a connecting line to a first or second telecommunication terminal. The term "connecting line" here is generally understood, it can be both a wired and a wireless connection to the respective telecommunication terminal.
p0009The security module according to the invention comprises a protocol processing means, which messages the key exchange protocol and using the encrypted transport protocol transported data packets processed when the security module onsendgerät in a phone call in a connecting line to a first or second telecommunication interposed. Object of Protokollver- processing device is to convert speech signals, which are generated at the respective telecommunication terminal into data packets for transport over the encrypted transport protocol and convert to the security module incoming data packets that are transported over the encrypted transport protocol into voice signals.
p0010The security module further includes a modem connection uniform, which always is used, if that's See r- interposed integrated module in a connecting line to a second telecommunications terminal. In this case, the modem unit is built in a phone call a modem connection between the second telecommunication terminal and the access computer and / or another such "one th telecommunications terminal to which are transported via the modem data packets by means of the encrypted transport protocol and message of the key exchange protocol . Preferably, runs over the modem connection, a PPP connection (PPP = Point to Point Protocol), with which the data packets of the transport protocol and the
p0011News of the key exchange protocol to be transported. a transfer of encryption technologies from packet-oriented networks is thus realized in public telephone networks through the modem connection unit in the security module. This is possible because modem connections have now sufficient bandwidth or transmission rates for transmission of real-time media data packets.
p0012In a particularly preferred embodiment, the irer--encrypted transport protocol (SRTP, see document [1]) is used. To replace the key used in the encrypted transport protocol, preferably the key Autausch protocol MIKEY is (= Multimedia Internet Keying) used. MIKEY is currently a draft in the IETF, which will be explained in the foreseeable future to Standard. In a further embodiment of the security module messages of key exchange protocol over the method known from the prior art SIP protocol are in a phone call (SIP = Session Initiation Protocol) transport, the protocol processing means of the security module is configured such that they present Protocol can handle.
p0013The telephone network, in the security module of the invention is used is, for example, a digital ISDN network. Preferably, the modem connection unit building on a modem connection via the B channel in the ISDN network. In the packet-oriented network, it is preferably an IP-based data network, in particular a LAN network. The modem connection unit is preferably establishes a modem connection to the V90 and / or V92 standard, this standard provides sufficient bandwidth or transmission rate for the transmission of data packets from packet-oriented networks.
p0014In a variant of the invention, the security module for phones used with a cable connection between the telephone set and telephone receiver, wherein the security module is designed such that it is switched on intermediately in the connecting cable.
p0015Embodiments of the invention will be described below with reference to the accompanying drawings.
p0016It shows
p0017Figure 1 is the schematic diagram of a heterogeneous network in which the security module according to the invention for encrypting speech signals is used. The heterogeneous network shown in Figure 1 includes firstly an IP-based local area network (LAN Local Area Network) and a public TDM telephone network (TDM = Time Division Multiplexing). In the TDM network is a digital network, however, for the transmission of speech, a separate analog voice channel is used. The LAN and the TDM network are connected to each other via a gateway G. The gateway is used to modify transmitted in the LAN IP data packets for transmission in the TDM network and data corresponding to from the TDM network for forwarding in the LAN network.
p0018In LAN, two so-called VoIP clients VoIP C which loan enables telephoning over packet-oriented networks are. While talking via "Voice over IP" can be used for H.323 signaling voice messages to the expert well-known standards or SIP. The lower VoIP client in FIG. 1 is a phone with which the structure of an encrypted telephone call is intended. Therefore, between the receiver of the telephone and the actual telephone in the corresponding link<sup>¬</sup> line the security module SM invention interposed.
p0019In the TDM network of Figure 1 are exemplary two TDM
p0020Clients TDM C shown in the form of telephones, which encrypted telephone calls can also be performed. Therefore, the security module SM according to the invention is interposed also in these phones between the receiver and the actual telephone set in the connecting line.
p0021The processes known from the prior art security modules allow encrypt the phone call only within the TDM network, each telephone call party to establish an encrypted telephone link by pressing a button on his security module generates a single key, which via a proprietary signaling Protocol between telephones of Gesprächsteilneri- exchanged mer. Finally, each combination of numbers nations are on display, which are integrated into the security modules, indicated that by saying the callers GE mutually via the telephone connection. If the number combinations match can be assumed that the connection of any third party is listening. So that with the help of the exchanged key finally the encrypted data transmission takes place, for which purpose, in turn, a proprietary protocol is used. Experi<sup>¬</sup> ments have shown that the traditional security modules not encrypted telephone calls between a telephone in a packet-oriented network and a telephone can be done in a TDM network. This results from the fact that in packet-oriented networks, the data is transferred asynchronously, leading to bandwidth fluctuations (also referred to as "jitter") may result which can not be processed by conventional security modules. Also occurring packet loss result in packet-oriented networks with traditional safety modules to problems.
