IMS Trust Level Indicator for Interoperability Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IP Multimedia Subsystem (IMS) networks face challenges in handling trust levels across different access technologies and networks, leading to reduced security and increased risk of unsolicited communications, particularly when interoperating with non-3GPP networks like TISPAN and PacketCable, which have lower security mechanisms.
Innovation Solution
The introduction of a trust level indicator in SIP messages allows nodes in the IMS network to apply flexible security policies based on the trust level of the communication, enabling differentiated handling of signalling messages from various sources, including numerical or descriptive indicators that consider factors like user terminal type, encryption, and network security mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IMS networks interoperate with non-3GPP networks (TISPAN, PacketCable) using their security mechanisms (HTTP Digest, TLS, NASS-IMS), then network interoperability and access options are improved, but security level deteriorates because these mechanisms offer lower security than IMS AKA
Solution Approach 1:
The patent applies different security policies to different network sources by introducing trust level indicators. Each network (3GPP IMS, TISPAN, PacketCable) is assigned a specific trust level based on its security mechanism capabilities. This allows the system to maintain high security for 3GPP IMS AKA traffic while still accepting interoperability traffic from non-3GPP networks with their lower-security mechanisms, thus resolving the contradiction between interoperability and security level.
Solution Approach 2:
The patent introduces dynamic security policy selection based on trust level indicators in SIP messages. Instead of applying a static security policy to all traffic, the system dynamically adjusts security handling according to the trust level of each message source. This enables the network to adapt security measures to the specific interoperability scenario, maintaining high security where possible while enabling interoperability where required.
2Device complexity
If a single trust domain is applied to all signalling in current IMS networks, then implementation simplicity is maintained, but the ability to handle differentiated trust levels from different networks deteriorates, leading to reduced security when interconnecting with non-IMS networks
Solution Approach 1:
The patent segments the single trust domain into multiple trust levels (e.g., high trust for 3GPP IMS AKA, medium trust for TISPAN NASS-IMS, low trust for HTTP Digest/TLS). This segmentation allows the system to differentiate between various network sources and apply appropriate security policies to each, resolving the contradiction between implementation simplicity and security handling capability.
Solution Approach 2:
The patent changes the trust domain parameter from a single uniform trust level to a multi-level trust indicator system. Trust level indicators are embedded in SIP messages to convey the security capability of the message source. This parameter change enables the system to handle differentiated trust levels from different networks while maintaining a relatively simple implementation through standardized indicator handling.
Data Source
AI summary
A method and apparatus for handling trust in an IP Multimedia Subsystem network. A node in the IP Multimedia Subsystem network receives a Session Initiation Protocol message from a remote node. The message includes an indicator indicating the level of trust of a communication sent from the remote node to the IP Multimedia Subsystem node. The node can then apply a security policy to the message, the security policy being determined by the indicator.


