IP Library Granted Patent US 8,185,947
Granted Patent B2
US 8,185,947 · App. 11/776,509 · Granted May 22, 2012

System, method and apparatus for securely exchanging security keys and monitoring links in a IP communications network

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,185,947
App. No.
11/776,509
Granted
May 22, 2012
Kind
B2
Abstract

The present invention provides a system, method and apparatus for securely exchanging security keys and monitoring links in an IP communications network. The apparatus is disposed between the local device and the remote device and receives a security key associated with the secure communication(s) for the local device. The apparatus then uses the security key to decode one or more messages transmitted between the local device and the remote device. The apparatus may initiate one or more security protocols whenever the decoded message(s) satisfy one or more criteria. Note that the present invention can be implemented as a computer program embodied on a computer readable medium wherein each step is performed by one or more code segments.

Claims (64)

1. A method for monitoring two or more secure communications between a trusted local network device and two or more remote devices via a set of first secure communication channels, comprising the steps of:

receiving a security key associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices at a security device via a second secure communication channel whenever the trusted local network device creates or changes the security key, wherein (a) the second secure communication channel is a persistent connection used to transmit all security keys between the security device and the trusted local network device that is independent of the first secure communication channels, and (b) the security device is disposed between the trusted local network device and the two or more remote devices;

storing the security keys in a secure storage communicably coupled to the security device, wherein the stored security keys cannot be extracted or read by the security device;

decoding one or more messages transmitted between the trusted local network device and the two or more remote devices at the security device by performing operations on the stored security keys; and

maintaining the second secure communication channel independently of the set of first communication channels using one or more interface messages sent between the trusted local network device and the security device.

2. The method as recited in claim 1 , further comprising the step of initiating one or more security protocols whenever the decoded message(s) satisfy one or more criteria.

3. The method as recited in claim 1 , wherein the security device is communicably connected between the trusted local network device and the remote two or more devices, or is communicably connected to a tap communicably connected between the trusted local network device and the remote device.

4. The method as recited in claim 1 , further comprising the step of establishing the second secure communication channel between the security device and the trusted local network device.

5. The method as recited in claim 1 , wherein the security key is changed on a per session or per call basis.

6. The method as recited in claim 1 , further comprising the step of establishing a persistent connection for the second secure communication channel between the security device and the trusted local network device.

7. The method as recited in claim 1 , wherein the one or more interface messages comprise a key notification message, a keepalive message, a notify message, a request message or a response message.

8. The method as recited in claim 1 , wherein:

the security device comprises an application level security node or an Internet Protocol Communication Security device;

the trusted local network device comprises a packet data gateway;

the packet-based network comprises an Internet Protocol network;

the remote device comprises an end user device, a mobile handset, a computer, a portable computer, a personal data assistant, a multimedia device or a combination thereof; or

the message(s) comprise one or more data packets, voice packets, multimedia packets or a combination thereof.

9. A method for monitoring two or more secure communications between a trusted local network device and two or more remote devices via a set of first secure communication channels, comprising the steps of:

establishing a persistent connection between a security device and the trusted local network device wherein the security device is disposed between the trusted local network device and the two or more remote devices;

establishing a second secure communication channel between the security device and the trusted local network device via the persistent connection that is used to transmit all security keys to the security device and is independent of the set of first secure communication channels;

receiving a security key associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices at the security device via the second secure communication channel, whenever the trusted local network device creates or changes the security key;

storing the security keys in a secure storage communicably coupled to the security device, wherein the stored security keys cannot be extracted or read by the security device;

decoding one or more messages transmitted between the trusted local network device and the two or more remote devices at the security device by performing operations on the stored security keys;

initiating one or more security protocols whenever the decoded message(s) satisfy one or more criteria; and

maintaining the second secure communication channel independently of the set of first communication channels using one or more interface messages sent between the trusted local network device and the security device.

