A multi-channel communication security system where the information in an original information message is split among a number of channels in accordance with a message splitting routine such that the interception and analysis of any single channel does not compromise the privacy of the communication. The system provides secure communication terminal adapters in cojunction with user terminals for splitting and recombining of private communications together with control facilities in an integrated services digital network (ISDN) for selecting amoung a multiplicity of possible of message splitting routines and generating security code signals for transmission in separate D-channels to the user equipment. |
Citations|
| US1395378 | Sep 29, 1919 | Nov 1, 1921 | | AND JOHN P | | US1542567 | | 1925 | | MATHES | | US1558535 | Feb 1, 1922 | Oct 27, 1925 | | MENTS | | US1565521 | Dec 8, 1920 | Dec 15, 1925 | | AND CLAUSE CUSTER ROSE | | US1596251 | Dec 2, 1922 | Aug 17, 1926 | | SECRET RADIANT TELEPHONY | | US1869659 | Nov 14, 1929 | Aug 2, 1932 | | WJIILEM BROEBTJES | | US1875165 | Jun 11, 1928 | Aug 30, 1932 | | SCHROTER | | US2094132 | Jul 15, 1935 | Sep 28, 1937 | | TELEPHONE SYSTEM | | US3411089 | Jun 28, 1962 | Nov 12, 1968 | | CODE CARD
XI | | US3921151 | Jul 12, 1973 | 1975 | | APPARATUS FOR ENCIPHERING TRANSMITTED | | US3953677 | May 10, 1945 | Apr 27, 1976 | Bell Telephone Laboratories, Incorporated | Key signaling system with multiple pulse generators | | US4004089 | Feb 28, 1975 | Jan 18, 1977 | NCR Corporation | Programmable cryptic device for enciphering and deciphering data | | US4100374 | Apr 11, 1977 | Jul 11, 1978 | Bell Telephone Laboratories, Incorporated | Uniform permutation privacy system | | US4172213 | Nov 17, 1977 | Oct 23, 1979 | Burroughs Corporation | Byte stream selective encryption/decryption device | | US4172968 | Dec 8, 1961 | Oct 30, 1979 | General Atronics Corporation | Electrical system | | US4182933 | Feb 14, 1969 | Jan 8, 1980 | The United States of America as represented by the Secretary of the Army | Secure communication system with remote key setting | | US4200770 | Sep 6, 1977 | Apr 29, 1980 | Stanford University | Cryptographic apparatus and method | | US4223182 | Sep 27, 1944 | Sep 16, 1980 | Bell Telephone Laboratories, Incorporated | Transmission of signals with privacy | | US4275265 | Oct 2, 1978 | Jun 23, 1981 | Wisconsin Alumni Research Foundation | Complete substitution permutation enciphering and deciphering circuit | | US4283599 | Feb 5, 1979 | Aug 11, 1981 | Atalla Technovations | Method and apparatus for securing data transmissions | | US4319079 | Jan 17, 1980 | Mar 9, 1982 | | Crypto microprocessor using block cipher | | US4322577 | Aug 21, 1979 | Mar 30, 1982 | | Cryptosystem | | US4341925 | Apr 28, 1978 | Jul 27, 1982 | | Random digital encryption secure communication system | | US4349695 | Jun 25, 1979 | Sep 14, 1982 | Datotek, Inc. | Recipient and message authentication method and system | | US4357529 | Nov 17, 1980 | Nov 2, 1982 | Atalla Technovations | Multilevel security apparatus and method | | US4393269 | Jan 29, 1981 | Jul 12, 1983 | International Business Machines Corporation | Method and apparatus incorporating a one-way sequence for transaction and identity verification | | US4399323 | Feb 9, 1981 | Aug 16, 1983 | Bell Telephone Laboratories, Incorporated | Fast real-time public key cryptography | | US4411017 | Mar 14, 1980 | Oct 18, 1983 | Harris Corporation | Secure mobile telephone system | | US4418425 | Aug 31, 1981 | Nov 29, 1983 | IBM Corporation | Encryption using destination addresses in a TDMA satellite communications network | | US4423287 | Jun 26, 1981 | Dec 27, 1983 | VISA U.S.A., Inc. | End-to-end encryption system and method of operation | | US4433211 | Nov 4, 1981 | Feb 21, 1984 | Technical Communications Corporation | Privacy communication system employing time/frequency transformation | | US4525844 | May 19, 1982 | Jun 25, 1985 | Licentia Patent-Verwaltungs-GmbH | Method for interchanging n partial bands | | US4534037 | Sep 14, 1982 | Aug 6, 1985 | Robert Bosch GmbH | Method and apparatus for scrambled pulse-code modulation transmission or recording | | US4549308 | Jul 12, 1982 | Oct 22, 1985 | AT&T Bell Laboratories | Secure mobile radio telephony | | US4578530 | Dec 7, 1983 | Mar 25, 1986 | VISA U.S.A., Inc. | End-to-end encryption system and method of operation |
