IP Library Granted Patent US 10,666,691
Granted Patent B2
US 10,666,691 · App. 15/092,914 · Granted May 26, 2020

Dynamic session classification

Inventors: Douglas Richards (Cranberra, AU); Joel Ezell (Broomfield, CO)
Assignee: Avaya Inc.
H04L65/1069H04L65/1006H04L65/1076H04L67/00H04L67/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,666,691
App. No.
15/092,914
Granted
May 26, 2020
Kind
B2
Abstract

A request to establish a communication session between the first communication endpoint and a second communication endpoint is received. For example, the request may be a Session Initiation Protocol (SIP) INVITE message to establish a voice communication session. A security classification for the communication session is determined. For example, the determined security classification may be that the call is top secret or unclassified. The security classification is not based on whether the communication session is solely encrypted. The security classification is inserted into the request to establish the communication session. The request to establish the communication session with the security classification is sent to the second communication endpoint. This allows the second endpoint to display the security classification. A similar process is used in a response to the request to establish the communication session to convey the security classification to the first communication endpoint.

Claims (42)

1. A system comprising:

a microprocessor; and

a computer readable medium, coupled with the microprocessor and comprising microprocessor readable and executable instructions that program the microprocessor to:

receive, from a first communication endpoint, a Session Initiation Protocol (SIP) INVITE message to establish a communication session between the first communication endpoint and a second communication endpoint,

determine a first security classification of a plurality of possible security classifications for the communication session, wherein the first security classification is not based on whether the communication session is solely encrypted,

insert the first security classification into the SIP INVITE message, and

send the SIP INVITE message with the first security classification to the second communication endpoint.

2. The system of claim 1 , wherein first security classification is inserted into one of a SIP From: header, a SIP Contact header, a SIP P-Asserted-Identity header, or a proprietary header in the SIP INVITE message.

3. The system of claim 2 , wherein the first security classification is inserted into the SIP From: header, the SIP Contact header, and the SIP P-Asserted-Identity header in the SIP INVITE message.

4. The system of claim 2 , wherein the microprocessor receives a SIP 200 OK message from the second communication endpoint, inserts the first security classification into one of the SIP To: header, the SIP Contact header, the SIP P-Asserted-Identity header, or the proprietary header in the SIP 200 OK message, and sends the SIP 200 OK message with the first security classification to the first communication endpoint.

5. The system of claim 4 , wherein the first security classification is inserted into the SIP To: header, the SIP Contact header, and the SIP P-Asserted-Identity header in the SIP 200 OK message.

6. The system of claim 2 , wherein the microprocessor receives a SIP 200 OK message from a Back-to-Back User Agent (B2BUA), wherein the SIP 200 OK message comprises a second security classification for a SIP dialog between the B2BUA and the second communication endpoint in one of the SIP To: header, the SIP Contact header, the SIP P-Asserted-Identity header, or the proprietary header, determines an overall security classification based on the first security classification and the second security classification, and sends the SIP 200 OK message with the overall security classification to the first communication endpoint.

7. The system of claim 6 , wherein the overall security classification is sent in the SIP To: header, the SIP Contact header, and the SIP P-Asserted-Identity header in the sent SIP 200 OK message.

8. The system of claim 2 , wherein the communication session between the first communication endpoint and the second communication endpoint is transferred from the first communication endpoint to a third communication endpoint to establish a communication session between the second communication endpoint and the third communication endpoint, wherein the microprocessor receives a second SIP INVITE message or a SIP INVITE with replaces header message and inserts a second security classification into one of the SIP From: header, the SIP Contact header, the SIP P-Asserted-Identity header, or the proprietary header in the second SIP INVITE message or the SIP INVITE with replaces header message.

9. The system of claim 2 , wherein microprocessor receives a SIP 200 OK message from a Back-to-Back User Agent (B2BUA), wherein the SIP 200 OK message comprises a second security classification for a SIP dialog between the B2BUA and the second communication endpoint in a SIP via header.

10. The system of claim 2 , wherein the microprocessor receives a SIP 200 OK message from a Back-to-Back User Agent (B2BUA), wherein the SIP 200 OK message comprises an overall security classification inserted by a proxy server into the SIP 200 OK message.

