Proactive SA Key Transfer for IMS Handoff Delay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing IMS/MMD security architecture faces challenges in optimizing IPSec tunnel establishment during handoffs, leading to delays and increased overhead, which can impact network performance and user experience, especially in scenarios involving mobile nodes and roaming.

Innovation Solution

The proposed solution involves proactive key transfer mechanisms, such as transferring SA keys from the old P-CSCF to the new P-CSCF or from the S-CSCF to the new P-CSCF, before the mobile node physically moves to a new network, to establish security associations in advance, thereby reducing the delay and IPSec tunnel overhead during handoffs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security association is established between mobile node and P-CSCF using traditional IMS/MMD architecture, then security protection is provided, but handoff delay increases and network performance deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidhandoff delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing security associations between the mobile node and the target P-CSCF before the handoff occurs. When a mobile node moves to a new network, the target P-CSCF already has a pre-established security association with the mobile node, eliminating the need for time-consuming security association setup during handoff. This is achieved through the home P-CSCF transferring security context information to the target P-CSCF in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The home P-CSCF acts as an intermediary that facilitates the transfer of security context information from the mobile node to the target P-CSCF. This intermediary mechanism enables the target P-CSCF to obtain necessary security parameters without direct communication with the mobile node during handoff, thereby reducing handoff delay while maintaining security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If IPSec tunnel is established for security protection, then confidentiality and integrity are ensured, but tunnel overhead increases

Engineering Contradiction:
Improveconfidentiality and integrityVSAvoidtunnel overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts and transfers only the essential security context information (security parameters, keys, and identifiers) from the home P-CSCF to the target P-CSCF, rather than establishing complete IPSec tunnels. This selective extraction reduces the overhead by transferring only the minimum necessary data for security association establishment, eliminating redundant tunneling overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the security association parameters by using the home P-CSCF's security context as a template for the target P-CSCF. Instead of establishing new security associations from scratch, the system reuses and adapts existing security parameters, reducing the complexity and overhead of security setup during handoff.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9025771B2Security optimization for IMS/MMD architecture
Publication Date: 2015.05.05 TELCORDIA TECHNOLOGIES INC
  • US9025771B2 patent drawing
  • US9025771B2 patent drawing
  • US9025771B2 patent drawing

AI summary

A mechanism by which handoff delay can be minimized while not compromising the IMS/MMD security and also protecting the media if required by certain applications is presented. Methods for mitigating delay during SA re-association and mitigating the IPSec tunnel overhead for signaling and media at the Mobile Node are given. In one embodiment, SA keys can be transferred from the old P-CSCF to new P-CSCF, enabling the establishment of SAs before Mobile Node physically moves to the new subnet in a network. Proactive handover is used. In another embodiment, SA keys are transferred from S-CSCF to new P-CSCF. In this case, the SA keys are transferred to the new P-CSCF by S-CSCF through a context transfer mechanism well in advance so that SAs may be established before Mobile Node physically moves to new subnet. In another embodiment, methods for mitigating IPSec tunnel overhead are presented.