Referenced by|
| US4897874 | Mar 31, 1988 | Jan 30, 1990 | American Telephone and Telegraph Company AT&T Bell Laboratories | Metropolitan area network arrangement for serving virtual data networks | | US4920565 | Jul 18, 1988 | Apr 24, 1990 | Northern Telecom Limited | Method for connection of secure conference calls | | US5008935 | Jun 30, 1989 | Apr 16, 1991 | AT&T Bell Laboratories | Efficient method for encrypting superblocks of data | | US5161186 | Sep 6, 1991 | Nov 3, 1992 | International Business Machines Corporation | System for secure and private communication in a triple-connected network | | US5161193 | Jun 29, 1990 | Nov 3, 1992 | Digital Equipment Corporation | Pipelined cryptography processor and method for its use in communication networks | | US5172413 | Dec 20, 1990 | Dec 15, 1992 | SaskTel | Secure hierarchial video delivery system and method | | US5179592 | Nov 1, 1991 | Jan 12, 1993 | NEC Corporation | Data scrambler and descrambler capable of preventing continuous bit zeros or ones | | US5280529 | Apr 29, 1992 | Jan 18, 1994 | Alcatel STK A/S | Communication network intended for secure transmissions | | US5282208 | Apr 17, 1991 | Jan 25, 1994 | Yamaha Corporation | Data transfer system and method | | US5325419 | Jan 4, 1993 | Jun 28, 1994 | Ameritech Corporation | Wireless digital personal communications system having voice/data/image two-way calling and intercell hand-off | | US5410599 | May 14, 1993 | Apr 25, 1995 | TECSEC, Incorporated | Voice and data encryption device | | US5448698 | Apr 5, 1993 | Sep 5, 1995 | Hewlett-Packard Company | Inter-processor communication system in which messages are stored at locations specified by the sender | | US5459858 | Apr 13, 1992 | Oct 17, 1995 | International Business Machines Corporation | Method for file transfer | | US5465300 | Dec 27, 1993 | Nov 7, 1995 | Motorola, Inc. | Secure communication setup method | | US5469496 | Apr 19, 1994 | Nov 21, 1995 | Bell Atlantic Network Services, Inc. | Personal communications service using wireline/wireless integration | | US5506887 | Mar 31, 1995 | Apr 9, 1996 | Bell Atlantic Network Services, Inc. | Personal communications service using wireline/wireless integration | | US5551032 | Jun 30, 1995 | Aug 27, 1996 | International Business Machines Corporation | Method for file transfer | | US5553146 | Aug 16, 1994 | Sep 3, 1996 | Siemens Aktiengesellschaft | Method for exchanging information between ISDN terminal equipment, that is, data terminals, terminals, or telecommunication systems | | US5579379 | Oct 18, 1994 | Nov 26, 1996 | Bell Atlantic Network Services, Inc. | Personal communications service having a calling party pays capability | | US5588062 | Jul 13, 1995 | Dec 24, 1996 | Motorola, Inc. | Secure communication setup method | | US5610972 | Jun 5, 1995 | Mar 11, 1997 | Bell Atlantic Network Services, Inc. | Personal communications service using wireline/wireless integration | | US5615266 | Jan 11, 1996 | Mar 25, 1997 | Motorola, Inc | Secure communication setup method | | US5621787 | Sep 13, 1995 | Apr 15, 1997 | Bell Atlantic Network Services, Inc. | Prepaid cash card | | US5657375 | Nov 15, 1994 | Aug 12, 1997 | Ameritech Corporation | Wireless digital personal communications system having voice/data/image two-way calling and intercell hand off provided through distributed logic | | US5659684 | Feb 3, 1995 | Aug 19, 1997 | ISDN Systems Corporation | Methods and apparatus for interconnecting personal computers (PCs) and local area networks (LANs) using packet protocols transmitted over a digital data service (DDS) | | US5664005 | Jun 5, 1995 | Sep 2, 1997 | Bell Atlantic Network Services, Inc. | Personal communications service using wireline/wireless integration | | US5692130 | Dec 7, 1995 | Nov 25, 1997 | Ricoh Company, Ltd. | Method for selectively using one or two communication channel by a transmitting data terminal based on data type and channel availability | | US5757924 | Sep 18, 1995 | May 26, 1998 | Digital Secured Networks Techolognies, Inc. | Network security device