IMS Security Scrubbing via Independent Network Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The IP Multimedia Core Network Subsystem (IMS) lacks effective security measures to prevent malicious attacks and ensure accurate billing, as it does not address security concerns in modern IP networks, leading to potential malicious calls being reflected in customer bills.

Innovation Solution

Implementing an independent security network with a session-border controller (SBC) that receives outbound calls, forwards them to security servers for verification, and generates billing data, ensuring only legitimate calls are routed back to the IMS network for billing, thereby enhancing security and accuracy of billing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IMS network implements comprehensive security checks for all calls, then call security and billing accuracy improve, but network complexity and processing time increase

Engineering Contradiction:
Improvecall securityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security verification function from the core IMS network by introducing an independent security network. The SBC divides call processing into two paths: legitimate calls go through security verification while malicious calls are blocked. This segmentation allows comprehensive security checks without complicating the core IMS network architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security network with SBC and security servers that mediates between the IMS network and external networks. This intermediary performs all security verification and filtering functions, protecting the core IMS network from direct exposure to security threats while maintaining billing accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If IMS network performs security verification for all calls, then billing accuracy improves, but network processing time and resource consumption increase

Engineering Contradiction:
Improvebilling accuracyVSAvoidcall processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs security verification in advance before calls are routed through the IMS network. The SBC and security servers verify call legitimacy beforehand, so that only verified calls incur billing charges. This preliminary action ensures billing accuracy without adding processing time to legitimate calls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the security verification function from the core IMS network and places it in an independent security network. This extraction allows security checks to be performed separately, improving billing accuracy by filtering malicious calls before they reach the billing system, while minimizing impact on IMS network processing time.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If IMS network processes all calls including malicious calls, then network throughput is maintained, but billing accuracy deteriorates due to malicious calls being billed

Engineering Contradiction:
Improvenetwork throughputVSAvoidbilling accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent converts potentially harmful malicious calls into beneficial security verification opportunities. By analyzing malicious call patterns in the security network, the system learns to identify and block similar attacks while allowing legitimate calls to pass through unaffected. This approach maintains network throughput for legitimate traffic while improving billing accuracy by filtering malicious calls before billing.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

4Device complexity

If IMS network maintains simple architecture without external security network, then device complexity is reduced, but security capability and billing accuracy worsen

Engineering Contradiction:
Improvenetwork architecture simplicityVSAvoidsecurity capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces an intermediary security network that connects to the IMS network without requiring complex integration. The SBC provides a simple interface point where security verification occurs externally, maintaining the simplicity of the core IMS network architecture while significantly enhancing security capability and billing accuracy through the independent security verification function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10917442B2System and method for secure billing for IMS-based VoIP networks
Publication Date: 2021.02.09 SAUDI ARABIAN OIL CO
  • US10917442B2 patent drawing
  • US10917442B2 patent drawing

AI summary

Methods and systems for independent security scrubbing and billing of calls through an IP Multimedia Core Network Subsystem (IMS) are provided. The system includes a core IMS network and a security network cloud securely connected via session border controllers. The IMS network is configured to route calls to the security network cloud. The security network includes call-processing and billing servers that implement security checks on calls from OSI model layer three to seven and analyze the call to collect and generate billing data. After successful security and billing operations, the call is routed back to the IMS network for handling according to conventional workflows. Accordingly, the disclosed invention serves to enhance security for IMS traffic, improve the accuracy of customer billing and conserves IMS network resources which would otherwise be consumed by malicious attacks and billing responsibilities.