IP Library Granted Patent US 7,231,027
Granted Patent B2
US 7,231,027 · App. 10/790,610 · Granted Jun 12, 2007

Encapsulation, compression, and encryption of PCM data

Assignee: Securelogix Corporation
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,231,027
App. No.
10/790,610
Granted
Jun 12, 2007
Kind
B2
Abstract

A system and method to provide secure access across the untrusted public switched telephone network is described. The system and method can be initiated by a security policy defining actions to be taken based upon at least one attribute of the call.

Claims (329)

1. A virtual private telephone network for providing encrypted transport of a call across a public switched telephone network (PSTN) from a first enterprise location to a second enterprise location, said virtual private telephone network being located between one or more end-user stations at the first enterprise location and one or more end-user stations at the second enterprise location, said virtual private telephone network comprising:

at least one rule associated with the first enterprise location;

said at least one rule associated with the first enterprise location specifying at least one action associated with the first enterprise location to be performed based on at least one attribute of an incoming or outgoing call to/from the first enterprise location;

at least one rule associated with the second enterprise location;

said at least one rule associated with the second enterprise location specifying at least one action associated with the second enterprise location to be performed based on at least one attribute of the incoming or outgoing call to/from the second enterprise location;

at least one first telephony appliance associated with the first enterprise location;

said at least one first telephony appliance associated with the first enterprise location including means for determining said at least one attribute of the incoming or outgoing call to/from the first enterprise location;

said at least one attribute being from a group including:

the call direction,

the call source number,

the call destination number,

the call type,

said call type attribute being defined as one of voice, fax, or data transfer (modem),

the call date,

the call time,

the call duration,

the identifier for the extension or direct connect line carrying the call,

the channel through which the call is processed,

the start date of the call,

the start time of the call,

the end date of the call, and

the end time of the call;

said at least one first telephony appliance associated with the first enterprise location further including means for performing said at least one action associated with the first enterprise location specified in said at least one rule associated with the first enterprise location;

said at least one action being from a group including:

allowing the call,

denying the call,

conducting the call in encrypted mode,

sending a tone,

sending a message,

logging the call,

generating a report, and

providing an alert; and

at least one second telephony appliance associated with the second enterprise location;

said at least one second telephony appliance associated with the second enterprise location including means for determining said at least one attribute of the incoming or outgoing call to/from the second enterprise location;

said at least one attribute being from said group including:

the call direction,

the call source number,

the call destination number,

the call type,

said call type attribute being defined as one of voice, fax, or data transfer (modem),

the call date,

the call time,

the call duration,

the identifier for the extension or direct connect line carrying the call,

the channel through which the call is processed, the start date of the call,

the start time of the call,

the end date of the call, and

the end time of the call;

said at least one second telephony appliance associated with the second enterprise location further including means for performing said at least one action associated with the second enterprise location specified in said at least one rule associated with the second enterprise location;

said at least one action being from said group including:

allowing the call,

denying the call,

conducting the call in encrypted mode,

sending a tone,

sending a message,

logging the call,

generating a report, and

providing an alert.

2. The virtual private telephone network as defined in claim 1 wherein said group of attributes of the incoming or outgoing call to/from the first enterprise location further includes:

the trunk group through which the call is processed,

the digits dialed prior to the base phone number,

the digits dialed after the base phone number,

the caller ID identifier,

the call connect time,

the keywords detected in the call content, and

the digits dialed after call connect.

3. The virtual private telephone network as defined in claim 1 wherein said group of attributes of the incoming or outgoing call to/from the second enterprise location further includes:

the trunk group through which the call is processed,

the digits dialed prior to the base phone number,

the digits dialed after the base phone number,

the caller ID identifier,

the call connect time,

the keywords detected in the call content, and

the digits dialed after call connect.

4. The virtual private telephone network as defined in claim 1 wherein one of said at least one rule associated with the first enterprise effects the encryption of all calls.

5. The virtual private telephone network as defined in claim 1 wherein one of said at least one rule associated with the second enterprise effects the encryption of all calls.

6. The virtual private telephone network as defined in claim 1 further including means for performing at least one additional action associated with the first enterprise location responsive to the success or failure of said action of conducting the call in encrypted mode, said at least one additional action being from a group including:

allowing the call,

denying the call,

sending a tone,

sending a message,

adjusting the security policy,

logging the call,

generating a report, and

providing an alert.

