IMS Server Access Network Security Tunnel Recommendation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The establishment and maintenance of secure tunnels in VoIP networks based on IMS architecture are resource-intensive for both terminals and servers, leading to battery life issues in mobile devices and increased server dimensioning, due to double encryption processes.

Innovation Solution

A method where a server in a multimedia IP core network identifies the access network used by a terminal and recommends whether to establish a secure tunnel based on the access network's security level, allowing the terminal to decide or not to establish the tunnel, thereby conserving resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure tunnel is established between the terminal and the P-CSCF server, then data security is improved, but resource consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The invention changes the parameter of secure tunnel establishment from a fixed requirement to a conditional recommendation based on access network security level. The server evaluates the security characteristics of the access network and dynamically adjusts the secure tunnel establishment recommendation accordingly, allowing terminals to conserve resources when the access network already provides sufficient security.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If double encryption is implemented, then data protection is improved, but terminal battery life deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidbattery life
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The invention extracts the secure tunnel establishment step from the mandatory registration process and makes it conditional. By evaluating whether the access network already provides adequate security, the system can omit the second encryption layer when unnecessary, thereby eliminating redundant computational operations that would drain terminal battery resources.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If secure tunnel establishment is mandatory, then security is improved, but server dimensioning requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidserver dimensioning
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention introduces dynamic behavior to the secure tunnel establishment process. Instead of a static mandatory requirement, the system dynamically evaluates access network security levels and adjusts the secure tunnel establishment recommendation in real-time. This dynamic approach allows servers to handle varying security requirements without over-provisioning resources for worst-case scenarios.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10182037B2Method for the transmission of a message by a server of an IMS multimedia IP core network, and server
Publication Date: 2019.01.15 ORANGE SA
  • US10182037B2 patent drawing
  • US10182037B2 patent drawing
  • US10182037B2 patent drawing

AI summary

A method for the transmission of a message by a server of a multimedia IP core network is disclosed. In one aspect, following the reception, by the server, of a request from a terminal to register with the core network, the registration request proposing an authentication method for the establishment of a secure tunnel between the terminal and an entity for the connection of the terminal to the core network. The transmission method may comprise identifying an access network used by the terminal for registering with the multimedia IP core network, drawing-up, according to the identified access network, a recommendation concerning the establishment or otherwise of the secure tunnel between the terminal and the connection entity for the authentication method, and inserting said recommendation into the message transmitted by the server.