10. A non-transitory computer readable medium for monitoring two or more secure communications between a trusted local network device and two or more remote devices via a set of first secure communication channels, the non-transitory computer readable medium comprising program instructions when executed by a security device causes the security device to perform the steps of:

receiving a security key associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices at the security device via a second secure communication channel whenever the trusted local network device creates or changes the security key, wherein (a) the second secure communication channel is a persistent connection used to transmit all the security keys between the security device and the trusted local network device that is independent of the first secure communication channels, and (b) the security device is disposed between the trusted local network device and the two or more remote devices;

storing the security keys in a secure storage communicably coupled to the security device, wherein the stored security keys cannot be extracted or read by the security device;

decoding one or more messages transmitted between the trusted local network device and the two or more remote devices at the security device by performing operations on the stored security keys; and

maintaining the second secure communication channel independently of the set of first communication channels using one or more interface messages sent between the trusted local network device and the security device.

11. A non-transitory computer readable medium for monitoring two or more secure communications between a trusted local network device and two or more remote devices via a set of first secure communication channels, the non-transitory computer readable medium comprising program instructions when executed by a security device causes the security device to perform the steps of:

establishing a persistent connection between a security device and the trusted local network device wherein the security device is disposed between the trusted local network device and the two or more remote devices;

establishing a second secure communication channel between the security device and the trusted local network device via the persistent connection that is used to transmit all security keys to the security device and is independent of the set of first secure communication channels;

receiving a security key associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices at the security device via the second secure communication channel whenever the trusted local network device creates or changes the security key;

storing the security keys in a secure storage communicably coupled to the security device, wherein the stored security keys cannot be extracted or read by the security device;

decoding one or more messages transmitted between the trusted local network device and the two or more remote devices at the security device by performing operations on the stored security keys;

initiating one or more security protocols whenever the decoded message(s) satisfy one or more criteria; and

maintaining the second secure communication channel independently of the set of first communication channels using one or more interface messages sent between the trusted local network device and the security device.

12. An apparatus for monitoring two or more secure communications between a trusted local network device and two or more remote devices via a set of secure local-to-remote device communication channels comprising:

a first interface for a secure private communication channel to the trusted local network device that is a persistent connection used to transmit all security keys between the apparatus and the trusted local network device and is independent of the set of secure local-to-remote device communication channels;

a second interface for the set of secure local-to-remote device communication channels;

a secure data storage; and

a processor communicably coupled to the first interface, the second interface and the secure data storage wherein the processor: (a) receives a security key at the first interface that is associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices via the secure private channel whenever the trusted local network device creates or changes the security key, (b) stores the security keys in the secure data storage such that the stored security keys cannot be extracted or read by the security device, (c) decodes one or more messages by performing operations on the stored security keys wherein the one or more messages are transmitted between the trusted local network device and the one or more remote devices and are obtained from the set of secure local-to-remote device communication channels via the second interface, and (d) maintains the secure private communication channel independently of the set of secure local-to-remote device communication channels using one or more interface messages sent between the trusted local network device and the security device via the first interface.

13. The apparatus as recited in claim 12 , wherein the processor initiates one or more security protocols whenever the decoded message(s) satisfy one or more criteria.

14. The apparatus as recited in claim 12 , wherein the processor establishes the secure private communication channel between the security device and the trusted local network device.

15. The apparatus as recited in claim 12 , wherein the processor establishes the persistent connection for the secure private communication channel between the security device and the trusted local network device.

16. A security device for monitoring two or more secure communications between a trusted local network device and two or more remote devices via a set of secure local-to-remote device communication channels comprising:

a first interface for a secure private communication channel to the trusted local network device that is a persistent connection used to transmit all security keys between the security device and the trusted local network device and is independent of the set of secure local-to-remote device communication channels;

a second interface for the set of secure local-to-remote device communication channels;

a secure data storage; and

a processor communicably coupled to the first interface, the second interface and the secure data storage wherein the processor: (a) establishes the persistent connection with the trusted local network device, (b) establishes the secure private communication channel with the trusted local network device via the persistent connection, (c) receives a security key at the first interface that is associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices via the secure private channel whenever the trusted local network device creates or changes the security key, (d) stores the security keys in the secure data storage such that the stored security keys cannot be extracted or read by the security device, (e) decodes one or more messages by performing operations on the stored security keys wherein the one or more messages are transmitted between the trusted local network device and the remote devices and are obtained from the set of secure local-to-remote device communication channels via the second interface, (f) initiates one or more security protocols whenever the decoded message(s) satisfy one or more criteria, and (g) maintains the secure private communication channel independently of the set of secure local-to-remote device communication channels using one or more interface messages sent between the trusted local network device and the security device via the first interface.

