IMS Media Protection Endpoint for Access Edge Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current media protection solutions in IMS systems face challenges such as interference with end-to-end solutions, security policy issues during roaming, and complexities in key management and authentication, particularly when using protocols like SRTP and MIKEY for terminal-to-access-edge media protection.
Innovation Solution
The system modifies SIP INVITE messages to offer and manage media protection by inserting or removing protection offers based on network policies and user entity capabilities, directing media traffic through a selected media protection endpoint and establishing corresponding security associations, allowing for end-to-access-edge security without interfering with end-to-end solutions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IPSec tunnel is used for terminal to access edge media protection, then security is improved, but message expansion and traffic policing difficulty increase
Solution Approach 1:
The patent extracts the media protection function from the signaling path by establishing security associations between the terminal and the media protection endpoint, allowing media traffic to be protected without requiring the entire SIP signaling to traverse secure tunnels. This separates the security establishment phase from the media transmission phase, reducing signaling overhead.
Solution Approach 2:
The patent introduces a media protection endpoint as an intermediary component that acts as a key management server and security anchor. This intermediary handles key distribution and security association management between terminals and the access edge, reducing the complexity of direct end-to-end security management while maintaining protection efficacy.
2Reliability
If end-to-end media protection is implemented, then security is improved, but network support for transcoding becomes impossible
Solution Approach 1:
The patent segments the media protection scope into terminal-to-access-edge protection rather than true end-to-end protection. This allows the media path to be divided into protected segments (terminal to media protection endpoint) and unprotected segments (through the core network where transcoding can occur), enabling both security and network functionality.
Solution Approach 2:
The patent applies media protection selectively at the access edge where it is most needed, rather than uniformly across the entire end-to-end path. The media protection endpoint provides local security termination, allowing different parts of the media path to have different security characteristics - protected at the access edge, and accessible for network functions in the core.
3Reliability
If SRTP and MIKEY are used for media protection, then media security is achieved, but key management and authentication complexities increase
Solution Approach 1:
The patent performs preliminary key management and authentication through the media protection endpoint before actual media transmission begins. Security associations are established in advance during session setup, and keys are pre-distributed through the key management server, simplifying the runtime key management burden during media playback.
Solution Approach 2:
The terminal autonomously performs local key derivation and security association establishment with the media protection endpoint using standardized protocols like SRTP and MIKEY. This self-service capability reduces the burden on network infrastructure while maintaining secure key management, as each terminal independently manages its own security context.
4Reliability
If media protection is enforced in roaming situations, then security policy compliance is improved, but interoperability between home and visited networks becomes problematic
Solution Approach 1:
The patent creates a universal media protection interface at the access edge that can be consistently implemented across different networks and operators. The media protection endpoint serves multiple functions - acting as a security anchor for home networks, a trusted intermediary for visited networks, and a standardized interface for terminals regardless of their home network. This multi-functional design enables seamless roaming while maintaining security policy compliance.
Data Source
Figure 1
Figure 2
Figure 3~5
AI summary
An IMS system includes an IMS initiator user entity. The system includes an IMS responder user entity that is called by the initiator user entity. The system includes a calling side S-CSCF in communication with the caller entity which receives an INVITE having a first protection offer and parameters for key establishment from the caller entity, removes the first protection offer from the INVITE and forwards the INVITE without the first protection offer. The system includes a receiving end S-CSCF in communication with the responder user entity and the calling side S-CSCF which receives the INVITE without the first protection offer and checks that the responder user entity supports the protection, inserts a second protection offer into the INVITE and forwards the INVITE to the responder user entity, wherein the responder user entity accepts the INVITE including the second protection offer and answers with an acknowledgment having a first protection accept. A method for supporting a call by a telecommunications node.