IP Library Granted Patent US 12,192,401
Granted Patent B2
US 12,192,401 · App. 17/689,714 · Granted Jan 7, 2025

Real time switching from unsecured to secured signaling channel

Inventor: Ananda H P (Pune, IN)
Assignee: Avaya Management L.P.
H04M3/205H04L63/166H04L65/1104H04M2203/609
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,192,401
App. No.
17/689,714
Granted
Jan 7, 2025
Kind
B2
Abstract

Calls that can be secure (e.g., are conducted with end-to-end encryption) may originate with some or all of the call being unsecured. Then, upon a triggering event such as a user deciding that sensitive information will be discussed or a “sniffer” determining that the call is being monitored by a spoofed endpoint, triggers a transition of the call from an unsecure connection to a secure connection without terminating and reestablishing the call. Accordingly, an unsecure call, such as one utilizing Transmission Control Protocol (TCP) signaling and Real-Time Transport Protocol (RTP) and transitioned to Transport Layer Security (TLS) and Secure RTP (SRTP) to allow a previously unsecured call to become secured with end-to-end encryption.

Claims (44)

1. A method for securing an ongoing unsecured call, comprising:

establishing a call via a network between a first endpoint and second endpoint, the call comprising a signaling path and a first data channel, wherein the signaling path comprises at least a portion not secured by end-to-end encryption;

receiving a signal at the first endpoint to secure the call;

in response to the signal, sending a first Session Initiation Protocol (SIP) message to the second endpoint;

receiving, in response to the first SIP message, a second SIP message accepting the first SIP message; and

in response to the second SIP message, transitioning the call from the first data channel to a second data channel, wherein the second data channel utilizes end-to-end encryption between the first endpoint and the second endpoint.

2. The method of claim 1 , wherein the first SIP message is sent from the first endpoint to the second endpoint via sending the first SIP message to a server located in the signaling path which, in turn, provides the first SIP message to the second endpoint.

3. The method of claim 1 , wherein the first data channel comprises a Real-Time Transport Protocol (RTP).

4. The method of claim 1 , wherein the second data channel consists entirely of a Secure Real-time transport Protocol (SRTP).

5. The method of claim 1 , wherein the signaling path utilized to establish the first data channel comprises a Transmission Control Protocol (TCP).

6. The method of claim 1 , wherein the signaling path utilized after the second SIP message consists entirely of a Transport Layer Security (TLS) connection.

7. The method of claim 1 , wherein the signal is provided in response to a user selection received on the first endpoint.

8. The method of claim 1 , further comprising:

a sniffer application operable to determine that a spoofed endpoint is a node of the call; and

wherein the sniffer application provides the signal to the first endpoint upon determining that a spoofed endpoint is currently present on the call.

9. A system for securing an ongoing unsecured call, comprising:

a first endpoint comprising a processor and a first network interface to a network;

a second endpoint comprising a processor and a second network interface to the network, wherein the first endpoint and the second endpoint are engaged in a call, via the network, the call comprising a signaling path and a first data channel, wherein the signaling path comprises at least a portion not secured by end-to-end encryption, and wherein the call is initially established without end-to-end encryption;

wherein one of the first endpoint or the second endpoint receives a signal to secure the call;

wherein, in response to the signal, sending, by the one of the first endpoint or the second endpoint that received the signal, a first Session Initiation Protocol (SIP) message to one other of the first endpoint or the second endpoint;

receiving, in response to the first SIP message, a second SIP message accepting the first SIP message; and

in response to the second SIP message, transitioning the call from the first data channel to a second data channel, wherein the second data channel utilizes end-to-end encryption between the first endpoint and the second endpoint.

10. The system of claim 9 , further comprising:

a sniffer comprising a third network interface to the network; and

wherein the sniffer, upon detecting the presence of a spoofed endpoint on the call, provides the signal to the one of the first endpoint or the second endpoint.

11. The system of claim 9 , wherein the first SIP message is sent from the first endpoint to the second endpoint via sending the first SIP message to a server located in the signaling path which, in turn, provides the first SIP message to the second endpoint.

12. The system of claim 9 , wherein the first data channel comprises of a Real-Time Transport Protocol (RTP).

13. The system of claim 9 , wherein the second data channel consists entirely of a Secure Real-time Transport Protocol (SRTP).

14. The system of claim 9 , wherein the signaling path utilized to establish the first data channel comprises a Transmission Control Protocol (TCP).

15. The system of claim 9 , wherein the signaling path utilized after the second SIP message consists entirely of a Transport Layer Security (TLS) connection.

