IP Library › Granted Patent US 12,003,484
Granted Patent B2
US 12,003,484 · App. 17/859,162 · Granted Jun 4, 2024

Systems and methods for preventing data leaks over RTP or SIP

Inventor: Jochen Pretli (Frankfurt, DE)
Assignee: Fortinet, Inc.
H04L63/0245H04L61/2564H04L63/0421
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,003,484
App. No.
17/859,162
Granted
Jun 4, 2024
Kind
B2
Abstract

Systems, devices, and methods are discussed for avoiding data thefts in real-time transactions.

Claims (45)

1. A method comprising:

receiving, by a processing resource, a data transfer packet including a data payload;

determining, by the processing resource, that the data transfer packet is a real-time data transfer packet;

based at least in part on the data transfer packet being a real time data transfer packet, providing, by the processing resource, the data payload to a conversion circuit, converting the data payload by the conversion circuit from a digital domain to an analog domain, and then from the analog domain to the digital domain to yield a modified data payload, and receiving, by the processing resource, the modified data payload; and

forwarding, by the processing resource, the data transfer packet including the modified data payload in place of the data payload.

2. The method of claim 1 , wherein the real-time data transfer packet is a real-time transfer protocol packet.

3. The method of claim 1 , wherein the real-time data transfer packet is session initiated transfer protocol packet.

4. The method of claim 1 , wherein the method further comprises:

scanning, by the processing resource, the data payload for an expected data type pattern;

identifying, by the processing resource, a portion of the data payload as not matching the expected data type pattern; and

obscuring, by the processing resource, the identified portion of the data payload to yield and obscure data set; and

wherein the modified data payload includes the obscure data set in place of the identified portion of the data payload.

5. The method of claim 4 , wherein obscuring the identified portion includes replacing the identified portion with a random pattern.

6. The method of claim 4 , wherein obscuring the identified portion includes replacing the identified portion with a fixed pattern.

7. The method of claim 1 , wherein the conversion of the data payload is done using a process that is compatible with at least a portion of the data payload.

8. The method of claim 7 , wherein the portion of the data payload is a first portion of the data payload, and wherein the process is incompatible with a second portion of the data payload.

9. A system for reducing the possibility of data theft via a real-time transfer, the system comprising:

a processing resource;

a non-transitory computer-readable medium, coupled to the processing resource, having stored therein instructions that when executed by the processing resource cause the processing resource to:

receive a data transfer packet including a data payload;

determine that the data transfer packet is a real-time data transfer packet;

based at least in part on the data transfer packet being a real time data transfer packet, provide the data payload to a conversion circuit, wherein the conversion circuit is to convert the data payload from a digital domain to an analog domain, and then from the analog domain to the digital domain to yield a modified data payload, and receive the modified data payload from the conversion circuit; and

forward the data transfer packet including the modified data payload in place of the data payload.

10. The system of claim 9 , wherein the instructions that when executed by the processing resource cause the processing resource to:

real-time data transfer packet is a real-time transfer protocol packet.

11. The system of claim 9 , wherein the real-time data transfer packet is session initiated transfer protocol packet.

12. The system of claim 9 , wherein the computer-readable medium further has instructions stored therein that when executed by the processing resource cause the processing resource to:

scan the data payload for an expected data type pattern;

identify a portion of the data payload as not matching the expected data type pattern; and

obscure the identified portion of the data payload to yield and obscure data set; and

wherein the modified data payload includes the obscure data set in place of the identified portion of the data payload.

13. The system of claim 12 , wherein obscuring the identified portion includes replacing the identified portion with a random pattern.

14. The method of claim 12 , wherein obscuring the identified portion includes replacing the identified portion with a fixed pattern.

15. The system of claim 9 , wherein the conversion of the data payload is done using a process that is compatible with at least a portion of the data payload.

16. The system of claim 15 , wherein the portion of the data payload is a first portion of the data payload, and wherein the process is incompatible with a second portion of the data payload.

17. A non-transitory computer-readable storage medium embodying a set of instructions, which when executed by a processing resource, causes the processing resource to:

receive a data transfer packet including a data payload;

determine that the data transfer packet is a real-time data transfer packet;

based at least in part on the data transfer packet being a real time data transfer packet, provide the data payload to a conversion circuit, wherein the conversion circuit is to convert the data payload from a digital domain to an analog domain, and then from the analog domain to the digital domain to yield a modified data payload, and receive the modified data payload from the conversion circuit; and

forward the data transfer packet including the modified data payload in place of the data payload.

18. The non-transitory computer-readable storage medium of claim 17 , wherein the non-transitory computer-readable storage medium further has instructions stored therein that when executed by the processing resource cause the processing resource to:

scan the data payload for an expected data type pattern;

identify a portion of the data payload as not matching the expected data type pattern; and

obscure the identified portion of the data payload to yield and obscure data set; and

wherein the modified data payload includes the obscure data set in place of the identified portion of the data payload.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 7, 2022
From: PRETLI, JOCHEN
To: FORTINET, INC.
Reel/Frame 060428/0468 →
Continuity (1)
Related Publication 20240015139A1 · Jan 11, 2024