IMS P-CSCF Source Address Comparison for Fraud Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing IP multimedia subsystem (IMS) network faces challenges in providing secure access due to the hop-by-hop security model, which allows fraudulent users to send messages appearing to come from a different subscriber, as the Proxy-CSCF (P-CSCF) lacks complete information on allowed messages and the Serving-CSCF (S-CSCF) is unaware of the message's actual origin, especially with implicitly registered public identities.
Innovation Solution
A method and network element that derive and compare source information from message headers and security associations to initiate protection processing, without requiring knowledge of private identities or additional message fields, ensuring that only authorized identities are used for message forwarding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If hop-by-hop security model is used in IMS network, then message transmission efficiency is improved, but security against fraudulent user attacks deteriorates
Solution Approach 1:
The P-CSCF acts as an intermediary between the UE and S-CSCF, performing source address comparison to prevent fraudulent messages before forwarding them to the S-CSCF. This mediator function maintains hop-by-hop security efficiency while adding a security check layer that prevents identity spoofing attacks.
Solution Approach 2:
The source address comparison is performed in advance by the P-CSCF before messages are forwarded to the S-CSCF. By preliminarily filtering out fraudulent messages with mismatched source addresses, the system prevents security issues before they reach the core network elements, maintaining both efficiency and security.
2Reliability
If P-CSCF performs source address comparison, then security against fraudulent attacks is improved, but device complexity increases
Solution Approach 1:
The P-CSCF uses its own received message data (source address from IP header and source information from message header) to perform the comparison itself, without requiring additional external verification systems. This self-service approach enhances security while minimizing additional complexity.
Solution Approach 2:
The P-CSCF performs multiple functions including proxy operations, security association maintenance, and source address comparison. By integrating the security check function into the existing P-CSCF multi-functional architecture, the system avoids adding separate dedicated security devices, thus limiting complexity increase.
3Loss of information
If additional fields are added to message formats for security verification, then security information completeness is improved, but ease of operation deteriorates
Solution Approach 1:
The invention extracts source address information from existing message headers (such as P-Asserted-Identity or From headers) and IP packet headers, rather than adding new fields. This extraction approach provides complete security verification information while maintaining compatibility with existing message formats and operations.
Data Source
AI summary
The present invention relates to a method and network element for providing secure access to a packet data network, wherein a first source information is derived from a message received from a terminal device (40, 60), and is compared with a second source information derived from a packet data unit used for conveying said message, or derived from a security association set up between the terminal device and the data network. A protection processing for protecting the packet data network from a fraudulent user attack is then initiated based on the comparing result. Thereby, a simple and efficient protection mechanism can be provided without sending any additional information or providing any additional fields in the message.