which performs MAC address translation without affecting the IP address | | US5758281 | Jun 6, 1995 | May 26, 1998 | Bell Atlantic Network Services, Inc. | Personal communications service using wireline/wireless integration | | US5809480 | Aug 30, 1993 | Sep 15, 1998 | | Automated, secure inter authority settlement method and system for electronic toll collection | | US5822433 | Apr 22, 1996 | Oct 13, 1998 | Alcatel N.V. | Method, system and subscriber facility for manipulation-proof separation of message streams | | US6011975 | Oct 16, 1997 | Jan 4, 2000 | Bell Atlantic Network Services, Inc. | Method of personal communications service using wireline/wireless integration detecting a predetermined event during process of a call | | US6058433 | Jul 23, 1996 | May 2, 2000 | Gateway 2000, Inc. | System and method for providing increased throughput through a computer serial port to a modem communications port | | US6137792 | Jun 14, 1996 | Oct 24, 2000 | International Discount Telecommunications Corp. | Method and apparatus for enabling transmission of data packets over a bypass circuit-switched public telephone connection | | US6151679 | Jan 21, 1998 | Nov 21, 2000 | Fortress Technologies Inc. of Florida | System and method for preventing a first node from being emulated by another node | | US6199165 | Mar 31, 1998 | Mar 6, 2001 | Telefonaktiebolaget LM Ericsson (publ) | Method and apparatus for secure data communication | | US6240513 | Dec 31, 1997 | May 29, 2001 | Fortress Technologies, Inc. | Network security device | | US6256491 | Dec 31, 1997 | Jul 3, 2001 | Transcript International, Inc. | Voice security between a composite channel telephone communications link and a telephone | | US6266418 | Oct 28, 1999 | Jul 24, 2001 | L3-Communications Corporation | Encryption and authentication methods and apparatus for securing telephone communications | | US6584562 | Dec 10, 1998 | Jun 24, 2003 | France Telecom | Device for securing a telephone link between two subscriber sets | | US6704866 | Nov 5, 1998 | Mar 9, 2004 | Cisco Technology, Inc. | Compression and encryption protocol for controlling data flow in a network | | US6745231 | Aug 8, 2000 | Jun 1, 2004 | International Business Machines Corporation | System for securing electronic mail | | US6785281 | May 28, 1999 | Aug 31, 2004 | Fujitsu Limited | Method of transferring data via bypass line in connection-type network | | US6937579 | Jul 25, 2003 | Aug 30, 2005 | International Business Machines Corporation | Electronic device connection resource management | | US7013419 | Apr 11, 2002 | Mar 14, 2006 | Mellanox Technologies Ltd. | Reliable message transmission with packet-level resend | | US7171493 | Dec 19, 2001 | Jan 30, 2007 | The Charles Stark Draper Laboratory | Camouflage of network traffic to resist attack | | US7210045 | Aug 19, 2003 | Apr 24, 2007 | Intel Corporation | Storing encrypted and/or compressed system context information when entering a low-power state | | US7350228 | Jan 22, 2002 | Mar 25, 2008 | PortAuthority Technologies Inc. | Method for securing digital content | | US7464121 | Jan 6, 2006 | Dec 9, 2008 | International Business Machines Corporation | Apparatus for sending a sequence of asynchronous messages to the same member of a clustered consumer | | US7539313 | Sep 13, 2001 | May 26, 2009 | Nortel Networks Limited | System and method for key management across geographic domains | | US7548556 | Jun 25, 2008 | Jun 16, 2009 | Raptor Networks Technology, Inc. | Secure communication through a network fabric | | US7620685 | Apr 21, 2004 | Nov 17, 2009 | Microsoft Corporation | Smart shares and transports | | US7929697 | Mar 9, 2004 | Apr 19, 2011 | Thomson Licensing | Secure data transmission via multichannel entitlement management and control | | USRE35651 | Dec 15, 1994 | Nov 4, 1997 | SaskTel | Secure hierarchial video delivery system and method | | USRE38627 | Sep 2, 1997 | Oct 19, 2004 | InterDigital Technology Corp. | High capacity spread spectrum channel |
Claims1. A security arrangement for communicating an information message comprising - a plurality of user stations, and