17. A system comprising:

a network;

two or more remote devices;

a trusted local network device communicably coupled to the remote devices via the network to engage in two or more secure communications via a set of secure local-to-remote communication channels;

a security device disposed between the trusted local network device and the two or more remote devices wherein the security device comprises: (1) a first interface for a secure private communication channel to the trusted local network device that is a persistent connection used to transmit all security keys between the trusted local network device and the security device and is independent of the set of secure local-to-remote device communication channels, (2) a second interface for the secure local-to-remote device communication channels, (3) a secure data storage, and (4) a processor communicably coupled to the first interface, the second interface and the secure data storage wherein the processor: (a) receives a security key at the first interface that is associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices via the secure private channel whenever the trusted local network device creates or changes the security key, (b) stores the security keys in the secure data storage such that the stored security keys cannot be extracted or read by the security device, (c) decodes one or more messages by performing operations on the stored security keys wherein the one or more messages are transmitted between the trusted local network device and the two or more remote devices and are obtained from the set of secure local-to-remote device communication channels via the second interface, and (d) maintains the secure private communication channel independently of the set of secure local-to-remote device communication channels using one or more interface messages sent between the trusted local network device and the security device via the first interface.

18. The system as recited in claim 17 , wherein the processor initiates one or more security protocols whenever the decoded message(s) satisfy one or more criteria.

19. The system as recited in claim 17 , wherein the processor establishes the secure private communication channel between the security device and the trusted local network device.

20. The system as recited in claim 17 , wherein the processor establishes the persistent connection for the secure private communication channel between the security device and the trusted local network device.

21. A system comprising:

a network;

two or more remote devices;

a trusted local network device communicably coupled to the remote devices via the network to engage in two or more secure communications via a set of secure local-to-remote communication channels;

a security device disposed between the trusted local network device and the two or more remote devices wherein the security device comprises: (1) a first interface for a secure private communication channel to the trusted local network device that is a persistent connection used to transmit all security keys between the trusted local network device and the security device and is independent of the set of secure local-to-remote device communication channels, (3) a secure data storage, and (4) a processor communicably coupled to the first interface, the second interface and the secure data storage wherein the processor: (a) establishes the persistent connection with the trusted local network device, (b) establishes the secure private communication channel with the trusted local network device via the persistent connection, (c) receives a security key at the first interface that is associated with any of the secure communication(s) between the trusted local network device and the two or more remote devices via the secure private channel whenever the trusted local network device creates or changes the security key, (d) stores the security keys in the secure data storage such that the stored security keys cannot be extracted or read by the security device, (e) decodes one or more messages by performing operations on the stored security keys wherein the one or more messages are transmitted between the trusted local network device and the remote devices and are obtained from the set of secure local-to-remote device communication channels via the second interface, (f) initiates one or more security protocols whenever the decoded message(s) satisfy one or more criteria, and (g) maintains the secure private communication channel independently of the set of secure local-to-remote device communication channels using one or more interface messages sent between the trusted local network device and the security device via the first interface.

Assignments (21)
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
MERGER Recorded Oct 28, 2011
From: SIPERA SYSTEMS, INC.
To: AVAYA INC.
Reel/Frame 027138/0920 →
RELEASE Recorded Oct 24, 2011
From: SILICON VALLEY BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 027120/0119 →
RELEASE OF SECURITY INTEREST Recorded Mar 4, 2011
From: COMERICA BANK
To: SIPERA SYSTEMS, INC.
Reel/Frame 025901/0892 →
SECURITY AGREEMENT Recorded Jan 25, 2011
From: SIPERA SYSTEMS, INC.
To: SILICON VALLEY BANK
Reel/Frame 025694/0699 →
SECURITY AGREEMENT Recorded May 21, 2008
From: SIPERA SYSTEMS, INC.
To: COMERICA BANK
Reel/Frame 020979/0211 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2007
From: KURAPATI, SRIKRISHNA; HERLE, SUDHINDRA PUNDALEEKA
To: SIPERA SYSTEMS, INC.
Reel/Frame 019776/0158 →