IP Library Granted Patent US 9,900,291
Granted Patent B2
US 9,900,291 · App. 15/608,832 · Granted Feb 20, 2018

Methods and apparatus for synchronizing decryption state with remote encryption state

Inventors: Shiping Li (Acton, MA); Prashant Motagi (Chelmsford, MA); Gregory Paul Khederian (Westford, MA)
Assignee: Sonus Networks, Inc.
H04L63/0428G06N99/005H04L65/60H04M7/006H04W12/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,900,291
App. No.
15/608,832
Granted
Feb 20, 2018
Kind
B2
Abstract

Methods and apparatus for supporting secure packet communications, e.g., SRTP, which use implicit index numbers for synchronization and sequencing of received packets. The secure communications methods and apparatus having an adaptive index learning mode of operation and a non-adaptive index learning mode of operation. The adaptive index learning mode of operation being used to determine a correct estimated sequence number roll over counter number and the implicit index number for one of a plurality of secure packets received when an adaptive index learning process condition is satisfied.

Claims (84)

1. A secure communications method, the method comprising:

receiving signaling information corresponding to a secure real time packet stream;

receiving a plurality of encrypted secure real time packets, said plurality of packets being a part of said secure real time packet stream, said secure real time packet stream using an implicit packet index for sequencing of packets in said secure real time packet stream, said implicit packet index being generated from a sequence number and a sequence number roll over counter number, said sequence number for each of said plurality of packets being included in each of said packets, said roll over counter number for each of said plurality of packets not being included with said packets;

determining, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream; and

storing in memory an indication that the adaptive index learning process condition is satisfied when said determination is that said condition is satisfied; and

when said adaptive index learning process condition is satisfied using an adaptive index learning process to determine a correct estimated sequence number roll over counter number for one of said plurality of received packets, and

after determining said correct estimated sequence number roll over counter number for one of said plurality of received packets storing in said memory an indication that said adaptive index learning process condition is no longer satisfied; and

wherein said adaptive index learning process includes:

setting an estimated sequence number roll over counter number to zero after a determination that said adaptive index learning process condition is satisfied for the secure real time packet stream;

performing an authentication test on one or more of the received packets received using said estimated sequence number roll over counter number; and

when said authentication test fails discarding each packet which fails the authentication test and incrementing said estimated sequence number roll over counter number after a predetermined number of received packets fail said authentication test, and

when said authentication test passes accepting said packet as being valid.

2. The method of claim 1 wherein said predetermined number of received packets is one, said method further including:

generating a first packet index sequence number using a first sequence number and said estimated sequence number roll over counter number set to zero when it is determined that said adaptive index learning process condition exists, said first sequence number being included in a first packet received after determining that said adaptive index learning process condition exists; and

wherein said performing an authentication test on one or more of the received packets using said estimated sequence number roll over counter number includes performing an authentication test on said first packet using said estimated sequence number roll over counter number and authentication information included in said first received packet; and

when said authentication test on said first packet fails generating a second packet index sequence number using a second sequence number and said incremented estimated sequence number roll over counter number, said second sequence number being included in a second packet received after said first packet.

3. The method of claim 2 further including performing an authentication test on said second packet using said incremented estimated sequence number roll over counter number and authentication information included in said second received packet and discarding said second packet and incrementing said estimated sequence number roll over counter number when said authentication test fails.

4. The method of claim 1 , wherein said signaling information includes at least one of the following: session control signaling information, call flow signaling information or decryption device status signaling information.

5. The method of claim 4 , wherein said plurality of encrypted secure real time packets are part of a Voice Over Internet Protocol (VOIP) call and wherein determining, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream includes determining that said adaptive index learning process condition is satisfied for the secure real time packet stream when said signaling information is call flow signaling information indicating that said VOIP call is resuming after having been placed on hold.

6. The method of claim 4 , wherein said plurality of encrypted secure real time packets are part of a Voice Over Internet Protocol (VOIP) call received at a standby Session Border Controller and wherein determining, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream includes determining that said adaptive index learning process condition is satisfied for the secure real time packet stream when said signaling information includes status information indicating that the processing of said VOIP call is to be switched from an active Session Border Controller servicing said VOIP call to said standby Session Border Controller.

7. The method of claim 4 , wherein said plurality of encrypted secure real time packets are part of a Voice Over Internet Protocol call received at a Session Border Controller and wherein determining, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream includes determining that said adaptive index learning process condition is satisfied for the secure real time packet stream when said signaling information is session information indicating a change in encryption keys.

8. The method of claim 1 , wherein said adaptive index learning process further includes:

not performing anti-replay packet testing when said adaptive index learning process condition is satisfied.

