IMS P-CSCF Source Address Comparison for Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IP multimedia subsystem (IMS) network faces challenges in providing secure access due to the hop-by-hop security model, which allows fraudulent users to send messages appearing to come from a different subscriber, as the Proxy-CSCF (P-CSCF) lacks complete information on allowed messages and the Serving-CSCF (S-CSCF) is unaware of the message's actual origin, especially with implicitly registered public identities.

Innovation Solution

A method and network element that derive and compare source information from message headers and security associations to initiate protection processing, without requiring knowledge of private identities or additional message fields, ensuring that only authorized identities are used for message forwarding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hop-by-hop security model is used in IMS network, then message transmission efficiency is improved, but security against fraudulent user attacks deteriorates

Engineering Contradiction:
Improvemessage transmission efficiencyVSAvoidsecurity against fraudulent attacks
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The P-CSCF acts as an intermediary between the UE and S-CSCF, performing source address comparison to prevent fraudulent messages before forwarding them to the S-CSCF. This mediator function maintains hop-by-hop security efficiency while adding a security check layer that prevents identity spoofing attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The source address comparison is performed in advance by the P-CSCF before messages are forwarded to the S-CSCF. By preliminarily filtering out fraudulent messages with mismatched source addresses, the system prevents security issues before they reach the core network elements, maintaining both efficiency and security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If P-CSCF performs source address comparison, then security against fraudulent attacks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against fraudulent attacksVSAvoidP-CSCF processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The P-CSCF uses its own received message data (source address from IP header and source information from message header) to perform the comparison itself, without requiring additional external verification systems. This self-service approach enhances security while minimizing additional complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The P-CSCF performs multiple functions including proxy operations, security association maintenance, and source address comparison. By integrating the security check function into the existing P-CSCF multi-functional architecture, the system avoids adding separate dedicated security devices, thus limiting complexity increase.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Loss of information

If additional fields are added to message formats for security verification, then security information completeness is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity information completenessVSAvoidmessage format compatibility
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The invention extracts source address information from existing message headers (such as P-Asserted-Identity or From headers) and IP packet headers, rather than adding new fields. This extraction approach provides complete security verification information while maintaining compatibility with existing message formats and operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7574735B2Method and network element for providing secure access to a packet data network
Publication Date: 2009.08.11 NOKIA TECHNOLOGIES OY
  • US7574735B2 patent drawing
  • US7574735B2 patent drawing
  • US7574735B2 patent drawing

AI summary

The present invention relates to a method and network element for providing secure access to a packet data network, wherein a first source information is derived from a message received from a terminal device (40, 60), and is compared with a second source information derived from a packet data unit used for conveying said message, or derived from a security association set up between the terminal device and the data network. A protection processing for protecting the packet data network from a fraudulent user attack is then initiated based on the comparing result. Thereby, a simple and efficient protection mechanism can be provided without sending any additional information or providing any additional fields in the message.