Security Server Authentication in Telecommunications Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In telecommunications networks, particularly in UMTS systems, unauthorized access occurs when messages from unknown sources use publicly-known subscriber identifications, allowing unauthorized users to gain access to subscriber accounts and incur charges without the subscriber's knowledge.
Innovation Solution
A security server and network processing element that determine whether incoming messages are from known or unknown sources, modifying and forwarding messages accordingly to ensure security checks are performed, using Za and Zb interfaces for security clearance within the IMS network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the I-CSCF accepts messages from unknown sources using publicly-known subscriber identifications, then network accessibility and ease of operation are improved, but security and reliability deteriorate as unauthorized users can access subscriber accounts
Solution Approach 1:
A security server is introduced as an intermediary component between the I-CSCF and the HSS. This security server performs authentication and authorization checks on incoming messages before they are processed by the I-CSCF, acting as a mediator that filters out unauthorized access attempts while allowing legitimate messages to pass through. The security server uses Za and Zb interfaces to communicate with the HSS for verification purposes.
Solution Approach 2:
The security server performs authentication and authorization checks in advance, before the I-CSCF processes the incoming messages. By conducting these security checks preliminarily, the system prevents unauthorized messages from reaching the I-CSCF and HSS, thereby maintaining network security without affecting the ease of operation for legitimate users.
2Reliability
If the I-CSCF performs strict security verification on all incoming messages, then security and reliability are improved, but device complexity and processing overhead increase
Solution Approach 1:
The security verification process is segmented into distinct functional components: the security server handles authentication and authorization checks, while the I-CSCF focuses on message routing and the HSS manages subscriber data. This segmentation allows each component to perform its specific function efficiently without unnecessary complexity, as the security server pre- validates messages before they reach the I-CSCF.
Solution Approach 2:
By performing security checks in advance at the security server layer, the system avoids the need for the I-CSCF to perform complex verification operations on every incoming message. The preliminary authentication and authorization checks reduce the processing burden on the I-CSCF and HSS, maintaining security while reducing overall system complexity.
3Reliability
If the security server authenticates all messages before forwarding to I-CSCF, then unauthorized access is prevented, but message processing time increases
Solution Approach 1:
The security server performs authentication and authorization checks in advance, before messages are forwarded to the I-CSCF for further processing. By completing these security validations preliminarily, the system ensures that only authorized messages proceed to the I-CSCF, preventing unauthorized access while minimizing the time impact on legitimate message processing, as the security checks are performed in parallel with message routing decisions.
Data Source
AI summary
A security server for use in a telecommunications network is arranged to receive a message; determine whether the message is from a known source or an unknown source and, depending on the result of the determination, modify the message; and forward the message within the telecommunications network. A network processing element for use in a telecommunications network is arranged to receive a message from another network element; determine whether the message has been modified and, depending on the result of the determination, perform one or more security checks in respect of the message.