11. A method comprising:

receiving, by a microprocessor, from a first communication endpoint, a Session Initiation Protocol (SIP) INVITE message to establish a communication session between the first communication endpoint and a second communication endpoint;

determining, by the microprocessor, a first security classification of a plurality of possible security classifications for the communication session, wherein the first security classification is not based on whether the communication session is solely encrypted;

inserting, by the microprocessor, the first security classification into the SIP INVITE message; and

sending, by the microprocessor, the SIP INVITE message with the first security classification to the second communication endpoint.

12. The method of claim 11 , wherein the first security classification is inserted into one of a SIP From: header, a SIP Contact header, a SIP P-Asserted-Identity header, or a proprietary header in the SIP INVITE message.

13. The method of claim 12 , wherein the first security classification is inserted into the SIP From: header, the SIP Contact header, and the SIP P-Asserted-Identity header in the SIP INVITE message.

14. The method of claim 12 , further comprising:

receiving, by the microprocessor, a SIP 200 OK message from the second communication endpoint;

inserting, by the microprocessor, the first security classification into one of the SIP To: header, the SIP Contact header, the SIP P-Asserted-Identity header, or the proprietary header in the SIP 200 OK message; and

sending, by the microprocessor, the SIP 200 OK message with the first security classification to the first communication endpoint.

15. The method of claim 14 , wherein the first security classification is inserted into the SIP To: header, the SIP Contact header, and the SIP P-Asserted-Identity header in the SIP 200 OK message.

16. The method of claim 12 , further comprising:

receiving, by the microprocessor, a SIP 200 OK message from a Back-to-Back User Agent (B2BUA), wherein the SIP 200 OK message comprises a second security classification for a SIP dialog between the B2BUA and the second communication endpoint in one of the SIP To: header, the SIP Contact header, the SIP P-Asserted-Identity header, or the proprietary header;

determining, by the microprocessor, an overall security classification based on the first security classification and the second security classification; and

sending, by the microprocessor, the SIP 200 OK message with the overall security classification to the first communication endpoint.

17. A system comprising:

a microprocessor; and

a computer readable medium coupled with the microprocessor and comprising microprocessor readable and executable instructions that program the microprocessor to execute a conference bridge, wherein the conference bridge:

receives a first Session Initiation Protocol (SIP) INVITE message from a first communication endpoint, wherein the first SIP INVITE message comprises a first security classification,

receives a second SIP INVITE message from a second communication endpoint, wherein the second SIP INVITE message comprises a second security classification,

determines an overall security classification for a conferenced communication session based on the first security classification being different from the second security classification, and

in response to the first security classification being different from the second security classification, sends a first SIP Re-INVITE message to the first communication endpoint, wherein the first SIP Re-INVITE message comprises the overall security classification.

18. The system of claim 17 , wherein the overall security classification is not unclassified, wherein the conference bridge receives a third SIP INVITE message that does not comprise a security classification and, in response to receiving the third SIP INVITE message that does not comprise the security classification, sends a second SIP Re-INVITE message to the first communication endpoint, wherein the second SIP Re-INVITE message comprises a security classification of unclassified, and sends a third SIP Re-INVITE message to the second communication endpoint, wherein the third SIP Re-INVITE message comprises the security classification of unclassified.

19. The system of claim 17 , wherein the first security classification is in one of a SIP From: header, a SIP Contact header, a SIP P-Asserted-Identity header, or a proprietary header of the SIP INVITE message.

20. The system of claim 17 , wherein the conference bridge sends a SIP UPDATE message to the first communication endpoint, wherein the SIP UPDATE message comprises the overall security classification.

Assignments (17)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: AVAYA LLC
To: ARLINGTON TECHNOLOGIES, LLC
Reel/Frame 067022/0780 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: CITIBANK, N.A.
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0117 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0227 →
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 7, 2016
From: RICHARDS, DOUGLAS; EZELL, JOEL
To: AVAYA INC.
Reel/Frame 038218/0529 →
Continuity (1)
Related Publication 20170295208A1 · Oct 12, 2017
Cited By (1)
US 12,500,786