IP Library Granted Patent US 8,689,301
Granted Patent B2
US 8,689,301 · App. 12/242,105 · Granted Apr 1, 2014

SIP signaling without constant re-authentication

Inventors: Frank J. Boyle (Denver, CO); Gordon Brunson (Broomfield, CO); David Chavez (Broomfield, CO); Stephen Durney (Broomfield, CO); Gregory Weber (Westminster, CO)
Assignee: Avaya Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,689,301
App. No.
12/242,105
Granted
Apr 1, 2014
Kind
B2
Abstract

A proxy server causes an authentication authority to authenticate a client in response to a first Session Initiation Protocol (SIP) request of the client on a connection. It does not cause the client to be authenticated in response subsequent requests on the connection as long as the underlying connection is not broken, the subsequent requests are on behalf of the same client, the client has not been removed from the system, the client's password has not changed, a “safety net” timer has not expired, or any other policy that the server chooses to enforce. This eliminates the overhead of constant re-authentication in response to each SIP request.

Claims (90)

1. A method of authenticating SIP signaling comprising:

in response to a first request of a client on a communication connection to initiate a voice call over the communication connection, authenticating the client and associating the client, in a record, with a first identifier for the connection included in the first request;

in response to at least one second request of the client on the connection and subsequent to the first request, forbearing from authenticating the client, wherein forbearing from authenticating the client comprises determining, based on the record, whether a second identifier for the connection included in the second request matches the first identifier and forbearing from authenticating the client in response to determining that the second identifier matches the first identifier; and

in response to a third request of the client on the connection and subsequent to the at least one second request, authenticating the client, wherein authenticating the client comprises determining, based on the record, whether a third identifier for the connection in the third request does not match the first identifier and authenticating the client in response to determining that the third identifier does not match the first identifier.

2. The method of claim 1 further comprising:

in response to successfully authenticating the client, complying with the request; and

in response to unsuccessfully authenticating the client, forbearing from complying with the request.

3. The method of claim 2 further comprising:

in response to unsuccessfully authenticating the client, tearing down the connection.

4. The method of claim 1 wherein:

the first, the at least one second, and the third request are made via a TCP/IP model application-layer protocol.

5. The method of claim 4 wherein:

the protocol is SIP.

6. The method of claim 5 wherein:

the first request comprises a first SIP invite, the second request comprises a second SIP invite, and the third request comprises a third SIP invite.

7. The method of claim 4 wherein the transport layer protocol is a secure protocol.

8. The method of claim 1 wherein:

forbearing from authenticating the client further comprises

in response to determining that the second identifier matches the first identifier, determining whether the authentication of the client has expired, and

in response to determining that the authentication of the client has not expired, forbearing from authenticating the client; wherein

the method further comprises

in response to determining that the authentication of the client has expired, authenticating the client.

9. The method of claim 1 wherein:

forbearing from authenticating the client further comprises

in response to determining that the second identifier does not match the first identifier, authenticating the client.

10. The method of claim 1 wherein:

forbearing from authenticating the client comprises

in response to determining that the second identifier matches the first identifier, determining whether either (a) either an identifier of the client has changed from the first request or (b) the authentication of the client has expired, and

in response to determining that both (a) the identifier of the client has not changed and (b) the authentication of the client has not expired, forbearing from authenticating the client; wherein the method further comprises

in response to determining that either (a) either the identifier of the client has changed or (b) the authentication of the client has expired, authenticating the client.

11. The method of claim 1 wherein:

the first, the at least one second, and the third request are made via a TCP/IP model application-layer protocol.

12. The method of claim 1 wherein:

the first, the at least one second, and the third request are made via SIP.

13. The method of claim 1 wherein:

authenticating the client comprises

in response to an individual one of the first or the third request of the client, sending a request to an authentication authority for a challenge;

in response to receiving a response to the challenge from the client, determining whether the response is correct;

in response to determining that the response is correct, complying with the individual request; and

in response to determining that the response is not correct, forbearing from complying with the individual request.

14. A method comprising:

in response to a first SIP request of a client on a communication connection with a proxy server, authenticating the client and associating the client, in a record, with a first identifier for the connection included in the first SIP request;

in response to at least a second SIP request of the client on the connection and subsequent to the first SIP request, forbearing from authenticating the client, wherein forbearing from authenticating the client comprises determining, based on the record, whether a second identifier for the connection included in the second SIP request matches the first identifier and forbearing from authenticating the client in response to determining that the second identifier matches the first identifier; and

in response to at least a third SIP request of the client on the connection and subsequent to the at least one second SIP request, authenticating the client, wherein authenticating the client comprises determining, based on the record, whether a third identifier for the connection in the third SIP request does not match the first identifier and authenticating the client in response to determining that the third identifier does not match the first identifier.

15. A non-transitory computer storage medium storing computer-readable instructions which, when executed by the computer, perform the method of one of claims 1 - 14 .