p0022The security module according to the embodiment described herein solves this problem in that it can process well-known protocols to encrypt data in a normal public TDM network from the IP world. For this purpose, a protocol processing means is provided in the security module, which can process the encrypted Transportprotokoil SRTP (SRTP Secure Real Time Protocol). This protocol is expected in the future as a standard. used for encrypted transmission of media data.
p0023Moreover, the protocol processing means processing the key exchange protocol MIKEY. This protocol keys are generated and exchanged between clients or telephones in the heterogeneous network in FIG. 1. The keys are here used by the transport protocol SRTP for encrypted transmission of data packets using SRTP. The protocol allows processing device like encrypted telephony between VoIP clients on the LAN network. This is shown in Figure 1 with the double arrows MIKEY-KM (KM stands for Key Management) and SRTP-MS (MS stands for Media Security) shown.
p0024To establish an encrypted connection between telephone subscribers in the TDM network or between a subscriber in the LAN network and a subscriber in TDM network, the security module on a modem connection unit. This modem connection unit provides a long call, a
p0025Participant in TDM network to a subscriber in a modem connection over a voice channel in the TDM network to the gateway G forth LAN network. Preferably, here a V92 modem connection, with the data at 56 kbit / s downstream and can be transferred 48 kbit / s upstream. Using this connection, another connection using the PPP protocol (PPP = Point to Point Protocol) is provided, wherein the latter transported over data in the key-exchange protocol MIKEY or the SRTP protocol. Since these logs can be processed by the protocol processing means in the security module, thus migration of the protocols from the LAN network to the TDM network is made possible.
p0026The MIKEY messages are transported in the LAN network, for example via the SIP protocol. In Gateway, the contents of the MIKEY messages can then be excised from the SIP message and added to the PPP Tunnel. It would also be conceivable that the gateway SIP messages simply continue to send the PPP Tunnel, without cutting out the MIKEY- messages. In such a case, the protocol processing means of the security module must be able to process the SIP protocol. Thus, a solution is also conceivable, in which the security module acts as a SIP endpoint. With regard to the data that is transported over the SRTP protocol, the gateway accepts G le<sup>¬</sup> diglich a forwarding function and changed the data not. The also applies to the actual key exchange data in the form of MIKEY messages. If necessary, however, the gateway can also be included as a trusted component in the compound so as to facilitate, for example to "Lawful home terception".
p0027The arrows at the bottom of Figure 1, the mechanism of the invention is further clarified. The p-IP designated double arrow (p = IP piain IP) is high- lighted that for a purely IP-based encrypted data transmission between a VoIP Client VoIP C and Gateway G is used. In contrast, uses a modem connection between the gateway G and a TDM-TDM Client C for encrypted data transport over which the PPP protocol is running, turn IP data packets are transported by. This is d hrough the double arrow IP PPP TDM clarified. Despite these different connection mechanisms between a client in the LAN network and a client in a TDM network end-to-end encryption using the key-exchange protocol MIKEY and SRTP
p0028Transport Protocol SRTP achieved. This is highlighted by the double arrows labeled MIKEY-KM and SRTP-MS.
