Lawful Intercept KMS Identification in IMS Core Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network communication security solutions for IP multimedia subsystems (IMS) rely on the security of the signaling plane, which is compromised when multiple Key Management Servers (KMSs) are deployed, making lawful intercepting insecure.
Innovation Solution
Storing KMS information in the IMS core network network elements during user registration and intercepting session request signaling to obtain identification information, allowing lawful intercepting devices to find and retrieve key material from the corresponding KMS, independent of the signaling plane security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the KMS ID is transmitted in plaintext in signaling, then the lawful intercepting device can easily obtain the KMS information, but the security of the system is compromised
Solution Approach 1:
The patent extracts the KMS information transmission from the plaintext signaling domain and relocates it to the encrypted domain. The KMS ID is encrypted using the first encryption algorithm along with other signaling parameters, separating secure key management information from the unprotected signaling plane. This allows lawful intercepting devices to access encrypted traffic and extract KMS information without relying on plaintext signaling security.
Solution Approach 2:
The patent introduces an encryption algorithm as an intermediary between the KMS ID and the signaling transmission. Instead of directly transmitting the KMS ID in plaintext, the system uses encryption as a mediator to transform the KMS ID into ciphertext that can be securely transmitted within the signaling message, maintaining both security and accessibility for lawful interception.
2Adaptability or versatility
If multiple KMSs are deployed in the network, then the system flexibility and load distribution are improved, but the complexity of KMS identification and selection increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring the mapping relationship between user equipment and KMS in the network element before actual communication occurs. During user registration, the network element stores the correspondence between user identifiers and their assigned KMS identifiers. When lawful interception is needed, the intercepting device can directly query this pre-established mapping using the user's identifier to quickly determine which KMS to access, eliminating the need for complex real-time selection algorithms.
3Ease of operation
If the signaling plane security is relied upon for lawful intercepting, then the intercepting process is simplified, but the intercepting security is reduced when signaling is tampered with
Solution Approach 1:
The patent converts the potential harm of signaling tampering into a benefit by using the same encryption mechanism that protects user communication to also protect KMS information transmission. The lawful intercepting device, which has access to the decryption keys, can decrypt the encrypted signaling to extract KMS information, while any unauthorized tampering with the signaling would result in decryption failures or invalid data, automatically preventing unauthorized access. This transforms the security vulnerability of plaintext signaling into a secure authenticated access mechanism.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
The present invention discloses a method for obtaining key management server information, and an intercepting method, system and device, including: in the process of a user equipment registering an IP multimedia subsystem (IMS), storing the KMS information corresponding to the user equipment in a preset IMS core network network element; and when a lawful intercepting device monitors a session initiated by the user equipment, intercepting a session request signaling sent by the user equipment, and obtaining an identification information of the user equipment from the session request signaling, and searching the KMS information corresponding to the user equipment from the preset IMS core network network element according to the identification information of the user equipment. The technical solution of the present invention makes the requirement of lawful intercepting be met without depending on security of the signaling plane when a plurality of KMSs are deployed in the IP multimedia subsystem.