16. A server comprising:

means responsive to a first SIP invite of a client on a communication connection to initiate a voice call over the communication connection, for authenticating the client and associating the client, in a record, with a first identifier for the connection included in the first SIP invite;

means responsive to at least one second SIP invite of the client on the connection and subsequent to the first SIP invite, for forbearing from authenticating the client, wherein forbearing from authenticating the client comprises determining, based on the record, whether a second identifier for the connection included in the second SIP invite matches the first identifier and forbearing from authenticating the client in response to determining that the second identifier matches the first identifier; and

means responsive to a third SIP invite of the client on the connection and subsequent to the at least one second SIP invite, for authenticating the client, wherein authenticating the client comprises determining, based on the record, whether a third identifier for the connection in the third SIP invite does not match the first identifier and authenticating the client in response to determining that the third identifier does not match the first identifier.

17. The server of claim 16 wherein:

the server is a proxy server.

18. An apparatus comprising:

a server adapted to respond to a first SIP invite of a client on a communication connection to initiate a voice call over the communication connection by authenticating the client and associating the client, in a record, with a first identifier for the connection included in the first SIP invite, adapted to respond to at least one second SIP invite of the client on the connection and subsequent to the first SIP invite by forbearing from authenticating the client, wherein forbearing from authenticating the client comprises determining, based on the record, whether a second identifier for the connection included in the second SIP invite matches the first identifier and forbearing from authenticating the client in response to determining that the second identifier matches the first identifier, and adapted to respond to a third SIP invite of the client on the connection and subsequent to the at least one second SIP invite by authenticating the client, wherein authenticating the client comprises determining, based on the record, whether a third identifier for the connection in the third SIP invite does not match the first identifier and authenticating the client in response to determining that the third identifier does not match the first identifier; and

an authentication authority adapted to cooperate with the server to authenticate the client.

19. An apparatus for authenticating SIP signaling comprising:

a store for storing instructions; and

a processor for executing the instructions;

wherein the store and the processor together form a server adapted to respond to a first request of a client on a communication connection to initiate a voice call over the communication connection by authenticating the client and associating the client, in a record, with a first identifier for the connection included in the first request, to respond to at least one second request of the client on the connection and subsequent to the first request by forbearing from authenticating the client, wherein forbearing from authenticating the client comprises determining, based on the record, whether a second identifier for the connection included in the second request matches the first identifier and forbearing from authenticating the client in response to determining that the second identifier matches the first identifier, and to respond to a third request of the client on the connection and subsequent to the at least one second request by authenticating the client, wherein authenticating the client comprises determining, based on the record, whether a third identifier for the connection in the third request does not match the first identifier and authenticating the client in response to determining that the third identifier does not match the first identifier.

20. The apparatus of claim 19 wherein:

the server is further adapted to respond to successfully authenticating the client by complying with the request, and to respond to unsuccessfully authenticating the client by forbearing from complying with the request.

21. The apparatus of claim 20 wherein:

the server is further adapted to respond to unsuccessfully authenticating the client by tearing down the connection.

22. The apparatus of claim 19 wherein:

the server is adapted to receive the first, the at least one second, and the third request via a TCP/IP model application-layer protocol.

23. The apparatus of claim 22 wherein:

the protocol is SIP.

24. The apparatus of claim 23 wherein:

the first request comprises a first SIP invite, the second request comprises a second SIP invite, and the third request comprises a third SIP invite.

25. The apparatus of claim 22 wherein:

the transport layer protocol is a secure protocol.

26. The apparatus of claim 19 wherein:

the server is adapted to forbear from authenticating the client by (a) in response to determining that the second identifier matches the first identifier, determining whether the authentication of the client has expired, and (b) in response to determining that the authentication of the client has not expired, forbearing from authenticating the client; and wherein

the server is further adapted to respond to determining that the authentication of the client has expired, by authenticating the client.

27. The apparatus of claim 19 wherein:

the server is further adapted to respond to determining that the second identifier does not match the first identifier, by authenticating the client.

28. The apparatus of claim 19 wherein:

the server is adapted to forbear from authenticating the client by (a) in response to determining that the second identifier matches the first identifier, determining whether either (1) either an identifier of the client has changed from the first request or (2) the authentication of the client has expired, and (b) in response to determining that both (1) the identifier of the client has not changed and (2) the authentication of the client has not expired, by forbearing from authenticating the client; and wherein

the server is further adapted to respond to determining that either (1) either the identifier of the client has changed or (2) the authentication of the client has expired, by authenticating the client.

29. The apparatus of claim 19 wherein:

the server is adapted to receive the first, the at least one second, and the third request via a TCP/IP model application-layer protocol.

30. The apparatus of claim 19 wherein:

the server is adapted to receive the first, the at least one second, and the third request via SIP.