p0029The security module according to the invention therefore makes it possible to easily transfer known in the world of IP encryption protocols in a public telephone network. This is ensured through a modem connection, which enables the transport of real-time data packets and signaling messages from the IP world due to its nowadays possible bandwidth or transmission rates. Bibliography :
p0030[1] Internet Draft: The Secure Real-time Transport Protocol; Baugher, McGrew, Oran, Blom, Carrara, Naslund, Norrman; Work in Progress; http://search.ietf.org/internet- drafts / draft-ietf-avt-srtp-09.txt
p0031[2] Internet Draft: MIKEY: Multimedia Internet Keying; J. Arkko, E. Carrara, F. Lindholm, M. Naslund, K. Norrman; Work in Progress; http://search.ietf.org/internet- drafts / draft-ietf-msec-mikey-07th txt
1 sheet
Sheet 1
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| WO2007059944A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| WO2009048259A2 | Cited by | World Intellectual Property Organization (WIPO) | – | Search report | – |
| WO2005069940A2 | Cited by | World Intellectual Property Organization (WIPO) | – | Applicant | – |
| US8428559B2 | Cited by | United States of America | – | Applicant | – |
| WO2009048259A3 | Cited by | World Intellectual Property Organization (WIPO) | – | International search | – |
| EP1738508A4 | Cited by | European Patent Office (EPO) | – | Search report | – |
| EP1738508A2 | Cited by | European Patent Office (EPO) | – | Search report | – |
| US5778071A | Cites | United States of America | A | International search | 1-10 |
| US5778071A | Cites | United States of America | A | International search | 1-10 |
| US6356638B1 | Cites | United States of America | Y | International search | 1-10 |
| US6584562B1 | Cites | United States of America | A | International search | 1-10 |
| US6584562B1 | Cites | United States of America | A | International search | 1-10 |
| SCHNEIER B: "APPLIED CRYPTOGRAPHY, PROTOCOLS, ALGORITHMS, AND SOURCE CODE IN C", JOHN WILEY & SONS, 1996, NEW YORK, US, XP002322926, ISBN: 0-471-11709-9 | Non-patent | – | – | International search | – |
| LU W P ET AL: "SECURE COMMUNICATION IN INTERNET ENVIRONMENTS: A HIERARCHICAL KEY MANAGEMENT SCHEME FOR END-TO-END ENCRYPTION", IEEE TRANSACTIONS ON COMMUNICATIONS, IEEE INC. NEW YORK, US, vol. 37, no. 10, 1 October 1989 (1989-10-01), pages 1014 - 1023, XP000070200, ISSN: 0090-6778 | Non-patent | – | – | International search | – |
| TANENBAUM A S: "COMPUTER NETWORKS, PASSAGE", COMPUTER NETWORKS, LONDON : PRENTICE-HALL INTERNATIONAL, GB, 1996, XP002322927, ISBN: 0-13-394248-1 | Non-patent | – | – | International search | – |
| DUTTA A ET AL: "Realizing mobile wireless Internet telephony and streaming multimedia testbed", COMPUTER COMMUNICATIONS, ELSEVIER SCIENCE PUBLISHERS BV, AMSTERDAM, NL, vol. 27, no. 8, May 2004 (2004-05-01), pages 725 - 738, XP004501203, ISSN: 0140-3664 | Non-patent | – | – | International search | – |
| HYUN WOOK ET AL: "Study on robust billing mechanism for SIP-based internet telephony services", ADVANCED COMMUNICATION TECHNOLOGY, 2004. THE 6TH INTERNATIONAL CONFERENCE ON PHOENIX PARK, KOREA FEB. 9-11, 2004, PISCATAWAY, NJ, USA,IEEE, vol. 2, 9 February 2004 (2004-02-09), pages 756 - 759, XP010702560, ISBN: 89-5519-119-7 | Non-patent | – | – | International search | – |
8 members in 5 offices; this record represents the family
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 10355418 | Germany | A | |
| DE2003155418 | – | – | – |
| 103554181 | – | – | – |
Members8
| Document | Office | Kind | |
|---|---|---|---|
| WO2005053290A1This record | World Intellectual Property Organization (WIPO) | A1 | |
| DE10355418A1 | Germany | A1 | |
| EP1687962A1 | European Patent Office (EPO) | A1 | |
| CN1886974A | China | A | |
| US2007121582A1 | United States of America | A1 | |
| DE10355418B4 | Germany | B4 | |
| CN100459620C | China | C | |
| US8195958B2 | United States of America | B2 |
11 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Non-entry into the national phaseNENP | NENP | DE | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Wipo information: withdrawn in national officeWithdrawnWWW | WWW | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO |
Numbers
- Publication
- 2005/053290
- Publication, DOCDB
- 2005053290
- Publication, EPODOC
- WO2005053290
- Application
- 52885
- Application, DOCDB
- 2004052885
- Application, EPODOC
- WO2004EP52885
Titles3
- German
- SICHERHEITSMODUL ZUM VERSCHLÜSSELN EINES TELEFONGESPRÄCHS
- English
- SECURITY MODULE FOR ENCRYPTING A TELEPHONE CONVERSATION
- French
- MODULE DE SECURITE POUR LE CRYPTAGE D'UNE CONVERSATION TELEPHONIQUE
Classification
- CPC, 8
- H04L63/0428
- H04K1/00
- H04L9/0844
- H04L63/061
- H04M1/2535
- H04M7/0078
- H04M7/1205
- H04M2203/609
- IPC, 5
- H04K1 00
- H04L9 08
- H04L29 06
- H04M1 253
- H04M7 00
Designated states4
- Regional, 4
- Zimbabwe
- Turkmenistan
- Türkiye
- Togo