A method and system for session copy-based sip session protection
By assessing the quality of user-end SIP sessions and establishing channels, a defense mechanism was built to solve the problem of session interruption caused by single-node failure in the SIP network, thus achieving the stability and security of SIP sessions.
Patent Information
- Application Number
- CN202210949816.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-09
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2042-08-09
AI Technical Summary
The small capacity, low reliability, and low stability of individual nodes in existing SIP networks lead to SIP call interruptions or dropouts, increasing the network burden.
Collect user SIP sessions on the user-end SIP server, conduct quality assessments, determine the session content that needs protection, establish channels between SIP servers, and build a defense mechanism to protect the session content.
This enables a backup SIP entity to provide services in place of the primary SIP entity when the SIP server fails, avoiding SIP session interruption and improving session quality and security.
Smart Images

Figure CN115514516B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the SIP session technical field, in particular to a SIP session protection method and system based on session copy. BACKGROUND
[0002] At present, SIP is an application layer signaling control protocol, which is used to create, modify and release a session of one or more participants. SIP protocol is widely used in soft switch and IMS. In these telecommunication networks, it is generally considered that the core network has large capacity and high reliability, and the session protection can be realized in the network element, and the session protection between network elements is generally not considered. In some SIP networks, the capacity of single node is small, and the reliability and stability are relatively low. When the nodes fail, the SIP call of the user in progress is interrupted or even exited, thereby increasing unnecessary call reconnection and the burden of the whole network. SUMMARY
[0003] The present application provides a SIP session protection method and system based on session copy, which is used to solve the problems in the background.
[0004] The present application provides a SIP session protection method based on session copy, comprising:
[0005] collecting the SIP session of the user of the user terminal SIP server, quality evaluating the SIP session of the user, and determining the SIP session content to be protected;
[0006] copying the SIP session content to be protected, and establishing a channel between the SIP servers of the SIP session content to be protected;
[0007] constructing a defense mechanism on the channel, and protecting the SIP session content to be protected based on the defense mechanism.
[0008] As an embodiment of the present application, the collecting the SIP session of the user of the user terminal SIP server, quality evaluating the SIP session of the user, and determining the SIP session content to be protected, comprises:
[0009] obtaining the session distribution characteristics according to the SIP session process of the user terminal SIP server;
[0010] quality evaluating the session distribution characteristics based on the preset quality evaluation index, and determining the evaluation result;
[0011] wherein, the quality evaluation index at least comprises a flow evaluation index, a credibility evaluation index and a distribution steady state evaluation index;
[0012] The SIP session content is scored according to the evaluation result, and the SIP session content with a score less than a preset standard score is screened to determine the SIP session content that needs to be protected.
[0013] As an embodiment of the technical solution, the copying of the SIP session content that needs to be protected and the establishment of a channel between the SIP servers in the SIP session content that needs to be protected include:
[0014] The SIP session that needs to be protected is acquired, the address information of the user-side SIP server is determined, and the address information is backed up to determine backup address information.
[0015] The request address information in the user request command is collected, the corresponding terminal SIP server is searched through the request address information, a terminal SIP server sequence list is generated, and the address information is transmitted to the terminal SIP server at the first sequence in the terminal SIP server sequence list.
[0016] When the terminal SIP server cannot provide services, the backup address information is sequentially transmitted to the terminal SIP server at the second sequence, and the backup address information is backed up again.
[0017] Until the terminal SIP server can provide services, a channel is established between the user-side SIP server and the terminal SIP server in the SIP session content that needs to be protected.
[0018] As an embodiment of the technical solution, the defense mechanism is constructed on the channel, and the SIP session content that needs to be protected is protected based on the defense mechanism, including:
[0019] The defense mechanism is constructed on the channel, the SIP session content that needs to be protected is monitored through the defense mechanism, and a monitoring result is determined.
[0020] When the monitoring result is a state change between the user-side SIP server and the terminal SIP server, state change information is acquired.