7. The virtual private telephone network as defined in claim 1 further including means for performing at least one additional action associated with the second enterprise location responsive to the success or failure of said action of conducting the call in encrypted mode, said at least one additional action being from a group including:

allowing the call,

denying the call,

sending a tone,

sending a message,

adjusting the security policy,

logging the call,

generating a report, and

providing an alert.

8. The virtual private telephone network as defined in claim 6 wherein said action of adjusting the security policy, to be performed in association with the first enterprise location, includes changing, in accordance with said at least one rule associated with the first enterprise location, one or more actions and/or one or more additional actions associated with the first enterprise location to be performed on future incoming or outgoing calls to the one or more end-user stations at the first enterprise location.

9. The virtual private telephone network as defined in claim 7 wherein said action of adjusting the security policy, to be performed in association with the second enterprise location, includes changing, in accordance with said at least one rule associated with the second enterprise location, one or more actions and/or one or more additional actions associated with the second enterprise location to be performed on future incoming or outgoing calls to the one or more end-user stations at the second enterprise location.

10. The virtual private telephone network as defined in claim 1 wherein said action of conducting the call in encrypted mode, to be performed in association with the first enterprise location, includes creation of a VoIP-compatible packet for transport over the PSTN.

11. The virtual private telephone network as defined in claim 1 wherein said action of conducting the call in encrypted mode, to be performed in association with the second enterprise location, includes creation of a VoIP-compatible packet for transport over the PSTN.

12. The virtual private telephone network as defined in claim 1 further including:

a public branch exchange (PBX) located at the first enterprise location, and

means for said PBX to determine and provide one or more attributes of said at least one attribute of the incoming or outgoing call to/from the first enterprise location.

13. The virtual private telephone network as defined in claim 1 further including:

a public branch exchange (PBX) located at the second enterprise location, and

means for said PBX to determine and provide one or more attributes of said at least one attribute of the incoming or outgoing call to/from the second enterprise location.

14. The virtual private telephone network as defined in claim 1 further including:

a public branch exchange (PBX) located at the first enterprise location, and

means for said PBX to be used to perform one or more actions of said at least one action specified in said at least one rule associated with the first enterprise location.

15. The virtual private telephone network as defined in claim 1 further including:

a public branch exchange (PBX) located at the second enterprise location, and

means for said PBX to be used to perform one or more actions of said at least one action specified in said at least one rule associated with the second enterprise location.

16. The virtual private telephone network as defined in claim 1 wherein said action of conducting the call in encrypted mode to be performed in association with the first enterprise location is performed without encrypting actions being taken by either the party using the one or more end-user stations at the first enterprise location or the party using the one or more end-user stations at the second enterprise location.

17. The virtual private telephone network as defined in claim 1 wherein said action of conducting the call in encrypted mode, to be performed in association with the second enterprise location, is performed without encrypting actions being taken by the party using the one or more end-user stations at the second enterprise location or the party using the one or more end-user stations at the first enterprise location.

18. A method for providing encrypted transport of a call across a public switched telephone network (PSTN) from a first enterprise location to a second enterprise location, said method being implemented between one or more end-user stations located at the first enterprise location and one or more end-user stations located at the second enterprise location, said method comprising the steps of:

defining at least one rule associated with the one or more end-user stations located at the first enterprise location;

said at least one rule associated with the one or more end-user stations located at the first enterprise location specifying at least one action associated with the first enterprise location to be performed based on at least one attribute of an incoming or outgoing call to/from the first enterprise location;

defining at least one rule associated with the one or more end-user stations located at the second enterprise location;

said at least one rule associated with the one or more end-user stations located at the second enterprise location specifying at least one action associated with the second enterprise location to be performed based on at least one attribute of the incoming or outgoing call to/from the second enterprise location;

determining said at least one attribute of the incoming or outgoing call to/from the first enterprise location;

said at least one attribute being from a group including:

the call direction,

the call source number,

the call destination number,

the call type,

said call type attribute being defined as one of voice, fax, or data transfer (modem),

the call date,

the call time,

the call duration,

the identifier for the extension or direct connect line carrying the call,

the channel through which the call is processed,

the start date of the call,

the start time of the call,

the end date of the call, and

the end time of the call;

determining said at least one attribute of the incoming or outgoing call to/from the second enterprise location;

said at least one attribute being from a group including:

the call direction,

the call source number,

the call destination number,

the call type,

said call type attribute being defined as one of voice, fax, or data transfer (modem),

the call date,

the call time, the call duration,

the identifier for the extension or direct connect line carrying the call,

the channel through which the call is processed,

the start date of the call,

the start time of the call,

the end date of the call, and

the end time of the call;

performing said at least one action associated with the first enterprise location and specified in said at least one rule associated with the one or more end-user stations located at the first enterprise location;

said at least one action being from a group including:

allowing the call,

denying the call,

conducting the call in encrypted mode,

sending a tone,

sending a message,

logging the call,

generating a report, and

providing an alert; and

performing said at least one action associated with the second enterprise location and specified in said at least one rule associated with the one or more end-user stations located at the second enterprise location;

said at least one action being from a group including:

allowing the call,

denying the call,

conducting the call in encrypted mode,

sending a tone,

sending a message,

logging the call,

generating a report, and

providing an alert.

19. The method as defined in claim 18 wherein said group of attributes in said step of determining said at least one attribute of the incoming or outgoing call to/from the first enterprise location further includes:

the trunk group through which the call is processed,

the digits dialed prior to the base phone number,

the digits dialed after the base phone number,

the caller ID identifier,

the call connect time,

the keywords detected in the call content, and

the digits dialed after call connect.

20. The method as defined in claim 18 wherein said group of attributes in said step of determining said at least one attribute of the incoming or outgoing call to/from the second enterprise location further includes:

the trunk group through which the call is processed,

the digits dialed prior to the base phone number,

the digits dialed after the base phone number,

the caller ID identifier,

the call connect time,

the keywords detected in the call content, and

the digits dialed after call connect.

21. The method as defined in claim 18 wherein said step of defining at least one rule associated with the one or more end-user stations located at the first enterprise location effects the encryption of all calls.

22. The method as defined in claim 18 wherein said step of defining at least one rule associated with the one or more end-user stations located at the second enterprise location effects the encryption of all calls.

23. The method as defined in claim 18 further including the step of performing at least one additional action associated with the first enterprise location responsive to the success or failure of conducting the call in encrypted mode;

said at least one additional action being from a group including:

allowing the call,

denying the call,

sending a tone,

sending a message,

adjusting the security policy,

logging the call,

generating a report, and

providing an alert.

24. The method as defined in claim 18 further including the step of performing at least one additional action associated with the second enterprise location responsive to the success or failure of conducting the call in encrypted mode;

said at least one additional action being from a group including:

allowing the call,

denying the call,

sending a tone,

sending a message,

adjusting the security policy,

logging the call,

generating a report, and

providing an alert.

25. The method as defined in claim 18 wherein said action of adjusting the security policy in said step of performing said at least one action associated with the first enterprise location includes changing, in accordance with said at least one rule associated with the one or more end-user stations located at the first enterprise location, one or more actions and/or one or more additional actions to be performed on all future incoming or outgoing calls to/from the one or more end-user stations at the first enterprise location.

26. The method as defined in claim 18 wherein said action of adjusting the security policy in said step of performing said at least one action associated with the second enterprise location includes changing, in accordance with said at least one rule associated with the one or more end-user stations located at the second enterprise location, one or more actions and/or one or more additional actions to be performed on all future incoming or outgoing calls to/from the one or more end-user stations at the second enterprise location.

27. The method as defined in claim 18 wherein said action of conducting the call in encrypted mode in said step of performing said at least one action associated with the first enterprise location includes creating a VoIP-compatible packet for transport over the PSTN.

28. The method as defined in claim 18 wherein said action of conducting the call in encrypted mode in said step of performing said at least one action associated with the second enterprise location includes creating a VoIP-compatible packet for transport over the PSTN.

29. The method as defined in claim 18 wherein said step of determining said at least one attribute of the incoming or outgoing call to/from the first enterprise location includes:

using a public branch exchange (PBX) located at the first enterprise location for determining and providing one or more attributes of said at least one attribute of the incoming or outgoing call to/from the first enterprise location.

30. The method as defined in claim 18 wherein said step of determining said at least one attribute of the incoming or outgoing call to/from the second enterprise location includes:

using a public branch exchange (PBX) located at the second enterprise location for determining and providing one or more attributes of said at least one attribute of the incoming or outgoing call to/from the second enterprise location.

