Network Node SIP Encryption Policy Management for VoLTE Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for lawful intercept (LI) in voice over LTE (VoLTE) and voice over New Radio (VoNR) fail to intercept SIP-encrypted calls during handovers between public land mobile networks (PLMNs) across international borders, due to SIP encryption policies set by home operators.
Innovation Solution
Implementing a method where a network node enforces a UE to perform a SIP registration that switches off SIP encryption immediately after entering a second PLMN, initiates a SIP re-INVITE with SDP including subscriber IDs and speech codec information, and sends messages to configure different SIP encryption policies as needed for LI compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIP encryption is enforced during handover between PLMNs, then call security is improved, but lawful intercept capability deteriorates
Solution Approach 1:
The patent applies dynamics by making the SIP encryption policy changeable and context-dependent. The encryption status transitions from encrypted (in home PLMN) to unencrypted (in visiting PLMN for LI compliance) based on the network location and regulatory requirements. This dynamic adjustment allows the system to adapt encryption behavior to different operational contexts, resolving the contradiction between maintaining security and enabling lawful intercept.
Solution Approach 2:
The patent changes the encryption parameter (SIP message encryption status) based on PLMN location and lawful intercept requirements. By modifying this critical parameter dynamically during handover, the system can switch between secure communication mode and lawful intercept mode, allowing both security and intercept capability to coexist through parameter adaptation rather than fixed behavior.
2Loss of information
If SIP encryption is switched off for LI compliance, then intercept capability is improved, but call security deteriorates
Solution Approach 1:
The patent applies local quality by implementing different encryption policies in different locations (PLMNs). The home PLMN maintains encryption for security, while the visiting PLMN disables encryption to enable lawful intercept. This spatial differentiation of security characteristics allows each location to have the appropriate quality of encryption for its specific requirements, resolving the contradiction through localized policy application.
3Productivity
If handover procedure is simplified, then mobility management is improved, but encryption policy management complexity increases
Solution Approach 1:
The patent introduces an intermediary mechanism (network node/S-CSCF) that handles the complex encryption policy management during handover. Instead of requiring the UE to manage encryption transitions, the network intermediary automatically detects PLMN changes, determines appropriate encryption policies, and executes the transition. This shifts the complexity from the UE to the network, simplifying mobility management while centralizing policy management functionality.
Data Source
AI summary
Embodiments herein relate, for example, to a method performed by a network node (150,13,15) for handling registering to an Internet Protocol Multimedia Subsystem, IMS, network in a communication network. The network node, with the proviso that a user equipment, UE, (10) is performing a handover from a first public land mobile network, PLMN, of a first country or operator to a second PLMN of a second country or operator, performs one or more of the following: —enforcing the UE (10) to make a session initiation protocol, SIP, registration whereby an IMS system can switch off SIP encryption policy, immediately after having entered the second PLMN; —initiating a SIP re-INVITE with a session description protocol, SDP, including a UE subscriber identity, ID, a remote party ID, and an indication of a speech codec; and 7 or —when the network node knows by configuration that the second PLMN requires a different SIP encryption policy than currently used, sending a message to another network node, wherein the message indicates explicitly or implicitly that a different SIP encryption policy and/or LI policy is to be used.