[0021] It is judged whether the state change information is attacked by an external server; wherein,
[0022] When the state change information is attacked by an external server, the address of the external server is tracked through the defense mechanism, and a firewall is automatically started.
[0023] When the state change information is not attacked by an external server, the state change information is recorded and stored in a preset state storage database.
[0024] This invention provides a SIP session protection system based on session copying, comprising:
[0025] The quality assessment module is used to collect user SIP sessions on the user-end SIP server, perform quality assessment on the user SIP sessions, and determine the SIP session content that needs to be protected.
[0026] The channel establishment module is used to copy the SIP session content that needs to be protected and establish a channel between the SIP servers that are communicating in the SIP session content that needs to be protected.
[0027] The defense mechanism module is used to build a defense mechanism on the channel and, based on the defense mechanism, protect the SIP session content that needs to be protected.
[0028] As one embodiment of this technical solution, the quality assessment module includes:
[0029] The session distribution feature unit is used to obtain session distribution features based on the SIP session process of the user-end SIP server.
[0030] An evaluation unit is used to perform a quality evaluation on the session distribution characteristics based on preset quality evaluation indicators and determine the evaluation result.
[0031] The quality assessment indicators include at least flow assessment indicators, reliability assessment indicators, and distribution steady-state assessment indicators;
[0032] The scoring unit is used to score the SIP session content based on the evaluation results, and to filter SIP session content with scores lower than the preset standard score to determine the SIP session content that needs to be protected.
[0033] As one embodiment of this technical solution, the channel establishment module includes:
[0034] The backup unit is used to obtain the SIP sessions that need to be protected, determine the address information of the user-end SIP server, back up the address information, and determine the backup address information;
[0035] The acquisition unit is used to acquire the request address information in the user's request command, retrieve the corresponding terminal SIP server through the request address information, generate a terminal SIP server sequence table, and transmit the address information to the terminal SIP server in the first position of the terminal SIP server sequence table.
[0036] The transmission unit is used to transmit the backup address information sequentially to the second-order terminal SIP server when the terminal SIP server cannot provide services, and to back up the backup address information again.
[0037] The establishment unit is used to establish a channel between the user-end SIP server and the terminal SIP server for a SIP session content call that needs to be protected, until the terminal SIP server can provide services.
[0038] As one embodiment of this technical solution, the defense mechanism module includes:
[0039] The monitoring unit is used to build a defense mechanism on the channel, monitor the SIP session content that needs to be protected through the defense mechanism, and determine the monitoring results.
[0040] The status change unit is used to acquire status change information when the monitoring result indicates that a status change has occurred between the user-end SIP server and the terminal SIP server.
[0041] A judgment unit is used to determine whether the state change information has been attacked by an external server.
[0042] The defense unit is used to track the address of the external server and automatically activate the firewall when the state change information is attacked by an external server, through the defense mechanism.
[0043] The storage unit is used to record the state change information and store it in a preset state storage database when the state change information is not attacked by an external server.
[0044] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.
[0045] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0046] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0047] Figure 1 This is a flowchart of a SIP session protection method based on session copy in an embodiment of the present invention;
[0048] Figure 2 This is a flowchart of a SIP session protection method based on session copy in an embodiment of the present invention. Detailed Implementation
[0049] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0050] Example 1:
[0051] This invention provides a SIP session protection method based on session copying, comprising:
[0052] Collect user SIP sessions on the user-end SIP server, perform quality assessment on the user SIP sessions, and determine the SIP session content that needs to be protected.
[0053] Copy the SIP session content that needs to be protected, and establish a channel between the SIP servers that are communicating in the SIP session content that needs to be protected.
[0054] A defense mechanism is built on the channel, and based on the defense mechanism, the SIP session content that needs to be protected is protected.