- a digital switching network for selectively establishing communication channels among said plurality of user stations and including control means responsive to a request in a first signalling channel from a first one of said user stations for a secure call to a second one of said user stations both for controlling the establishment by said digital switching network of first and second ones of said communication channels from said first user station through said digital switching network without security processing to said second user station and for selecting a splitting routine from a plurality of message splitting routines said control means being responsive to said selected splitting routine for transmitting in said first signaling channel a first security code signal defining said selected splitting routine to said first user station and transmitting a second security code signal defining a combining routine associated with said selected splitting routine in a second signaling channel to said second user station, said first and second signaling channels each being distinct from said first and second communication channels, said first user station comprising
- means responsive to said first security code signal defining said selected splitting routine, for splitting said message into first portions and second portions in accordance with said selected splitting routine, and
- means for communicating said first portions and said second portions over said first and second communication channels, respectively, through said digital switching network, and said second user station comprising
- means responsive to said second security code signal defining said combining routine and to a receipt of said first portions and second portions from said first and second communication channels, for reforming said message in accordance with said combining routine.
2. A security arrangement in accordance with claim 1 wherein said first and second communication channels are included in separate circuit-switched channels of said digital switching network. 3. A security arrangement in accordance with claim 1 wherein said first and second communication channels are included in separate logical packet-switched channels of said digital switching network. 4. A security arrangement in accordance with claim 1 wherein said first and second communication channels are included in a single logical packet-switched channel of said digital switching network. 5. A security arrangement in accordance with claim 1 - wherein said splitting means further comprises
- first memory means for storing control information defining the splitting of messages into portions in accordance with a number of splitting routines,
- first processor means responsive to said first security code signal for reading from said first memory means control information defining the splitting of messages in accordance with said selected splitting routine, and
- means responsive to said control information read from said first memory means, for controlling the splitting of said information message into said first portions and said second portions; and
- wherein said reforming means further comprises
- second memory means for storing control information defining the combining of message portions in accordance with a number of combining routines,
second processor means responsive to said second security code signal for reading from said second memory means control information defining the combining of message portions in accordance with said combining routine, - means responsive to said control information read from said second memory means, for combining said first portions and said second portions to reform said information message.
6. A security arrangement in accordance with claim 5 - wherein said communicating means comprises
- means for separately encrypting said first portions and said second portions and
- means for transmitting said encrypted first portions and said encrypted second portions over said first and second communication channels, respective, through said digital switching network; and
- wherein said combining means comprises
- means for separately decrypting said first portions and said second portions and
- means for combining said decrypted first portions and said decrypted second portions to reform said information message.
