WO2016193404A1

Methods and systems for communication-session arrangement on behalf of cryptographic endpoints

Abstract

In an embodiment, a communication device receives a request to establish a media session with a remote endpoint. In response to receiving the request, the communication device exchanges media-session control data with the remote endpoint on behalf of a local endpoint to establish the requested media session between the local endpoint and the remote endpoint. The communication device is communicatively connected to the local endpoint via a Personal Area Network (PAN) communication link. The communication device relays media-session payload data between the local and remote endpoints. The media-session payload data (i) is associated with the media session and (ii) is encrypted based on at least one payload-data cryptographic key that is not accessible to the communication device.

WO2016193404A1, drawing sheet 1
Sheet 1 of 5

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

15 claims: 10 independent, 5 dependent

  1. 1
    CLAIMS 1. A method comprising:a communication device receiving a request to establish a media session with a remote endpoint;in response to receiving the request, the communication device exchanging media- session control data with the remote endpoint on behalf of a local endpoint to establish the requested media session between the local endpoint and the remote endpoint, wherein the communication device is communicatively connected to the local endpoint via a Personal Area Network (PAN) communication link;and the communication device relaying media-session payload data between the local and remote endpoints, wherein the media-session payload data (i) is associated with the media session and (ii) is encrypted based on at least one payload-data cryptographic key that is not accessible to the communication device.
  2. 3
    The method of any of the claims 1-2, wherein the media-session control data comprises a second cryptographic key.
  3. 6
    The method of any of the claims 1-5, wherein the media-session control data comprises media-session key-exchange data.
  4. 7
    The method of any of the claims 1-6, wherein the media-session control data comprises a digital signature.
  5. 9
    The method of any of the claims 7-8, wherein the digital signature comprises a digital signature generated by a trusted third party.
  6. 10
    The method of any of the claims 7-9, wherein:the received media-session control data further comprises a second cryptographic key;and the digital signature is based on the second cryptographic key.
  7. 11
    The method of any of the claims 1-10, wherein the media-session control data comprises one or more of (i) Session Initial Protocol (SIP) data, (ii) ZRTP data, (iii) Secure Real-time Transport Protocol (SRTP) data, and (iv) Session Description Protocol (SDP) data.
  8. 12
    The method of any of the claims 1-11, wherein:relaying the media-session payload data comprises relaying media-session payload data that includes both the media-session payload data and a digital signature that is based on the media-session payload data;and the digital signature comprises a digital signature generated by the remote endpoint based on the media-session payload data.
  9. 13
    The method of any of the claims 1-12, wherein:the PAN communication link comprises a Bluetooth communication link;relaying the media-session payload data comprises relaying the media-session payload data between the local endpoint and the communication device via the Bluetooth communication link according to a first Bluetooth profile;and the first Bluetooth profile comprises a Serial Port Profile (SPP).
  10. 15
    A communication device comprising :a communication interface;a processor;and data storage containing instructions executable by the processor for causing the communication device to carry out a set of functions, the set of functions comprising: a communication device receiving a request to establish a media session with a remote endpoint;in response to receiving the request, the communication device exchanging media-session control data with the remote endpoint on behalf of a local endpoint to establish the requested media session between the local endpoint and the remote endpoint, wherein the communication device is communicatively connected to the local endpoint via a Personal Area Network (PAN) communication link;and the communication device relaying media-session payload data between the local and remote endpoints, wherein the media-session payload data (i) is associated with the media session and (ii) is encrypted based on at least one payload-data cryptographic key that is not accessible to the communication device.