[0055] The working principle and beneficial effects of the above technical solution are as follows:
[0056] This invention provides a SIP session protection method based on session copying, comprising: collecting user SIP sessions on a user-end SIP server; performing a quality assessment on the user SIP sessions; and determining the SIP session content that needs protection; copying the SIP session content that needs protection; and establishing a channel between the SIP servers communicating in the SIP session content that needs protection; constructing a defense mechanism on the channel; and protecting the SIP session content that needs protection based on the defense mechanism. By employing the session copy-based SIP session protection method, when a customer SIP entity cannot provide service, a backup SIP entity can replace the primary SIP entity to provide service support, thereby achieving the goal of uninterrupted SIP session service.
[0057] Example 2:
[0058] In one embodiment, the step of collecting user SIP sessions from the user-end SIP server, performing a quality assessment on the user SIP sessions, and determining the SIP session content that needs to be protected includes:
[0059] Based on the SIP session process of the user-side SIP server, obtain the session distribution characteristics;
[0060] Based on preset quality assessment indicators, the session distribution characteristics are assessed for quality, and the assessment results are determined.
[0061] The quality assessment indicators include at least flow assessment indicators, reliability assessment indicators, and distribution steady-state assessment indicators;
[0062] Based on the evaluation results, the SIP session content is scored, and SIP session content with scores lower than the preset standard score is filtered out to determine the SIP session content that needs to be protected.
[0063] The working principle and beneficial effects of the above technical solution are as follows:
[0064] This technical solution collects user SIP sessions from the user-end SIP server, performs quality assessment on the user SIP sessions, and determines the SIP session content that needs protection. This includes: obtaining session distribution characteristics based on the SIP session process of the user-end SIP server; performing quality assessment on the session distribution characteristics based on preset quality assessment indicators, and determining the assessment results; wherein the quality assessment indicators include at least traffic assessment indicators, reliability assessment indicators, and distribution steady-state assessment indicators; scoring the SIP session content based on the assessment results, and filtering out SIP session content with scores lower than a preset standard score to determine the SIP session content that needs protection. This improves session quality.
[0065] Example 3:
[0066] In one embodiment, copying the SIP session content to be protected and establishing a channel between the SIP servers communicating within the protected SIP session content includes:
[0067] Obtain the SIP sessions that need to be protected, determine the address information of the user-end SIP server, back up the address information, and determine the backup address information;
[0068] Collect the request address information in the user's request command, retrieve the corresponding terminal SIP server through the request address information, generate a terminal SIP server sequence table, and transmit the address information to the terminal SIP server in the first position of the terminal SIP server sequence table.
[0069] When the terminal SIP server is unable to provide service, the backup address information is sequentially transmitted to the second terminal SIP server, and the backup address information is backed up again.
[0070] A channel is established between the client-side SIP server and the terminal SIP server for the SIP session content that needs protection until the terminal SIP server can provide services.
[0071] The working principle and beneficial effects of the above technical solution are as follows:
[0072] This technical solution copies the SIP session content that needs protection and establishes a channel between the SIP servers involved in the SIP session communication. The process includes: acquiring the SIP session to be protected, determining the address information of the user-end SIP server, backing up the address information, and determining backup address information; collecting the request address information from the user request command, retrieving the corresponding terminal SIP server using the request address information, generating a terminal SIP server sequence table, and simultaneously transmitting the address information to the first-order terminal SIP server in the sequence table; when the terminal SIP server cannot provide service, transmitting the backup address information sequentially to the second-order terminal SIP server, and backing up the backup address information again; until the terminal SIP server can provide service, establishing a channel between the user-end SIP server and the terminal SIP server involved in the SIP session communication, thus establishing a secure and robust communication channel.
[0073] Example 4:
[0074] In one embodiment, the step of building a defense mechanism on the channel and protecting the SIP session content that needs protection based on the defense mechanism includes:
[0075] A defense mechanism is built on the channel, and the SIP session content that needs to be protected is monitored through the defense mechanism to determine the monitoring results;
[0076] When the monitoring result indicates a state change between the user-end SIP server and the terminal SIP server, obtain the state change information;
[0077] Determine whether the state change information has been attacked by an external server; wherein...
