Diameter Agent Topology Hiding via Signaling Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Diameter networks, providing node identification and location information poses a security risk and may reveal sensitive network topology, making it desirable to encrypt this information to protect against attacks and maintain confidentiality.
Innovation Solution
A Diameter agent equipped with an encryption-based topology hiding module (ETHM) encrypts Diameter identification information within signaling messages, replacing the original information to ensure secure communication and hide network elements' identities, using encryption keys and decryption keys to route messages securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If Diameter node identification information is included in signaling messages, then routing and communication between nodes can be established, but security risks increase and network topology becomes exposed
Solution Approach 1:
The patent introduces an intermediary encryption mechanism that processes Diameter node identification information before it is included in signaling messages. The encryption module acts as a mediator between the routing function and security requirements, transforming identifiable information into encrypted form while preserving routing capability through encrypted indicators.
Solution Approach 2:
The patent changes the state of identification information from plaintext to encrypted form. By applying encryption algorithms to the identification parameters, the system transforms them into a secure state that maintains functional utility for routing while eliminating security vulnerabilities associated with exposed identification data.
2Ease of operation
If Diameter node identification information is provided to requesting nodes, then communication functionality is enabled, but network topology confidentiality is compromised
Solution Approach 1:
The encryption module serves as an intermediary that preserves communication functionality while protecting topology information. It allows nodes to communicate using encrypted identifiers without revealing the underlying network structure, maintaining operational ease while preventing topology disclosure.
Solution Approach 2:
The system creates encrypted copies of the identification information that functionally replace the original plaintext identifiers. These encrypted copies enable communication operations while containing no exploitable information about the actual network topology, effectively copying the functional need without copying the sensitive data.
3Device complexity
If plaintext identification information is used in Diameter messages, then message routing is simplified, but susceptibility to attacks increases
Solution Approach 1:
The patent changes the parameter state of identification information from unencrypted to encrypted form. This transformation maintains routing functionality while fundamentally altering the security profile of the data, reducing attack susceptibility without significantly increasing routing complexity due to the transparent nature of the encryption module.
Data Source
AI summary
The subject matter described herein includes systems, methods, and computer readable media for encrypting Diameter identification information contained in Diameter signaling messages. The system includes a Diameter agent that comprises a network interface configured to receive, from a first Diameter node, a Diameter signaling message that includes Diameter identification information associated with the first Diameter node and a Diameter encryption topology hiding module (ETHM) configured to encrypt the Diameter identification information to generate encrypted Diameter identification information and to replace the Diameter identification information in the Diameter signaling message with the encrypted Diameter identification information. The Diameter agent further includes a routing module configured to route the Diameter signaling message with the encrypted Diameter identification information to a second Diameter node.