7. A security arrangement in accordance with claim 6 - wherein said means for separately encrypting said first portions and said second portions comprises means for combining first and second random data with said first portions and said second portions, respectively, and
- wherein said means for separately decrypting said first portions and said second portions comprises means for removing said first and second random data from said first portions and said second portions, respectively.
8. A security arrangement in accordance with claim 6 further comprising - means for transmitting a special character on both of said first and second communication channels, and
- means responsive to a receipt of said special character on both of said first and second communication channels, for enabling said reforming means.
9. A security arrangement in accordance with claim 6 - wherein said communicating means is responsive to the initiation by said splitting means of the splitting of said information message into said first portions and said second portions, for transmitting a first character on said first communication channel before transmitting said first portions, and for transmitting a second character on said second channel before transmitting said second communication portions, where said first and second characters may be identical characters, and
- wherein said combining means is responsive to a receipt of said first character on said first communication channel and said second communication character on said second channel, for initiating the decrypting and combining of said first portions and said second portions.
10. A security arrangement in accordance with claim 6 wherein said network comprises - a circuit switching network,
- wherein said first and second communication channels comprise first and second circuit-switched channels of said circuit switching network.
11. A security arrangement in accordance with claim 10 wherein said first and second circuit-switched channels of said circuit switching network, are transmitted along, physically separate paths. 12. A security arrangement in accordance with claim 6 wherein said network comprises - packet transport means,
- wherein said first and second communication channels comprise first and second logical channels through said packet transport means.
13. A security arrangement in accordance with claim 12 wherein said first and second logical channels are transmitted through said packet transport means along physically separate paths. 14. A security arrangement in accordance with claim 1 - wherein said message comprises a plurality of bits and
- wherein each of said first portions and each of said second portions include at least one of said bits.
15. An arrangement in accordance with claim 1 - wherein said communicating means comprises
- means for separately encrypting said first portions and said second portions and
- means for transmitting said encrypted first portions and said encrypted second portions over said first and second communication channels, respectively, through said digital switching network; and
- wherein said reforming means comprises
- means for separately decrypting said first portions and said second portions and
- means for combining said decrypted first portions and said decrypted second portions to reform said message.
16. A security arrangement in accordance with claim 15 - wherein said means for separately encrypting said first portions and said second portions comprises means for combining first and second random data with said first portions and said second portions, respectively, and
- wherein said means for separately decrypting said first portions and said second portions comprises means for removing said first and second random data from said first portions and said second portions, respectively.
17. A security arrangement in accordance with claim 1 further comprising - means for transmitting a special character on both of said first and second communication channels, and
- means responsive to a receipt of said special character on both of said first and second communication channels, for enabling said reforming means.
18. A security arrangement in accordance with claim 1 - wherein said communicating means is responsive to the initiation by said splitting means of the splitting of said information message into said first portions and said second portions, for transmitting a first character on said first communication channel before transmitting said first portions, and for transmitting a second character on said second communication channel before transmitting said second portions, where said first and second characters may be identical characters, and
- wherein said reforming means is responsive to a receipt of said first character on said first communication channel and said second character on said second communication channel, for initiating the reforming of said information message.
19. A security arrangement in accordance with claim 1 wherein said network comprises - a circuit switching network,
- wherein said first and second communication channels comprise first and second circuit-switched channels of said circuit switching network.
20. A security arrangement in accordance with claim 19 wherein said first and second circuit-switched channels of said circuit switching network, are transmitted along physically separate paths. 21. A security arrangement in accordance with claim 1 wherein said network comprises - packet transport means,
- wherein said first and second channels comprise first and second logical channels through said packet transport means.