9. A secure communications method, the method comprising:

receiving signaling information corresponding to a secure real time packet stream;

receiving a plurality of encrypted secure real time packets, said plurality of packets being a part of said secure real time packet stream, said secure real time packet stream using an implicit packet index for sequencing of packets in said secure real time packet stream, said implicit packet index being generated from a sequence number and a sequence number roll over counter number, said sequence number for each of said plurality of packets being included in each of said packets, said roll over counter number for each of said plurality of packets not being included with said packets;

determining, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream; and

storing in memory an indication that the adaptive index learning process condition is satisfied when said determination is that said condition is satisfied; and

when said adaptive index learning process condition is satisfied using an adaptive index learning process to determine a correct estimated sequence number roll over counter number for one of said plurality of received packets, and

after determining said correct estimated sequence number roll over counter number for one of said plurality of received packets storing in said memory an indication that said adaptive index learning process condition is no longer satisfied; and

wherein said adaptive index learning process includes:

setting a plurality of estimated sequence number roll over counter numbers to different values after a determination that said adaptive index learning process condition is satisfied for the secure real time packet stream;

performing a plurality of authentication tests on a packet received after said determination that said adaptive index learning process condition is satisfied for the secure real time packet stream using said plurality of estimated sequence number roll over counter numbers, said packet being one of said plurality of encrypted secure real time packets; and

when all of said plurality of authentication tests fail discarding said packet, and

when one of said authentication test passes accepting said packet as being valid and storing the estimated sequence number roll over counter number used in the authentication test that passed in memory as the correct estimated sequence number roll over counter number.

10. The method of claim 9 wherein said correct estimated sequence number roll over counter number is stored in memory as part of cryptographic context information for the secure real time packet stream.

11. A multi-mode secure communications decrypting device comprising:

a receiver configured to receive signaling information corresponding to a secure real time packet stream and a plurality of encrypted secure real time packets, said plurality of packets being a part of the secure real time packet stream, said secure real time packet stream using an implicit packet index for sequencing of packets in said secure real time packet stream, said implicit packet index being generated from a sequence number and a sequence number roll over counter number, said sequence number for each of said plurality of packets being included in each of said packets, said roll over counter number for each of said plurality of packets not being included with said packets;

memory;

one or more processors configured to:

determine, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream;

store in said memory an indication that the adaptive index learning process condition is satisfied when said one or more processors determines that said condition is satisfied;

use an adaptive index learning process to determine a correct estimated sequence number roll over counter number for one of said plurality of received packets when said adaptive index learning process condition is satisfied; and

store in said memory an indication that said adaptive index learning process condition is no longer satisfied after said one or more processors determines said correct estimated sequence number roll over counter number for one of said plurality of received packets;

wherein said one or more processors is further configured to:

set an estimated sequence number roll over counter number to zero after a determination that said adaptive index learning process condition is satisfied for the secure real time packet stream;

perform an authentication test on one or more of the received packets received using said estimated sequence number roll over counter number;

increment said estimated sequence number roll over counter number after a predetermined number of received packets fail said authentication test, when said authentication test fails discarding each packet which fails the authentication test; and

accept said packet as being valid when said authentication test passes.

12. The device of claim 11 ,

wherein said predetermined number of received packets is one; and

wherein said one or more processors is further configured to:

generate a first packet index sequence number using a first sequence number and said estimated sequence number roll over counter number set to zero when it is determined that said adaptive index learning process condition exists, said first sequence number being included in a first packet received after determining that said adaptive index learning process condition exists;

perform an authentication test on said first packet using said estimated sequence number roll over counter number and authentication information included in said first received packet as part of performing an authentication test on one or more of the received packets using said estimated sequence number roll over counter sequence number; and

when said authentication test fails:

i) increment said estimated sequence number roll over counter number, and

ii) generate a second packet index sequence number using a second sequence number and said incremented estimated sequence number roll over counter number, said second sequence number being included in a second packet received after said first packet.

13. The device of claim 12 wherein said one or more processors is further configured to:

perform an authentication test on said second packet using said incremented estimated sequence number roll over counter number and authentication information included in said second received packet; and

discard said second packet and increment said estimated sequence number roll over counter number when said authentication test fails.

14. The device of claim 11 , wherein said signaling information includes at least one of the following: session control signaling information, call flow signaling information or decryption device status signaling information.

15. The device of claim 14 ,

wherein said plurality of encrypted secure real time packets are part of a Voice Over Internet Protocol (VOIP) call, and

wherein said one or more processors is further configured to determine that said adaptive index learning process condition is satisfied for the secure real time packet stream when said signaling information is call flow signaling information indicating that said VOIP call is resuming after having been placed on hold.

16. The device of claim 14 ,

wherein said plurality of encrypted secure real time packets are part of a Voice Over Internet Protocol (VOIP) call received at a standby Session Border Controller, and

wherein said one or more processors is further configured to determine that said adaptive index learning process condition is satisfied for the secure real time packet stream when said signaling information includes status information indicating that the processing of said VOIP call is to be switched from an active Session Border Controller servicing said VOIP call to said standby Session Border Controller.

17. The device of claim 14 , wherein said plurality of encrypted secure real time packets are part of a Voice Over Internet Protocol call received at a Session Border Controller and wherein determining, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream includes determining that said adaptive index learning process condition is satisfied for the secure real time packet stream when said signaling information is session information indicating a change in encryption keys.

