WO2016193135A1

Systems and methods for conducting secure voip multi-party calls

Abstract

System and method for establishing secure conference calls. In one example system, a central conference call server establishes point-to-point connections with accessory devices comprising a secure element and connected to corresponding participant devices. The conference call server includes an interface to a plurality of secure elements configured to perform scrambling and unscrambling of media signals communicated to and from the accessory devices. In another example, one of the participant devices operates as the central conference call server. In other examples, participant devices communicate on a conference call via point-to-point connections between all accessory devices connected to the participant devices. The accessory devices include secure elements for decryption and encryption of media signals communicated between the accessory devices.

WO2016193135A1, drawing sheet 1
Sheet 1 of 4

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 6 independent, 9 dependent

  1. 1
    CLAIMS What is claimed is:1. A method for performing a conference call on a server, the method comprising: receiving an inbound communication from each of a plurality of participant devices in a conference call communication, each of the plurality of participant devices comprising a connection to an accessory device having a secure element configured to scramble and unscramble audio signals using participant key information stored therein, the inbound communication comprising scrambled media signals communicated from the accessory device at a participant endpoint of a secure media session and relayed by the participant device;relaying the scrambled media signals from each inbound communication to a cryptographic interface with a plurality of server secure elements configured to unscramble and scramble audio signals at a server side endpoint of the secure media session with a corresponding one of the plurality of accessory devices using server key information maintained by the server secure element and not accessible by the server;receiving an audio signal from the cryptographic interface generated by each of the plurality of server secure elements from each scrambled media signal received in the media sessions with the plurality of participant devices;mixing the plurality of audio signals to generate conference call data to be communicated to all users as a mixed audio signal;providing the mixed audio signal to the cryptographic interface for each of the plurality of server secure elements to scramble the mixed audio signal to generate a plurality of outbound scrambled media signals;and communicating the outbound scrambled media signals as outbound communications to each of the plurality of participant devices.
  2. 5
    The method of any of the claims 1 -4, further comprising:receiving a request for a global key from one of the participant devices for participation in conference call conducted using the conference call server;retrieving the global key from a key management database;and sending the global key to the requesting participant device.
  3. 8
    A conference call server comprising:a communication interface configured to communicate over a data network with a plurality of participant devices, each participant device connected to an accessory device having audio input and output devices and a participant secure element for maintaining participant key information, where the communication interface communicates scrambled audio signals with each accessory device on a corresponding secure media session relayed by the associated participant device;a cryptographic interface connected to a plurality of server secure elements configured to scramble and unscramble audio signals communicated with the accessory devices connected to corresponding participant devices using server key information stored therein;and an audio mixer to mix audio signals from incoming scrambled audio signals unscrambled by the server secure element corresponding to the accessory devices connected to the plurality of participant devices to generate conference call data to be communicated to the users in the conference call as a mixed audio signal to provide to the cryptographic interface;wherein the cryptographic interface generates a scrambled mixed audio signal provided by each server secure element to communicate via the communication interface to each participant device to relay to its associated accessory device.
  4. 11
    The conference call server of any of the claims 9-10, wherein the hardware interface to the plurality of server secure elements is selected from a group consisting of:smart card interface, ball grid array ("BGA") interface, a surface mount device ("SMD") interface, and a printed circuit board interface.
  5. 12
    The conference call server of any of the claims 8-11 , wherein the server key information in each server secure element comprises a server encryption key and a server decryption key generated using a key exchange method performed during initiation of the scrambled media session using key information received from the participant secure element in the accessory device connected in the media session with the server secure element, where the server decryption key is used to unscramble the scrambled audio signals from the corresponding accessory device and the server encryption key is used to scramble the mixed audio signal for unscrambling by the corresponding accessory device.
  6. 13
    The conference call server of any of the claims 8-12, further comprising:a participant device authentication module to authenticate a global participant key provided by the participant device during initiation of a secure connection to the conference call server, wherein the participant device authentication module is configured to validate one or both of (i) a date and time associated with the global participant key and (ii) a segment key provided by the participant device during initiation of the secure connection to the conference call server, the segment key indicative of a group identity of the user of the participant device.