[0078] When the state change information is attacked by an external server, the defense mechanism tracks the address of the external server and automatically activates the firewall.
[0079] If the state change information is not attacked by an external server, the state change information is recorded and stored in a preset state storage database.
[0080] The working principle and beneficial effects of the above technical solution are as follows:
[0081] This technical solution constructs a defense mechanism on the channel and, based on this mechanism, protects the SIP session content that needs protection. This includes: constructing a defense mechanism on the channel; monitoring the SIP session content that needs protection through this mechanism and determining the monitoring results; when the monitoring results indicate a state change between the user-end SIP server and the terminal SIP server, acquiring the state change information; determining whether the state change information has been attacked by an external server; wherein, if the state change information has been attacked by an external server, the defense mechanism tracks the address of the external server and automatically activates a firewall; if the state change information has not been attacked by an external server, recording the state change information and storing it in a preset state storage database. This improves session security.
[0082] Example 5:
[0083] This technical solution provides a SIP session protection system based on session copy, including:
[0084] The quality assessment module is used to collect user SIP sessions on the user-end SIP server, perform quality assessment on the user SIP sessions, and determine the SIP session content that needs to be protected.
[0085] The channel establishment module is used to copy the SIP session content that needs to be protected and establish a channel between the SIP servers that are communicating in the SIP session content that needs to be protected.
[0086] The defense mechanism module is used to build a defense mechanism on the channel and, based on the defense mechanism, protect the SIP session content that needs to be protected.
[0087] The working principle and beneficial effects of the above technical solution are as follows:
[0088] This technical solution provides a SIP session protection system based on session copying, comprising: a quality assessment module, used to collect user SIP sessions on the user-end SIP server, perform quality assessment on the user SIP sessions, and determine the SIP session content that needs to be protected; a channel establishment module, used to copy the SIP session content that needs to be protected and establish a channel between the SIP servers communicating in the SIP session content that needs to be protected; and a defense mechanism module, used to build a defense mechanism on the channel and protect the SIP session content that needs to be protected based on the defense mechanism. By adopting the SIP session protection method based on session copying, when the customer SIP entity cannot provide service, the backup SIP entity can replace the primary SIP entity to provide service support, thereby achieving the goal of uninterrupted SIP session service.
[0089] Example 6:
[0090] In one embodiment, the quality assessment module includes:
[0091] The session distribution feature unit is used to obtain session distribution features based on the SIP session process of the user-end SIP server.
[0092] An evaluation unit is used to perform a quality evaluation on the session distribution characteristics based on preset quality evaluation indicators and determine the evaluation result.
[0093] The quality assessment indicators include at least flow assessment indicators, reliability assessment indicators, and distribution steady-state assessment indicators;
[0094] The scoring unit is used to score the SIP session content based on the evaluation results, and to filter SIP session content with scores lower than the preset standard score to determine the SIP session content that needs to be protected.
[0095] The working principle and beneficial effects of the above technical solution are as follows:
[0096] The quality assessment module of this technical solution includes: a session distribution feature unit, used to obtain session distribution features based on the SIP session process of the user-end SIP server; an assessment unit, used to perform quality assessment on the session distribution features based on preset quality assessment indicators and determine the assessment result; wherein, the quality assessment indicators include at least traffic assessment indicators, reliability assessment indicators, and distribution steady-state assessment indicators; and a scoring unit, used to score the SIP session content based on the assessment result, and to filter SIP session content with scores lower than a preset standard score to determine the SIP session content that needs to be protected. This improves session security.
[0097] Example 7:
[0098] In one embodiment, the channel establishment module includes:
[0099] The backup unit is used to obtain the SIP sessions that need to be protected, determine the address information of the user-end SIP server, back up the address information, and determine the backup address information;
[0100] The acquisition unit is used to acquire the request address information in the user's request command, retrieve the corresponding terminal SIP server through the request address information, generate a terminal SIP server sequence table, and transmit the address information to the terminal SIP server in the first position of the terminal SIP server sequence table.
