IMS VoIP Network Security via Multi-VPN Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

VoIP networks face security vulnerabilities such as DDoS attacks and eavesdropping due to lack of effective security measures, compromising corporate data and intellectual property.

Innovation Solution

Implementing a secure IP multimedia subsystem (IMS)-based VoIP network using multiple virtual private networks (VPNs) with separate IP routing and forwarding domains, where messages and media flows are encrypted and routed through a session border controller (SBC) to provide end-to-end security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple VPNs with separate IP routing and forwarding domains are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is divided into multiple separate VPNs (first VPN for IMS core servers, second VPN for IP phones, third VPN for non-IP-phone devices) with distinct IP routing and forwarding domains. This segmentation isolates different network functions and device types into secure, isolated environments, preventing lateral movement of attacks while maintaining individual security policies for each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A Session Border Controller (SBC) is introduced as an intermediary device that controls and manages traffic between the multiple VPNs. The SBC acts as a security gateway that enforces policy, performs authentication, and regulates communication between isolated network segments, reducing the complexity of direct peer-to-peer security configurations between multiple VPNs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If messages and media flows are encrypted and routed through SBC, then security is improved, but loss of time increases

Engineering Contradiction:
ImprovesecurityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security policies, encryption keys, and routing rules are pre-configured in the SBC and network devices before operation. The SBC maintains pre-established security associations and encryption contexts for different VPNs, allowing encrypted communication to be initiated without real-time key exchange or policy negotiation, thereby reducing latency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption and decryption operations are performed automatically by the SBC and endpoint devices using pre-shared keys and standardized protocols. The system self-manages security associations and encrypted traffic flow without requiring manual intervention or complex real-time authentication handshakes, minimizing processing delays.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10951663B2Securing an IMS-based VoIP network with multiple VPNs
Publication Date: 2021.03.16 SAUDI ARABIAN OIL CO
  • US10951663B2 patent drawing
  • US10951663B2 patent drawing
  • US10951663B2 patent drawing

AI summary

Systems and methods include a method for securing an Internet protocol (IP) Multimedia Subsystem (IMS)-based voice over IP (VoIP) network with multiple virtual private networks (VPNs). A call sent by a first user endpoint (UE) to a second UE is received by a SBC. The SBC provides security for an IMS-based VoIP network and controls traffic between a first VPN connecting IMS core servers, a second VPN connecting IP phones, and a third VPN connecting non-IP-phone devices. The call originates from either of the second VPN connecting the IP phones or from the third VPN connecting the non-IP-phone devices. A signaling for the call is encrypted and routed by the SBC to the second UE. A media flow for the call is encrypted and routed by the SBC through the third VPN before routing the call to the second UE.