31. The apparatus of claim 19 wherein:

the server is adapted to authenticate the client by (a) in response to an individual one of the first or the third request of the client, sending a request to an authentication authority for a challenge, (b) in response to receiving a response to the challenge from the client, forwarding the response to the authentication authority for determining whether the response is correct; (c) and wherein

the server is further adapted to respond to a determination that the response is correct by complying with the individual request, and to respond to a determination that the response is not correct by forbearing from complying with the individual request.

32. The apparatus of claim 19 wherein:

the server comprises a proxy server;

the first request is a first SIP request of a client on a communication connection with a proxy server;

the at least one second request is at least one second SIP request of the client on the connection and subsequent to the first SIP request; and

the third request is a third SIP request of the client on the connection and subsequent to the at least one second SIP request.

Assignments (23)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 4, 2024
From: AVAYA LLC
To: ARLINGTON TECHNOLOGIES, LLC
Reel/Frame 067022/0780 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: CITIBANK, N.A.
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0117 →
INTELLECTUAL PROPERTY RELEASE AND REASSIGNMENT Recorded Mar 25, 2024
From: WILMINGTON SAVINGS FUND SOCIETY, FSB
To: AVAYA LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 066894/0227 →
(SECURITY INTEREST) GRANTOR'S NAME CHANGE Recorded Sep 21, 2023
From: AVAYA INC.
To: AVAYA LLC
Reel/Frame 065019/0231 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 045034/0001) Recorded May 18, 2023
From: GOLDMAN SACHS BANK USA., AS COLLATERAL AGENT
To: AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC. (FORMER NAME OF AVAYA CLOUD INC.); HYPERQUALITY, INC.; HYPERQUALITY II, LLC; CAAS TECHNOLOGIES, LLC; AVAYA MANAGEMENT L.P.
Reel/Frame 063779/0622 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 53955/0436) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063705/0023 →
RELEASE OF SECURITY INTEREST IN PATENTS (REEL/FRAME 61087/0386) Recorded May 18, 2023
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063690/0359 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS AT REEL 45124/FRAME 0026 Recorded Apr 26, 2023
From: CITIBANK, N.A., AS COLLATERAL AGENT
To: AVAYA HOLDINGS CORP.; AVAYA INC.; AVAYA MANAGEMENT L.P.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
Reel/Frame 063457/0001 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 5, 2022
From: AVAYA INC.; INTELLISIST, INC.; AVAYA MANAGEMENT L.P.; AVAYA CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 061087/0386 →
SECURITY INTEREST Recorded Sep 25, 2020
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 053955/0436 →
SECURITY INTEREST Recorded Jan 23, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 045124/0026 →
SECURITY INTEREST Recorded Jan 10, 2018
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS LLC; OCTEL COMMUNICATIONS LLC; VPNET TECHNOLOGIES, INC.; ZANG, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 045034/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 030083/0639 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 045012/0666 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 029608/0256 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
To: AVAYA INC.
Reel/Frame 044891/0801 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 025863/0535 Recorded Dec 15, 2017
From: THE BANK OF NEW YORK MELLON TRUST, NA
To: AVAYA INC.
Reel/Frame 044892/0001 →
BANKRUPTCY COURT ORDER RELEASING ALL LIENS INCLUDING THE SECURITY INTEREST RECORDED AT REEL/FRAME 041576/0001 Recorded Dec 15, 2017
From: CITIBANK, N.A.
To: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS LLC (FORMERLY KNOWN AS OCTEL COMMUNICATIONS CORPORATION); VPNET TECHNOLOGIES, INC.
Reel/Frame 044893/0531 →
SECURITY INTEREST Recorded Jan 27, 2017
From: AVAYA INC.; AVAYA INTEGRATED CABINET SOLUTIONS INC.; OCTEL COMMUNICATIONS CORPORATION; VPNET TECHNOLOGIES, INC.
To: CITIBANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 041576/0001 →
SECURITY AGREEMENT Recorded Mar 13, 2013
From: AVAYA, INC.
To: BANK OF NEW YORK MELLON TRUST COMPANY, N.A., THE
Reel/Frame 030083/0639 →
SECURITY AGREEMENT Recorded Jan 10, 2013
From: AVAYA, INC.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 029608/0256 →
SECURITY AGREEMENT Recorded Feb 22, 2011
From: AVAYA INC., A DELAWARE CORPORATION
To: BANK OF NEW YORK MELLON TRUST, NA, AS NOTES COLLATERAL AGENT, THE
Reel/Frame 025863/0535 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 30, 2008
From: BOYLE, FRANK J.; BRUNSON, GORDON; CHAVEZ, DAVID; DURNEY, STEPHEN; WEBER, GREGORY
To: AVAYA INC
Reel/Frame 021610/0486 →
Continuity (1)
Related Publication 20100082977A1 · Apr 1, 2010