IP Library Granted Patent US 7,461,398
Granted Patent B2
US 7,461,398 · App. 10/970,552 · Granted Dec 2, 2008

Methods, systems, and computer program products for dynamic management of security parameters during a communications session

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,461,398
App. No.
10/970,552
Granted
Dec 2, 2008
Kind
B2
Abstract

A method of managing security parameters for a communications session includes dynamically assigning security parameters during the communications session responsive to changing aspects of the communications session to provide a variable degree of security for the session. Related systems and computer program products are also discussed.

Claims (27)

1. A method of managing security parameters for an endpoint communications device during a communications session with another communications device, the method comprising:

monitoring the communications session for information visible at the endpoint communications device during the communications session to detect first changing aspects of the communication session;

querying a network device for information not visible at the endpoint communications device during the communications session to detect second changing aspects of the communication session;

determining appropriate security parameters responsive to the detected first and second changing aspects; and

dynamically updating current security parameters of the endpoint communications device with the appropriate security parameters during the communications session to provide a variable degree of security for the session responsive to the detected first and second changing aspects.

2. The method of claim 1 , wherein determining appropriate security parameters comprises:

correlating the detected first and second changing aspects to predetermined security parameters associated with each of the detected aspects to determine the appropriate security parameters.

3. The method of claim 2 , wherein determining appropriate security parameters further comprises filtering the predetermined security parameters according to a software application used for the communications session to determine the appropriate security parameters that are usable by the software application.

4. The method of claim 2 , wherein determining appropriate security parameters further comprises obtaining customer security preferences and associating each of the obtained security preferences with security parameters to update correlation rules and/or the predetermined security parameters.

5. The method of claim 4 , wherein the customer security preferences comprise overall level of security for the communications session, specific levels of security information for respective aspects of the communications session, and/or specific levels of trust for respective parties to the communications session.

6. The method of claim 1 , wherein the information visible at the endpoint communications device comprises endpoint-visible information including at least one of a type and/or contents of the communications session, devices and/or software applications used for the communications session, method of connection and/or interface, parties at each endpoint of the communications session, and/or endpoint associated parameters.

7. The method of claim 1 , wherein the information not visible at the endpoint communications device comprises network-visible information including at least one of communications channel information for the session, customer profile and/or purchased level of service information, network conditions, security rating and/or historical trust level and/or status and/or parameters associated with one or more networks to be traversed in the communications session, owners and/or operators of the networks to be traversed, communications session type, and/or networks connected at and/or between each endpoint of the communication session.

8. A system for managing security parameters for an endpoint communications device during a communications session with another communications device, comprising:

an electronic device including a security control module therein, the security control module comprising:

a detection module configured to monitor the communications session for information visible at the endpoint communications device during the communications session to detect first changing aspects of the communication session and configured to query a network device for information not visible at the endpoint communications device during the communications session to detect second changing aspects of the communication session; and

a determination module configured to determine appropriate security parameters responsive to the detected first and second changing aspects and configured to dynamically update current security parameters of the endpoint communications device with the appropriate security parameters during the communications session to provide a variable degree of security for the session responsive to the detected first and second changing aspects.

9. The system of claim 8 , wherein the determination module is configured to correlate the detected first and second changing aspects to predetermined security parameters associated with each of the detected aspects and filter the predetermined security parameters according to a software application used for the communications session to determine the appropriate security parameters that are usable by the software application.

10. The system of claim 9 , further comprising an interface module configured to obtain customer security preferences and associate each of the obtained security preferences with security parameters to update correlation rules and/or the predetermined security parameters.

11. The system of claim 8 , wherein the detection module comprises a locally-based detection module configured to monitor the communications session for endpoint-visible information and a network-based detection module configured to query the network for network-visible information during the communications session.

12. The system of claim 11 , wherein the determination module comprises a network-based determination module configured to correlate the network-visible information to predetermined network security parameters and a locally-based determination module configured to correlate the endpoint-visible information to predetermined endpoint security parameters.

13. A computer program product for managing security parameters for an endpoint communications device during a communications session with another communications device, comprising:

a tangible computer readable storage medium having computer readable program code embodied therein, the computer readable program code comprising:

computer readable program code configured to monitor the communications session for information visible at the endpoint communications device during the communications session to detect first changing aspects of the communication session;

computer readable program code configured to query a network device for information not visible at the endpoint communications device during the communications session to detect second changing aspects of the communication session;

computer readable program code configured to determine appropriate security parameters responsive to the detected first and second changing aspects; and

computer readable program code configured to dynamically update current security parameters of the endpoint communications device with the appropriate security parameters during the communications session to provide a variable degree of security for the session responsive to the detected first and second changing aspects.

14. The computer program product of claim 13 , wherein the computer readable program code configured to determine appropriate security parameters is configured to correlate the detected first and second changing aspects to predetermined security parameters associated with each of the detected aspects and filter the predetermined security parameters according to a software application used for the communications session to determine the appropriate security parameters that are usable by the software application.

Assignments (9)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2025
From: INTELLECTUAL VENTURES ASSETS 198 LLC
To: DATASPHERE, LLC
Reel/Frame 071248/0632 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2025
From: INTELLECTUAL VENTURES ASSETS 3 LLC
To: INTELLECTUAL VENTURES ASSETS 198 LLC
Reel/Frame 070663/0680 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2021
From: INTELLECTUAL VENTURES II LLC
To: INTELLECTUAL VENTURES ASSETS 3 LLC
Reel/Frame 055989/0809 →
MERGER Recorded Jun 18, 2013
From: WORCESTER TECHNOLOGIES LLC
To: INTELLECTUAL VENTURES II LLC
Reel/Frame 030638/0027 →
CHANGE OF NAME Recorded Nov 16, 2011
From: AT&T BLS INTELLECTUAL PROPERTY, INC.
To: AT&T DELAWARE INTELLECTUAL PROPERTY, INC.
Reel/Frame 027242/0089 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2011
From: AT&T INTELLECTUAL PROPERTY I, LP
To: WORCESTER TECHNOLOGIES LLC
Reel/Frame 027241/0681 →
CHANGE OF NAME Recorded Nov 16, 2011
From: BELLSOUTH INTELLECTUAL PROPERTY CORPORATION
To: AT&T INTELLECTUAL PROPERTY, INC.
Reel/Frame 027242/0038 →
CHANGE OF NAME Recorded Nov 16, 2011
From: AT&T INTELLECTUAL PROPERTY, INC.
To: AT&T BLS INTELLECTUAL PROPERTY, INC.
Reel/Frame 027242/0076 →
NUNC PRO TUNC ASSIGNMENT Recorded Aug 25, 2011
From: AT&T DELAWARE INTELLECTUAL PROPERTY, INC.
To: AT&T INTELLECTUAL PROPERTY I, L.P.
Reel/Frame 026810/0547 →