18. The device of claim 11 , wherein said adaptive index learning process includes not performing anti-replay packet testing when said adaptive index learning process condition is satisfied.

19. A multi-mode secure communications decrypting device comprising:

a receiver configured to receive signaling information corresponding to a secure real time packet stream and a plurality of encrypted secure real time packets, said plurality of packets being a part of the secure real time packet stream, said secure real time packet stream using an implicit packet index for sequencing of packets in said secure real time packet stream, said implicit packet index being generated from a sequence number and a sequence number roll over counter number, said sequence number for each of said plurality of packets being included in each of said packets, said roll over counter number for each of said plurality of packets not being included with said packets;

memory;

one or more processors configured to:

determine, based at least in part on the received signaling information, whether an adaptive index learning process condition is satisfied for the secure real time packet stream;

store in said memory an indication that the adaptive index learning process condition is satisfied when said one or more processors determines that said condition is satisfied;

use an adaptive index learning process to determine a correct estimated sequence number roll over counter number for one of said plurality of received packets when said adaptive index learning process condition is satisfied; and

store in said memory an indication that said adaptive index learning process condition is no longer satisfied after said one or more processors determines said correct estimated sequence number roll over counter number for one of said plurality of received packets:

wherein said one or more processors is further configured to:

set a plurality of estimated sequence number roll over counter numbers to different values after a determination that said adaptive index learning process condition is satisfied for the secure real time packet stream;

perform a plurality of authentication tests on a packet received after said determination that said adaptive index learning process condition is satisfied for the secure real time packet stream using said plurality of estimated sequence number roll over counter numbers, said packet being one of said plurality of encrypted secure real time packets; and

discard said packet when all of said plurality of authentication tests fail; and

accept said packet as being valid when one of said authentication tests passes; and

store in memory the estimated sequence number roll over counter number used in the authentication test that passed as the correct estimated sequence number roll over counter number.

20. The device of claim 19 wherein said correct estimated sequence number roll over counter number is stored in memory as part of cryptographic context information for the secure real time packet stream.

Assignments (11)
RELEASE OF SECURITY INTEREST Recorded Jun 24, 2024
From: CITIZENS BANK, N.A.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 067822/0433 →
TERMINATION AND RELEASE OF FIRST SUPPLEMENT OT PATENT SECURITY AGREEMENT AT R/F 049035/0939 Recorded Dec 6, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 058740/0265 →
TERMINATION AND RELEASE OF PATENT SECURITY AGREEMENT AT R/F 044978/0801 Recorded Dec 6, 2021
From: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC. (F/K/A GENBAND US LLC AND SONUS NETWORKS, INC.)
Reel/Frame 058949/0497 →
SECURITY INTEREST Recorded Mar 3, 2020
From: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
To: CITIZENS BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 052076/0905 →
CORRECTIVE ASSIGNMENT TO CORRECT THE SCHEDULE PREVIOUSLY RECORDED ON REEL 049035 FRAME 0939. ASSIGNOR(S) HEREBY CONFIRMS THE FIRST SUPPLEMENT TO PATENT SECURITY AGREEMENT. Recorded Aug 22, 2019
From: GENBAND US LLC; RIBBON COMMUNICATIONS OPERATING COMPANY, INC., FORMERLY KNOWN AS SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 050705/0001 →
FIRST SUPPLEMENT TO SECURITY AGREEMENT Recorded Apr 30, 2019
From: GENBAND US LLC; RIBBON COMMUNICATIONS OPERATING COMPANY, INC., FORMERLY KNOWN AS SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 049035/0939 →
CHANGE OF NAME Recorded Jan 16, 2019
From: SONUS NETWORKS, INC.
To: RIBBON COMMUNICATIONS OPERATING COMPANY, INC.
Reel/Frame 048078/0036 →
SECURITY INTEREST Recorded Jan 2, 2018
From: GENBAND US LLC; SONUS NETWORKS, INC.
To: SILICON VALLEY BANK, AS ADMINISTRATIVE AGENT
Reel/Frame 044978/0801 →
CHANGE OF NAME Recorded Dec 24, 2017
From: SONUS, INC.
To: SONUS NETWORKS, INC.
Reel/Frame 044957/0213 →
MERGER AND CHANGE OF NAME Recorded Dec 24, 2017
From: SOLSTICE SAPPHIRE, INC.; SONUS NETWORKS, INC.; SONUS NETWORKS, INC.
To: SONUS, INC.
Reel/Frame 044957/0243 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 30, 2017
From: LI, SHIPING; MOTAGI, PRASHANT; KHEDERIAN, GREGORY PAUL
To: SONUS NETWORKS, INC.
Reel/Frame 042533/0765 →
Continuity (3)
Continuation 14841276 · Aug 31, 2015
Provisional Application 62121287 · Feb 26, 2015
Related Publication 20170272408A1 · Sep 21, 2017