IMS Security Scrubbing via Independent Network Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The IP Multimedia Core Network Subsystem (IMS) lacks effective security measures to prevent malicious attacks and ensure accurate billing, as it does not address security concerns in modern IP networks, leading to potential malicious calls being reflected in customer bills.
Innovation Solution
Implementing an independent security network with a session-border controller (SBC) that receives outbound calls, forwards them to security servers for verification, and generates billing data, ensuring only legitimate calls are routed back to the IMS network for billing, thereby enhancing security and accuracy of billing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IMS network implements comprehensive security checks for all calls, then call security and billing accuracy improve, but network complexity and processing time increase
Solution Approach 1:
The patent segments the security verification function from the core IMS network by introducing an independent security network. The SBC divides call processing into two paths: legitimate calls go through security verification while malicious calls are blocked. This segmentation allows comprehensive security checks without complicating the core IMS network architecture.
Solution Approach 2:
The patent introduces an intermediary security network with SBC and security servers that mediates between the IMS network and external networks. This intermediary performs all security verification and filtering functions, protecting the core IMS network from direct exposure to security threats while maintaining billing accuracy.
2Measurement precision
If IMS network performs security verification for all calls, then billing accuracy improves, but network processing time and resource consumption increase
Solution Approach 1:
The patent performs security verification in advance before calls are routed through the IMS network. The SBC and security servers verify call legitimacy beforehand, so that only verified calls incur billing charges. This preliminary action ensures billing accuracy without adding processing time to legitimate calls.
Solution Approach 2:
The patent extracts the security verification function from the core IMS network and places it in an independent security network. This extraction allows security checks to be performed separately, improving billing accuracy by filtering malicious calls before they reach the billing system, while minimizing impact on IMS network processing time.
3Productivity
If IMS network processes all calls including malicious calls, then network throughput is maintained, but billing accuracy deteriorates due to malicious calls being billed
Solution Approach 1:
The patent converts potentially harmful malicious calls into beneficial security verification opportunities. By analyzing malicious call patterns in the security network, the system learns to identify and block similar attacks while allowing legitimate calls to pass through unaffected. This approach maintains network throughput for legitimate traffic while improving billing accuracy by filtering malicious calls before billing.
4Device complexity
If IMS network maintains simple architecture without external security network, then device complexity is reduced, but security capability and billing accuracy worsen
Solution Approach 1:
The patent introduces an intermediary security network that connects to the IMS network without requiring complex integration. The SBC provides a simple interface point where security verification occurs externally, maintaining the simplicity of the core IMS network architecture while significantly enhancing security capability and billing accuracy through the independent security verification function.
Data Source
AI summary
Methods and systems for independent security scrubbing and billing of calls through an IP Multimedia Core Network Subsystem (IMS) are provided. The system includes a core IMS network and a security network cloud securely connected via session border controllers. The IMS network is configured to route calls to the security network cloud. The security network includes call-processing and billing servers that implement security checks on calls from OSI model layer three to seven and analyze the call to collect and generate billing data. After successful security and billing operations, the call is routed back to the IMS network for handling according to conventional workflows. Accordingly, the disclosed invention serves to enhance security for IMS traffic, improve the accuracy of customer billing and conserves IMS network resources which would otherwise be consumed by malicious attacks and billing responsibilities.

