IP Library Granted Patent US 9,143,488
Granted Patent B2
US 9,143,488 · App. 14/195,411 · Granted Sep 22, 2015

Real-time encryption of voice and fax over IP

Inventors: Pierre St-Germain (Montreal, CA); Cesar Hernandez (Montreal, CA); Khaled Tewfik (Saint-Lazare, CA); Gaetan Sheridan (Montreal-Nord, CA)
H04L63/0471H04L63/02H04L63/0281H04L63/166H04M1/2535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,143,488
App. No.
14/195,411
Granted
Sep 22, 2015
Kind
B2
Abstract

A method for encrypting application layer packets, including UDPTL data used by T.38 FOIP devices, for securing transmission of Fax communications over the Internet. In one embodiment, a client side SIPCryptAgent is provided and operably installed on the user's Fax or Voice over IP server/device. Similarly, a server side SIPCryptAgent is installed on the SBC servers at the service provider. The client side SIPCryptAgent acts as a proxy for the Fax device thereby receiving all data sent out by the Fax device and encrypting the SIP and media packets of the Fax device using a lightweight protocol before sending them to the SBC servers. Similarly, the server side acts as a proxy for the SBC servers and encrypts outgoing data and decrypts incoming data so that the exchange of data over the Internet between the client side CryptAgent and the server side CryptAgent is done in a secure, encrypted and real time manner.

Claims (28)

1. A method for securing Fax Over IP (FOIP) communications exchanged in real-time between a T.38 Fax server and a Session Border Controller (SBC) server, the method comprising:

operably installing or connecting a client side CryptAgent (BCA-CA) to the T.38 fax server;

configuring the BCA-CA as a proxy for the T.38 fax server;

operably installing or connecting a server side CryptAgent (BCA-SE) to the SBC server;

configuring the BCA-SE as a proxy for the SBC server;

the BCA-CA encrypting outgoing application data packets received from the T.38 Fax server and sending the encrypted packets to the BCA-SE over the Internet; and

the BCA-SE decrypting the encrypted packets received from the BCA-CA and sending the decrypted packets to the SBC server;

thereby securing fax communications sent over the Internet using existing communication protocols.

2. The method of claim 1 , further comprising encrypting the UDP data of the transport layer (the UDP payload), the encrypting comprising scrambling SIP application header data with SIP application payload data of the application layer to eliminate original structure of the application layer data.

3. The method of claim 1 , further comprising:

the BCA-CA implementing an authentication bridge on behalf of the T.38 Fax server to authenticate the Fax server with the SBC server.

4. The method of claim 1 , further comprising: implementing a SIP validator module in the BCA-CA, the SIP validator module being configured to diagnose Firewall restrictions blocking communications between the fax server and the SBC server.

5. The method of claim 4 , wherein the SIP validator module is adapted to mimic communication between the Fax server and the SBC server from a device residing in the same network and subject to the same firewall restrictions.

6. The method of claim 4 , wherein the SIP validator module is adapted to send SIP INVITE messages to the SBC server and extract a public IP address and IP port used by the firewall from responses received from the SBC server to verify Consistent NAT behavior of the firewall.

7. The method of claim 4 , wherein the SIP validator module is adapted to perform a network quality test including sending a series of packets consisting of real audio signals for a fixed duration to mimic a real audio traffic pattern during a VoIP call and determining the quality of the network from the echoed back packets based on a number of lost packets, delay and jitter.

8. The method of claim 1 , further comprising:

prior to the encrypting, the BCA-CA initiating an HTTPS session with the BCA-SE and requesting encryption keys; and

performing the encryption using said encryption keys.

9. The method of claim 8 , further comprising:

periodically updating the encryption keys and performing the encryption and decryption using the updated keys.

10. The method of claim 8 , further comprising duplicating the BCS-SE and SBC servers for redundancy to ensure continuity of a current secure session between the Fax server and the SBC server.

11. The method of claim 1 , further comprising:

the BCA-SE encrypting the application layer packets (SIP, RTP, UDPTL) received from the SBC and sending the encrypted packets to the BCA-CA;

the BCA-CA decrypting the encrypted packets received from the BCA-SE and sending the decrypted packets to the Fax server.

12. A memory having recorded thereon computer readable statements and instructions for implementing the method of claim 1 .

13. The method of claim 1 , further comprising:

the BCA-SE encrypting outgoing application layer packets received from the SBC server and sending the encrypted packets over the Internet to the BCA-CA for decrypting, the encrypting comprising scrambling header data and payload data of the application layer that make up a UDP payload to eliminate original structure of the application layer; and/or

the BCA-SE decrypting encrypted packets received from the BCA-CA and sending the decrypted packets to the SBC server, the decrypting comprising retrieving scrambled header data and payload data of the application data to retrieve original structure of the application layer.

Assignments (6)
SECURITY INTEREST Recorded Jun 23, 2022
From: CLOUDLI COMMUNICATIONS CORP.
To: SUSSER BANK
Reel/Frame 060285/0623 →
RELEASE OF SECURITY INTEREST Recorded Jun 23, 2022
From: ROYAL BANK OF CANADA
To: CLOUDLI COMMUNICATIONS CORP.
Reel/Frame 060436/0253 →
CHANGE OF NAME Recorded Jun 13, 2022
From: CLOUDLI COMMUNICATIONS LTD.
To: CLOUDLI COMMUNICATIONS CORP.
Reel/Frame 060352/0782 →
CHANGE OF NAME Recorded Feb 1, 2021
From: BABYTEL INC.
To: CLOUDLI COMMUNICATIONS LTD.
Reel/Frame 055191/0833 →
SECURITY AGREEMENT Recorded Nov 10, 2020
From: BABYTEL INC.
To: ROYAL BANK OF CANADA
Reel/Frame 054369/0846 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2014
From: ST-GERMAIN, PIERRE; HERNANDEZ, CESAR; TEWFIK, KHALED; SHERIDAN, GAETAN
To: BABYTEL INC
Reel/Frame 032949/0225 →
Continuity (2)
Provisional Application 61921575 · Dec 30, 2013
Related Publication 20150188895A1 · Jul 2, 2015