IMS Media Protection Endpoint for Access Edge Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current media protection solutions in IMS systems face challenges such as interference with end-to-end solutions, security policy issues during roaming, and complexities in key management and authentication, particularly when using protocols like SRTP and MIKEY for terminal-to-access-edge media protection.

Innovation Solution

The system modifies SIP INVITE messages to offer and manage media protection by inserting or removing protection offers based on network policies and user entity capabilities, directing media traffic through a selected media protection endpoint and establishing corresponding security associations, allowing for end-to-access-edge security without interfering with end-to-end solutions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec tunnel is used for terminal to access edge media protection, then security is improved, but message expansion and traffic policing difficulty increase

Engineering Contradiction:
Improvemedia protection securityVSAvoidmessage expansion and traffic policing
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the media protection function from the signaling path by establishing security associations between the terminal and the media protection endpoint, allowing media traffic to be protected without requiring the entire SIP signaling to traverse secure tunnels. This separates the security establishment phase from the media transmission phase, reducing signaling overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a media protection endpoint as an intermediary component that acts as a key management server and security anchor. This intermediary handles key distribution and security association management between terminals and the access edge, reducing the complexity of direct end-to-end security management while maintaining protection efficacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If end-to-end media protection is implemented, then security is improved, but network support for transcoding becomes impossible

Engineering Contradiction:
Improveend-to-end media protectionVSAvoidnetwork support for transcoding
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the media protection scope into terminal-to-access-edge protection rather than true end-to-end protection. This allows the media path to be divided into protected segments (terminal to media protection endpoint) and unprotected segments (through the core network where transcoding can occur), enabling both security and network functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies media protection selectively at the access edge where it is most needed, rather than uniformly across the entire end-to-end path. The media protection endpoint provides local security termination, allowing different parts of the media path to have different security characteristics - protected at the access edge, and accessible for network functions in the core.

Inventive Principle:
Principle #3Local quality

3Reliability

If SRTP and MIKEY are used for media protection, then media security is achieved, but key management and authentication complexities increase

Engineering Contradiction:
Improvemedia securityVSAvoidkey management and authentication
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary key management and authentication through the media protection endpoint before actual media transmission begins. Security associations are established in advance during session setup, and keys are pre-distributed through the key management server, simplifying the runtime key management burden during media playback.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal autonomously performs local key derivation and security association establishment with the media protection endpoint using standardized protocols like SRTP and MIKEY. This self-service capability reduces the burden on network infrastructure while maintaining secure key management, as each terminal independently manages its own security context.

Inventive Principle:
Principle #25Self-service

4Reliability

If media protection is enforced in roaming situations, then security policy compliance is improved, but interoperability between home and visited networks becomes problematic

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidroaming interoperability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal media protection interface at the access edge that can be consistently implemented across different networks and operators. The media protection endpoint serves multiple functions - acting as a security anchor for home networks, a trusted intermediary for visited networks, and a standardized interface for terminals regardless of their home network. This multi-functional design enables seamless roaming while maintaining security policy compliance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2229760B1Method and apparatuses for end-to-edge media protection in an IMS system
Publication Date: 2015.11.25 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2229760B1 patent drawingFigure 1
  • EP2229760B1 patent drawingFigure 2
  • EP2229760B1 patent drawingFigure 3~5

AI summary

An IMS system includes an IMS initiator user entity. The system includes an IMS responder user entity that is called by the initiator user entity. The system includes a calling side S-CSCF in communication with the caller entity which receives an INVITE having a first protection offer and parameters for key establishment from the caller entity, removes the first protection offer from the INVITE and forwards the INVITE without the first protection offer. The system includes a receiving end S-CSCF in communication with the responder user entity and the calling side S-CSCF which receives the INVITE without the first protection offer and checks that the responder user entity supports the protection, inserts a second protection offer into the INVITE and forwards the INVITE to the responder user entity, wherein the responder user entity accepts the INVITE including the second protection offer and answers with an acknowledgment having a first protection accept. A method for supporting a call by a telecommunications node.