22. A security arrangement in accordance with claim 21 wherein said first and second logical channels are transmitted through said packet transport means along physically separate paths. 23. A security arrangement for communicating a message comprising - a plurality of user stations, and
- a digital switching network for selectively establishing communication channels among said plurality of user stations and including control means responsive to a request in a first signaling channel from a first one of said user stations for a secure call to a second one of said user stations both for controlling the establishment by said digital switching network of N of said communication channels from said first user station through said digital switching network without security processing to said second user station, N being a positive integer greater than one, and for selecting a splitting routine from a plurality of message splitting routines, said control means being responsive to said selected splitting routine for transmitting in said first signaling channel a first security code signal defining said selected splitting routine to said first user station and transmitting a second security code signal defining a combining routine associated with said selected splitting routine in a second signaling channel to said second user station, said first and second signaling channels each being distinct from said N communication channels, said first user station comprising
- means responsive to said first security code signal defining said selected splitting routine, for splitting said message into N components in accordance with said selected splitting routine, and
- means for transmitting each of said N components on an associated one of said N communication channels through said digital switching network, and said second user station comprising
- means responsive to said second security code signal defining said combining routine and to a receipt of said N components on said N communication channels, for combining said N components in accordance with said combining routine to reform said message.
24. A security arrangement in accordance with claim 23 wherein - said splitting means further comprises
- first memory means for storing control information defining the splitting of messages into components in accordance with a number of splitting routines,
- first processor means responsive to said first security code signal for reading from said first memory means control information defining the splitting of messages in accordance with said selected splitting routine, and
- means responsive to said control information read from said first memory means, for controlling the splitting of said message into said N components; and
- wherein said combining means further comprises
- second memory means for storing control information defining the combining of message components in accordance with a number of combining routines,
- second processor means responsive to said second security code signal for reading from said second memory means control information defining the combining of message components in accordance with said combining routine associated with said selected splitting routine, and
- means responsive to said control information read from said second memory means for controlling the combining of said N components to reform said message.
25. A security arrangement in accordance with claim 24 - wherein said means for transmitting each of said N components comprises
- means for separately encrypting each of said N components and
- means for transmitting each of said N encrypted components on an associated one of said N communication channels; and
- wherein said combining means comprises
- means for separately decrypting each of said N received components and
- means for combining said N decrypted components to reform said message.
26. A security arrangement for communicating the information in N packets, N being a positive integer, said arrangement comprising - a plurality of user stations, and
- a digital switching network for selectively establishing communication channels among said plurality of user stations and including control means responsive to a request in a first signaling channel from a first one of said stations for a secure call to a second one of said user stations both for controlling the establishment by said digital switching network of at least one of said communication channels from said first user station through said digital switching network without security processing to said second user station and for selecting a splitting routine from a plurality of packet splitting routines, said control means being responsive to said selected splitting routine for transmitting in said first signaling channel a first security code signal defining said selected splitting routine to said first user station and transmitting a second security code signal defining a combining routine associated with said selected splitting routine in a second signaling channel to said second user station, said first and second signaling channels each being distinct from said at least one communication channel, said first user station comprising
- means responsive to said first security code signal defining said selected splitting routine, for splitting each of said N packets among M packets in accordance with said selected splitting routine, M being a positive integer greater than one, and
- means for transmitting said M packets on said at least one communication channel through said digital switching network, and said second user station comprising
- means responsive to said second security code signal defining said combining routine and to a receipt of said M packets on said at least one communication channel, for combining information from each of said M received packets in accordance with said combining routine to reform each of said N packets.
27. A security arrangement in accordance with claim 26 - wherein said splitting means further comprises
- first memory means for storing control information defining the splitting of individual packets among multiple packets in accordance with a number of packet splitting routines,
- first processor means responsive to said first security code signal for reading from said first memory means control information defining the splitting of packets in accordance with said selected splitting routine, and
- means responsive to said control information read from said first memory means, for controlling the splitting of each of said N packets among said M packets; and
- wherein said combining means further comprises
- second memory means for storing control information defining the combining of information from multiple packets into individual packets in accordance with a number of combining routines,
- second processor means responsive to said second security code signal for reading from said second memory means control information defining the combining of information from multiple packets in accordance with said combining routine associated with said selected splitting routine, and
- means responsive to said control information read from said second memory means for controlling the combining of said information from each of said M packets to reform each of said N packets.
28. A security arrangement in accordance with claim 27 - wherein said means for transmitting said M packets comprises
- means for separately encrypting each of said M packets and
- means for transmitting said M encrypted packets on said at least one communication channel; and
- wherein said combining means comprises
- means for separately decrypting each of said M received packets and
- means for combining information from said M decrypted packets, to reform each of said N packets.