31. The method as defined in claim 18 wherein said step of performing said at least one action associated with the first enterprise location includes:

using a PBX located at the first enterprise location to perform one or more actions of said at least one action associated with the first enterprise location.

32. The method as defined in claim 18 wherein said step of performing said at least one action associated with the second enterprise location includes:

using a PBX located at the second enterprise location to perform one or more actions of said at least one action associated with the second enterprise location.

33. The method as defined in claim 18 wherein said action of conducting the call in encrypted mode in said step of performing said at least one action associated with the first enterprise location is performed without encrypting actions being taken by either the party using the one or more end-user stations located at the first enterprise location or the party using the one or more end-user stations located at the second enterprise location.

34. The method as defined in claim 18 wherein said action of conducting the call in encrypted mode in said step of performing said at least one action associated with the second enterprise location is performed without encrypting actions being taken by either the party using the one or more end-user stations located at the second enterprise location or the party using the one or more end-user stations located at the first enterprise location.

35. A method of providing encrypted transport of a call from a first geographically separate location, across a public switched telephone network (PSTN), to a second geographically separate location, said method comprising the steps of:

defining one or more rules associated with an incoming or outgoing call to/from one or more end-user stations located at the first geographically separate location;

said at least one rule associated with the incoming or outgoing call to/from one or more end-user stations located at the first geographically separate location specifying one or more actions associated with the first geographically separate location to be performed based upon one or more attributes of the incoming or outgoing call to/from the first geographically separate location;

said one or more attributes being from a group including:

the call direction,

the call source number,

the call destination number,

the call type,

said call type attribute being defined as one of voice, fax, or data transfer (modem),

the call date,

the call time,

the call duration,

the identifier for the extension or direct connect line carrying the call,

the channel through which the call is processed,

the start date of the call,

the start time of the call,

the end date of the call, and

the end time of the call; and

said one or more actions being from a group including:

allowing the call,

denying the call,

conducting the call in encrypted mode,

sending a tone,

sending a message,

logging the call,

generating a report, and

providing an alert;

defining one or more rules associated with the incoming or outgoing call to/from one or more end-user stations located at the second geographically separate location;

said at least one rule associated with the incoming or outgoing call to/from one or more end-user stations located at the second geographically separate location specifying one or more actions associated with the second geographically separate location to be performed based upon one or more attributes of the incoming or outgoing call to/from the second geographically separate location;

said one or more attributes being from a group including:

the call direction,

the call source number,

the call destination number,

the call type,

said call type attribute being defined as one of a voice, fax, or data transfer (modem),

the call date,

the call time,

the call duration,

the identifier for the extension or direct connect line carrying the call,

the channel through which the call is processed,

the start date of the call,

the start time of the call,

the end date of the call, and

the end time of the call; and

said one or more actions being from a group including:

allowing the call,

denying the call,

conducting the call in encrypted mode,

sending a tone,

sending a message,

logging the call,

generating a report, and

providing an alert;

determining said one or more attributes of the incoming or outgoing call to/from the first geographically separate location;

determining said one or more attributes of the incoming or outgoing call to/from the second geographically separate location;

performing said one or more actions associated with the first geographically separate location in accordance with said one or more rules associated with the incoming or outgoing call to/from one or more end-user stations located at the first geographically separate location; and

performing said one or more actions associated with the second geographically separate location in accordance with said one or more rules associated with the incoming or outgoing call to/from one or more end-user stations located at the second geographically separate location.

36. The method as defined in claim 35 wherein said group of attributes in said step of determining said one or more attributes of the incoming or outgoing call to/from the first geographically separate location further includes:

the trunk group through which the call is processed,

the digits dialed prior to the base phone number,

the digits dialed after the base phone number,

the caller ID identifier,

the call connect time,

the keywords detected in the call content, and

the digits dialed after call connect.

37. The method as defined in claim 35 wherein said group of attributes in said step of determining said one or more attributes of the incoming or outgoing call to/from the second geographically separate location further includes:

the trunk group through which the call is processed,

the digits dialed prior to the base phone number,

the digits dialed after the base phone number,

the caller ID identifier,

the call connect time,

the keywords detected in the call content, and

the digits dialed after call connect.

38. The method as defined in claim 35 wherein said step of defining said one or more rules associated with the incoming or outgoing call to/from one or more end-user stations located at the first geographically separate location effects the encryption of all calls.

