Network Node SIP Encryption Policy Management for VoLTE Handover

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for lawful intercept (LI) in voice over LTE (VoLTE) and voice over New Radio (VoNR) fail to intercept SIP-encrypted calls during handovers between public land mobile networks (PLMNs) across international borders, due to SIP encryption policies set by home operators.

Innovation Solution

Implementing a method where a network node enforces a UE to perform a SIP registration that switches off SIP encryption immediately after entering a second PLMN, initiates a SIP re-INVITE with SDP including subscriber IDs and speech codec information, and sends messages to configure different SIP encryption policies as needed for LI compliance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIP encryption is enforced during handover between PLMNs, then call security is improved, but lawful intercept capability deteriorates

Engineering Contradiction:
Improvecall securityVSAvoidLI intercept capability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies dynamics by making the SIP encryption policy changeable and context-dependent. The encryption status transitions from encrypted (in home PLMN) to unencrypted (in visiting PLMN for LI compliance) based on the network location and regulatory requirements. This dynamic adjustment allows the system to adapt encryption behavior to different operational contexts, resolving the contradiction between maintaining security and enabling lawful intercept.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the encryption parameter (SIP message encryption status) based on PLMN location and lawful intercept requirements. By modifying this critical parameter dynamically during handover, the system can switch between secure communication mode and lawful intercept mode, allowing both security and intercept capability to coexist through parameter adaptation rather than fixed behavior.

Inventive Principle:
Principle #35Parameter changes

2Loss of information

If SIP encryption is switched off for LI compliance, then intercept capability is improved, but call security deteriorates

Engineering Contradiction:
ImproveLI intercept capabilityVSAvoidcall security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent applies local quality by implementing different encryption policies in different locations (PLMNs). The home PLMN maintains encryption for security, while the visiting PLMN disables encryption to enable lawful intercept. This spatial differentiation of security characteristics allows each location to have the appropriate quality of encryption for its specific requirements, resolving the contradiction through localized policy application.

Inventive Principle:
Principle #3Local quality

3Productivity

If handover procedure is simplified, then mobility management is improved, but encryption policy management complexity increases

Engineering Contradiction:
Improvemobility management efficiencyVSAvoidencryption policy management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism (network node/S-CSCF) that handles the complex encryption policy management during handover. Instead of requiring the UE to manage encryption transitions, the network intermediary automatically detects PLMN changes, determines appropriate encryption policies, and executes the transition. This shifts the complexity from the UE to the network, simplifying mobility management while centralizing policy management functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250048214A1Network Node, User Equipment and Methods Performed Therein
Publication Date: 2025.02.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20250048214A1 patent drawing
  • US20250048214A1 patent drawing
  • US20250048214A1 patent drawing

AI summary

Embodiments herein relate, for example, to a method performed by a network node (150,13,15) for handling registering to an Internet Protocol Multimedia Subsystem, IMS, network in a communication network. The network node, with the proviso that a user equipment, UE, (10) is performing a handover from a first public land mobile network, PLMN, of a first country or operator to a second PLMN of a second country or operator, performs one or more of the following: —enforcing the UE (10) to make a session initiation protocol, SIP, registration whereby an IMS system can switch off SIP encryption policy, immediately after having entered the second PLMN; —initiating a SIP re-INVITE with a session description protocol, SDP, including a UE subscriber identity, ID, a remote party ID, and an indication of a speech codec; and 7 or —when the network node knows by configuration that the second PLMN requires a different SIP encryption policy than currently used, sending a message to another network node, wherein the message indicates explicitly or implicitly that a different SIP encryption policy and/or LI policy is to be used.