IMS Terminal Traversing Private Network via Virtual IP Tunnel

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for a terminal to access an Internet Protocol multimedia subsystem (IMS) core network require modifying the enterprise network and deploying IPSec VPN gateways, which is cumbersome and invasive.

Innovation Solution

A method where a terminal sets a virtual IP address allocated by the IMS core network, encapsulates service data into tunnel packets, and transmits them over a UDP or SSL VPN tunnel to a security tunnel gateway at the IMS core network edge, allowing communication without modifying the enterprise network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IPSec VPN gateway is deployed in enterprise network and data route is modified, then terminal can access IMS core network, but enterprise network requires great modification

Engineering Contradiction:
Improveaccess capability to IMS core networkVSAvoidenterprise network modification
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a VPN gateway deployed in the IMS core network as an intermediary device. This gateway receives tunnel packets from terminals, extracts service data, and forwards it to the IMS core network server, eliminating the need to modify the enterprise network while maintaining reliable access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of deploying the VPN gateway in the enterprise network and modifying routing tables there, the patent inverts the approach by placing the VPN gateway in the IMS core network. The terminal simply needs to establish a VPN tunnel to the gateway, and all routing modifications are performed on the gateway side rather than the terminal side.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If IPSec VPN gateway is deployed to enable terminal access, then communication with IMS core network is achieved, but deployment complexity increases

Engineering Contradiction:
Improvecommunication capabilityVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The VPN gateway acts as a mediator that simplifies terminal deployment. Terminals only need to configure a VPN tunnel parameter set pointing to the gateway's address, without requiring complex routing configurations or gateway deployments within the enterprise network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The VPN gateway in the IMS core network serves multiple functions: it acts as a VPN gateway for terminals, a NAT gateway for address translation, and a data forwarding gateway for routing service data to the IMS core network server, reducing the need for multiple separate devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2590368B1Method, equipment and network system for terminal communicating with IP multimedia subsystem(IMS) core network server by traversing private network
Publication Date: 2016.07.20 HUAWEI TECH CO LTD
  • EP2590368B1 patent drawingFigure 1A~1B
  • EP2590368B1 patent drawingFigure 2A~2B
  • EP2590368B1 patent drawingFigure 3~4

AI summary

Embodiments of the present invention provide a method, an apparatus, and a network system for a terminal to traverse a private network to communicate with a server in an IMS core network. The method for a terminal to traverse a private network to communicate with a server in an IMS core network includes: setting, by the terminal, a source address of service data to be sent as a virtual IP address, setting a destination address of the service data to be sent as an address of an internal network server, and obtaining a first service packet, where the virtual IP address is an address allocated by the multimedia subsystem IMS core network to the terminal; and encapsulating, by the terminal, the first service packet into a first tunnel packet, and send the first tunnel packet to the security tunnel gateway over a virtual private network tunnel (VPN) between the terminal and a security tunnel gateway, so that the security tunnel gateway sends the first service packet in the first tunnel packet to the internal network server. By using the technical solution provided in the embodiments of the present invention, the terminal is capable of traversing the private network to communicate with the server in the IMS core network without modifying an enterprise network.