29. In a switching arrangement for providing switched connections among a plurality of user stations each having a plurality of channels contemporaneously available for communication, a security method of communication a message from an originating one of said user stations to a terminating one of said stations comprising - transmitting, by said originating user station, a request to said switching arrangement for a secure call from said originating user to said terminating user stations,
- providing, by said switching arrangement in response to said request, a first connection without security processing between a first one of said channels of said originating user station and a first one of said channels of said terminating user station,
- providing, by said switching arrangement in response to said request, a second connection without security processing between a second one of said channels of said originating user station and a second one of said channels of said terminating user station,
- selecting, by said switching arrangement in response to said request, a splitting routine from a plurality of message splitting routines,
- transmitting, by said switching arrangement, a first security code signal defining said selected splitting routine to said originating user station,
- transmitting, by said switching arrangement, a second security code signal defining a combining routine associated with said selected splitting routine to said terminating user station,
- splitting by said originating user station in response to said first security code signal, said message into first portions and second portions in accordance with said selected splitting routine,
- separately encrypting, by said originating user station, said first portions and said second portions,
- transmitting, by said originating user station in its first channel, said encrypted first portions to said first connection,
- transmitting, by said originating user station in its second channel, said encrypted second portions to said second connection,
- receiving, by said terminating user station in its first channel, said encrypted first portions from said first connection,
- receiving, by said terminating user station in its second channel, said encrypted second portions from said second connection,
- separately decrypting, by said terminating user station, said received encrypted first portions and said received encrypted second portions and
- combining, by said terminating user station in response to said second security code signal, said decrypted first portions and said decrypted second portions in accordance with said combining routine to reform said message.
30. In an arrangement comprising - a first switch serving a first user station,
- a first plurality of user channels between said first user station and said first switch,
- a second switch serving a second user station and
- a second plurality of user channels between said second user station and said second switch,
- a security method of communicating a message from said first user station to said second user station,
- said first user station transmitting a call request in a given one of said first plurality of channels to said first switch, said call request defining a secure call to said second user station,
- said first switch transmitting said call request to said second switch,
- a given one of said first and second switches selecting one of a plurality of message splitting routines for splitting said message among predetermined ones of said first plurality of channels each being distinct from said given one of said first plurality of channels,
- said given switch transmitting a definition of said selected splitting routine to the other one of said first and second switches,
- said first switch transmitting said definition of said selected splitting routine in said given one of said first plurality of channels to said first user station,
- said second switch transmitting said definition of said selected splitting routine in a given one of said second plurality of channels to said second user station,
- said first and second switches connecting without security processing of information from said predetermined ones of said first plurality of channels to corresponding ones of said second plurality of channels each being distinct from said given one of said second plurality of channels,
- said first user station transmitting said message on said predetermined ones of said first plurality of channels in accordance with said selected splitting routine, and
- said second user station combining information received on said corresponding ones of said second plurality of channels in accordance with a combining routine that is the inverse of said selected splitting routine.
31. In an arrangement comprising a plurality of user stations, an integrated services digital network for providing digital connections among said user stations, and a plurality of user access lines each connecting an associated one of said user stations with said network, each of said user access lines having at least first and second B-channels and a D-channel thereon, said D-channel being distinct from said first and second B-channels, - a security method of communicating a message from a first one of said user stations having an associated first user access line, to a second one of said user stations having an associated second user access line, said method comprising
- said first user station transmitting in the D-channel of said first user access line, a secure call request to said network, said secure call request defining a secure call to said second user station,
- said network selecting, in response to said secure call request, one of a plurality of message splitting routines for splitting said message between the first and second B-channels of said first user access line,
- said network providing a circuit-switched connection without security processing from said first B-channel of said first user access line to the first B-channel of said second user access line, and providing a circuit-switched connection without security processing from said second B-channel of said first user access line to the second B-channel of said second user access line,
- said network transmitting a definition of said selected splitting routine to said first user station in said D-channel of said first user access line, and to said second user station in the D-channel of said second user access line,
- said first user station transmitting said message in said first and second B-channels of said first user access line in accordance with said selected splitting routine and
- said second user station combining information received in said first and second B-channels of said second user access line in accordance with a combining routine that is the inverse of said selected splitting routine.