39. The method as defined in claim 35 wherein said step of defining said one or more rules associated with the incoming or outgoing call to/from one or more end-user stations located at the second geographically separate location effects the encryption of all calls.

40. The method as defined in claim 35 further including the step of performing one or more additional actions associated with the first geographically separate location responsive to the success or failure of conducting the call in encrypted mode;

said one or more additional actions being from a group including:

allowing the call,

denying the call,

sending a tone,

sending a message,

adjusting the security policy,

logging the call,

generating a report, and

providing an alert.

41. The method as defined in claim 35 further including the step of performing one or more additional actions associated with the second geographically separate location responsive to the success or failure of conducting the call in encrypted mode;

said one or more additional actions being from a group including:

allowing the call,

denying the call,

sending a tone,

sending a message,

adjusting the security policy,

logging the call,

generating a report, and

providing an alert.

42. The method as defined in claim 35 wherein said action of adjusting the security policy in said step of performing said one or more actions associated with the first geographically separate location includes changing, in accordance with said one or more rules associated with the incoming or outgoing call to/from one or more end-user stations located at the first geographically separate location, one or more actions and/or one or more additional actions to be performed on all future incoming or outgoing calls to/from the one or more end-user stations located at the first geographically separate location.

43. The method as defined in claim 35 wherein said action of adjusting the security policy in said step of performing said one or more actions associated with the second geographically separate location includes changing, in accordance with said one or more rules associated with the incoming or outgoing call to/from one or more end-user stations located at the second geographically separate location, one or more actions and/or one or more additional actions to be performed on all future incoming or outgoing calls to/from the one or more end-user stations located at the second geographically separate location.

44. The method as defined in claim 35 wherein said action of conducting the call in encrypted mode in said step of performing said one or more actions associated with the first geographically separate location includes creating a VoIP-compatible packet for transport over the PSTN.

45. The method as defined in claim 35 wherein said action of conducting the call in encrypted mode in said step of performing said one or more actions associated with the second geographically separate location includes creating a VoIP-compatible packet for transport over the PSTN.

46. The method as defined in claim 35 wherein said step of determining said one or more attributes of the incoming or outgoing call to/from the first geographically separate location includes:

using a public branch exchange (PBX) located at the first geographically separate location for determining and providing at least one attribute of said one or more attributes of the incoming or outgoing call to/from the first geographically separate location.

47. The method as defined in claim 35 wherein said step of determining said one or more attributes of the incoming or outgoing call to/from the second geographically separate location includes:

using a public branch exchange (PBX) located at the second geographically separate location for determining and providing at least one attribute of said one or more attributes of the incoming or outgoing call to/from the second geographically separate location.

48. The method as defined in claim 35 wherein said step of performing said one or more actions associated with the first geographically separate location includes:

using a PBX located at the first geographically separate location to perform at least one action of said one or more actions associated with the first geographically separate location.

49. The method as defined in claim 35 wherein said step of performing said one or more actions associated with the second geographically separate location includes:

using a PBX located at the first geographically separate location to perform at least one action of said one or more actions associated with the second geographically separate location.

50. The method as defined in claim 35 wherein said action of conducting the call in encrypted mode in said step of performing said one or more actions associated with the first geographically separate location is performed without encrypting actions being taken by either the party using the one or more end-user stations located at the first geographically separate location or the party using the one or more end-user stations located at the second geographically separate location.

51. The method as defined in claim 35 wherein said action of conducting the call in encrypted mode in said step of performing said one or more actions associated with the second geographically separate location is performed without encrypting actions being taken by either the party using the one or more end-user stations located at the second geographically separate location or the party using the one or more end-user stations located at the first geographically separate location.

Assignments (3)
SECURITY INTEREST Recorded Jun 23, 2014
From: SECURELOGIX CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 033216/0855 →
RELEASE Recorded Nov 19, 2010
From: SILICON VALLEY BANK
To: SECURELOGIX CORPORATION
Reel/Frame 025321/0268 →
SECURITY INTEREST Recorded Oct 10, 2006
From: SECURELOGIX CORPORATION
To: SILICON VALLEY BANK
Reel/Frame 018385/0083 →
Continuity (3)
Continuation 1020096900 · Jul 23, 2002
Provisional Application 6030720900 · Jul 23, 2001
Related Publication 20040218742A1 · Nov 4, 2004