[0101] The transmission unit is used to transmit the backup address information sequentially to the second-order terminal SIP server when the terminal SIP server cannot provide services, and to back up the backup address information again.
[0102] The establishment unit is used to establish a channel between the user-end SIP server and the terminal SIP server for a SIP session content call that needs to be protected, until the terminal SIP server can provide services.
[0103] The working principle and beneficial effects of the above technical solution are as follows:
[0104] The channel establishment module of this technical solution includes: a backup unit, used to acquire the SIP session to be protected, determine the address information of the user-end SIP server, back up the address information, and determine backup address information; a collection unit, used to collect the request address information in the user request command, retrieve the corresponding terminal SIP server through the request address information, generate a terminal SIP server sequence table, and transmit the address information to the first-order terminal SIP server in the terminal SIP server sequence table; a transmission unit, used to transmit the backup address information sequentially to the second-order terminal SIP server when the terminal SIP server cannot provide service, and back up the backup address information again; and an establishment unit, used to establish a channel between the user-end SIP server and the terminal SIP server in the SIP session content to be protected until the terminal SIP server can provide service. This establishes a secure and stable drawing channel.
[0105] Example 8:
[0106] In one embodiment, the defense mechanism module includes:
[0107] The monitoring unit is used to build a defense mechanism on the channel, monitor the SIP session content that needs to be protected through the defense mechanism, and determine the monitoring results.
[0108] The status change unit is used to acquire status change information when the monitoring result indicates that a status change has occurred between the user-end SIP server and the terminal SIP server.
[0109] A judgment unit is used to determine whether the state change information has been attacked by an external server.
[0110] The defense unit is used to track the address of the external server and automatically activate the firewall when the state change information is attacked by an external server, through the defense mechanism.
[0111] The storage unit is used to record the state change information and store it in a preset state storage database when the state change information is not attacked by an external server.
[0112] The working principle and beneficial effects of the above technical solution are as follows:
[0113] The defense mechanism module of this technical solution includes: a monitoring unit, used to build a defense mechanism on the channel, monitor the SIP session content that needs protection through the defense mechanism, and determine the monitoring results; a state change unit, used to acquire state change information when the monitoring result indicates a state change between the user-end SIP server and the terminal SIP server; a judgment unit, used to determine whether the state change information has been attacked by an external server; a defense unit, used to track the address of the external server and automatically activate the firewall when the state change information has been attacked by an external server through the defense mechanism; and a storage unit, used to record the state change information and store it in a preset state storage database when the state change information has not been attacked by an external server. This improves session security.
[0114] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A SIP session protection method based on session copy, characterized in that, include: Collect user SIP sessions on the user-end SIP server, perform quality assessment on the user SIP sessions, and determine the SIP session content that needs to be protected. Copy the SIP session content that needs to be protected, and establish a channel between the SIP servers that are communicating in the SIP session content that needs to be protected. A defense mechanism is built on the channel, and based on the defense mechanism, the SIP session content that needs to be protected is protected; The step of constructing a defense mechanism on the channel and protecting the SIP session content that needs protection based on the defense mechanism includes: A defense mechanism is built on the channel, and the SIP session content that needs to be protected is monitored through the defense mechanism to determine the monitoring results; When the monitoring result indicates a state change between the user-end SIP server and the terminal SIP server, obtain the state change information; Determine whether the state change information has been attacked by an external server; wherein... When the state change information is attacked by an external server, the defense mechanism tracks the address of the external server and automatically activates the firewall. If the state change information is not attacked by an external server, the state change information is recorded and stored in a preset state storage database.