16. The system of claim 9 , further comprising a user input component on the one of the first endpoint or the second endpoint and wherein the signal is provided in response a user selection received by the user input component.

17. A communications endpoint, comprising:

a processor comprising instructions maintained in a non-transitory memory;

a network interface to a network for communicating thereon; and

wherein the processor:

receives a signal to secure a call, via the network, the call comprising a signaling path and a first data channel, wherein the signaling path comprises at least a portion not secured by end-to-end encryption, wherein the call comprises an exchange of data packets with a second endpoint, and wherein the call is absent end-to-end encryption;

sends, in response to the signal, a first Session Initiation Protocol (SIP) message to the second endpoint;

receives, in response to the first SIP message, a second SIP message accepting the first SIP message; and

in response to the second SIP message, transitions the call from the first data channel to a second data channel, wherein the second data channel utilizes end-to-end encryption between a first endpoint and the second endpoint.

18. The communications endpoint of claim 17 , wherein the signal is received from the second endpoint.

19. The communications endpoint of claim 17 , wherein the signal is received from a sniffer monitoring the call and in response to the sniffer determining that a spoofed endpoint is on the call.

20. The communications endpoint of claim 17 , further comprising:

a user input component; and

wherein the signal is received by the user input component in response to receiving an input to the user input component.

Assignments (7)
SECURITY INTEREST Recorded Jul 21, 2025
From: AVAYA LLC; AVAYA MANAGEMENT L.P.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071778/0717 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT – SUPPLEMENT NO. 9 Recorded May 27, 2025
From: AVAYA LLC; AVAYA MANAGEMENT L.P.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB, AS COLLATERAL AGENT
Reel/Frame 071395/0200 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT – SUPPLEMENT NO. 3 Recorded May 29, 2024
From: AVAYA LLC (FORMERLY KNOWN AS AVAYA INC.); AVAYA MANAGEMENT L.P.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB, AS COLLATERAL AGENT
Reel/Frame 067559/0295 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 2, 2023
From: AVAYA LLC (F/K/A AVAYA INC.); AVAYA MANAGEMENT L.P.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 065093/0584 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 4, 2023
From: AVAYA INC.; AVAYA MANAGEMENT L.P.; INTELLISIST, INC.
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 063542/0662 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 3, 2023
From: AVAYA MANAGEMENT L.P.; AVAYA INC.; INTELLISIST, INC.; KNOAHSOFT INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB [COLLATERAL AGENT]
Reel/Frame 063742/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 8, 2022
From: H P, ANANDA
To: AVAYA MANAGEMENT L.P.
Reel/Frame 059200/0651 →
Continuity (1)
Related Publication 20230291828A1 · Sep 14, 2023
References Cited (18)
US 8942671B2 · Haynes et al. · 2015 [cited by applicant]
US 20100027793A1 · Maki · 2010 [cited by examiner]
US 20140136718A1 · Menezes · 2014 [cited by examiner]
US 20150188889A1 · Lawson · 2015 [cited by examiner]
US 20160285823A1 · Herrero · 2016 [cited by examiner]
US 20170171257A1 · Zhu · 2017 [cited by examiner]
US 20190302229A1 · Ling · 2019 [cited by examiner]
US 20190372947A1 · Penar · 2019 [cited by examiner]
US 20210194939A1 · Forsyth et al. · 2021 [cited by applicant]
CN 101547269 · 2009 [cited by applicant]
CN 104753889 · 2015 [cited by applicant]
Andreasen et al. “Session Description Protocol (SDP) Capability Negotiation,” IETF Trust, Sep. 2010, RFC 5939, 77 pages. [cited by applicant]
Duke et al. “A Roadmap for Transmission Control Protocol (TCP) Specification Documents,” IETF Trust, Feb. 2015, RFC 7414, 57 pages. [cited by applicant]
Rescorla et al. “The Transport Layer Security (TLS) Protocol Version 1.3,” IETF Trust, Aug. 2018, RFC 8446, 160 pages. [cited by applicant]
Rosenberg et al. “SIP: Session Initiation Protocol,” The Internet Society, Network Working Group, Jun. 2002, RFC 3261, 269 pages. [cited by applicant]
Official Action for United Kingdom Patent Application No. GB2303350.9, dated Sep. 12, 2023 7 pages. [cited by applicant]
Official Action for India Patent Application No. 202314012093, dated Jun. 25, 2024 6 pages. [cited by applicant]
Intention to Grant for United Kingdom Patent Application No. GB2303350.9, dated Jul. 18, 2024 2 pages. [cited by applicant]