32. In an arrangement comprising a plurality of user stations, an integrated services digital network for providing digital connections among said use stations, and a plurality of user access lines each connecting an associated one of said user stations with said network, each of said user access lines having at least a D-channel thereon, said D-channel including a signaling channel and a plurality of logical data channels, said signaling channel being distinct from said logical data channels, - a security method of communicating a message from a first one of said user stations having an associated first user access line, to a second one of said user stations having an associated second user access line, said method comprising
- said first user station transmitting in the signaling channel of said first user access line, a secure call request to said network, said secure call request defining a secure call to said second user station,
- said network selecting, in response to said secure call request, one of a plurality of message splitting routines for splitting said message among logical data channels of said first user access line,
- said network providing packet-switched connections without security processing from said logical data channels of said first user access line to logical data channels of said second use access line,
- said network transmitting a definition of said selected splitting routine to said first user station in said signaling channel of said first user access line, and to said second user station in the signaling channel of said second user access line,
- said first user station transmitting said message in said logical data channels of said first user access line in accordance with said selected splitting routine and
- said second user station combining information received in said logical data channels of said second user access line in accordance with a combining routine that is the inverse of said selected splitting routine.
33. In an arrangement comprising a plurality of user stations, an integrated service digital network for providing digital connections among said user stations, and a plurality of user access lines each connecting an associated one of said user stations with said network, each of said user access lines having at least a D-channel thereon, said D-channel including a signaling channel and at least one logical data channel, said signaling channel being distinct from said logical data channel, - a security method of communicating a message from a first one of said user stations having an associated first user access line, to a second one of said user stations having an associated second user access line, said method comprising
- said first user station transmitting in the signaling channel of said first user access line, a secure call request to said network, said secure call request defining a secure call to said second user station,
- said network selecting, in response to said secure call request, one of a plurality of message splitting routines for splitting said message among a plurality of packets to be transmitted in a logical data channel of said first user access line,
- said network providing a packet-switched connection without security processing from said logical data channel of said first user access line to a logical data channel of said second user access line,
- said network transmitting a definition of said selected splitting routine to said first user station in said signaling channel of said first user access line, and to said second user station in the signaling channel of said second user access line,
- said first user station transmitting said message in said plurality of packets in said logical data channel of said first user access line in accordance with said selected splitting routine and
- said second user station combining information received in said plurality of packets in said logical data channel of said second user access line in accordance with a combining routine that is the inverse of said selected splitting routine.
34. Apparatus for secure communication of messages between different ones of a plurality of user stations interconnected via a switching arrangement wherein said switching arrangement comprises - means responsive to a request in a first signaling channel from a first one of said stations for a secure call to a second one of said stations for establishing first and second communication channels without security processing through said switching arrangement between said first and second stations, said first signaling channel being distinct from said first and second communication channels,
- means responsive to said request for selecting one of plurality of message splitting routines,
- means for storing data defining, for each of said plurality of stations, security code signals defining to said each station said plurality of splitting routines,
- means responsive to said request and said selection, for reading said stored data to determine a first security code signal defining said selected splitting routine to said first station and a second security code signal defining a combining routine associated with said selected splitting routine to said second station,
- means for transmitting said first security code signal in said first signaling channel to said first station and
- means for transmitting said second security code signal in a second signaling channel to said second station, said second signaling channel being distinct from said first and second communication channels,
- wherein said first station comprises means responsive to said first security code signal for splitting a message into first portions and second portions in accordance with said selected splitting routine and means for transmitting said first portions and said second portions over said first and second communication channels, respectively, and
- wherein said second station comprises means responsive to said second security code signal and to a receipt of said first and second portions from said first and second communication channels, for reforming said message in accordance with said combining routine associated with said selected splitting routine.
|