2. The SIP session protection method based on session copy as described in claim 1, characterized in that, The process involves collecting user SIP sessions from the user-end SIP server, performing a quality assessment on the user SIP sessions, and determining the SIP session content that needs to be protected, including: Based on the SIP session process of the user-side SIP server, obtain the session distribution characteristics; Based on preset quality assessment indicators, the session distribution characteristics are assessed for quality, and the assessment results are determined. The quality assessment indicators include at least flow assessment indicators, reliability assessment indicators, and distribution steady-state assessment indicators; Based on the evaluation results, the SIP session content is scored, and SIP session content with scores lower than the preset standard score is filtered out to determine the SIP session content that needs to be protected.
3. The SIP session protection method based on session copy as described in claim 1, characterized in that, The step of copying the SIP session content that needs to be protected and establishing a channel between the SIP servers communicating within the SIP session content that needs to be protected includes: Obtain the SIP sessions that need to be protected, determine the address information of the user-end SIP server, back up the address information, and determine the backup address information; Collect the request address information in the user's request command, retrieve the corresponding terminal SIP server through the request address information, generate a terminal SIP server sequence table, and transmit the address information to the terminal SIP server in the first position of the terminal SIP server sequence table. When the terminal SIP server is unable to provide service, the backup address information is sequentially transmitted to the second terminal SIP server, and the backup address information is backed up again. A channel is established between the client-side SIP server and the terminal SIP server for the SIP session content that needs protection until the terminal SIP server can provide services.
4. A SIP session protection system based on session copy, characterized in that, include: The quality assessment module is used to collect user SIP sessions on the user-end SIP server, perform quality assessment on the user SIP sessions, and determine the SIP session content that needs to be protected. The channel establishment module is used to copy the SIP session content that needs to be protected and establish a channel between the SIP servers that are communicating in the SIP session content that needs to be protected. The defense mechanism module is used to build a defense mechanism on the channel and, based on the defense mechanism, protect the SIP session content that needs to be protected. The defense mechanism module includes: The monitoring unit is used to build a defense mechanism on the channel, monitor the SIP session content that needs to be protected through the defense mechanism, and determine the monitoring results. The status change unit is used to acquire status change information when the monitoring result indicates that a status change has occurred between the user-end SIP server and the terminal SIP server. A judgment unit is used to determine whether the state change information has been attacked by an external server. The defense unit is used to track the address of the external server and automatically activate the firewall when the state change information is attacked by an external server, through the defense mechanism. The storage unit is used to record the state change information and store it in a preset state storage database when the state change information is not attacked by an external server.
5. A SIP session protection system based on session copy as described in claim 4, characterized in that, The quality assessment module includes: The session distribution feature unit is used to obtain session distribution features based on the SIP session process of the user-end SIP server. An evaluation unit is used to perform a quality evaluation on the session distribution characteristics based on preset quality evaluation indicators and determine the evaluation result. The quality assessment indicators include at least flow assessment indicators, reliability assessment indicators, and distribution steady-state assessment indicators; The scoring unit is used to score the SIP session content based on the evaluation results, and to filter SIP session content with scores lower than the preset standard score to determine the SIP session content that needs to be protected.
6. A SIP session protection system based on session copy as described in claim 4, characterized in that, The channel establishment module includes: The backup unit is used to obtain the SIP sessions that need to be protected, determine the address information of the user-end SIP server, back up the address information, and determine the backup address information; The acquisition unit is used to acquire the request address information in the user's request command, retrieve the corresponding terminal SIP server through the request address information, generate a terminal SIP server sequence table, and transmit the address information to the terminal SIP server in the first position of the terminal SIP server sequence table. The transmission unit is used to transmit the backup address information sequentially to the second-order terminal SIP server when the terminal SIP server cannot provide services, and to back up the backup address information again. The establishment unit is used to establish a channel between the user-end SIP server and the terminal SIP server for a SIP session content call that needs to be protected, until the terminal SIP server can provide services.
Citation Information
Patent Citations
SIP (Session Initiation Protocol) session protection method and SIP session protection system
CN102647397A
Deploying session initiation protocol application network security
US20200106809A1