Session Security Gatekeeper for VoIP Admission Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional admission control methods in packetized voice communication networks are inadequate for securely allowing traffic from un-trusted networks to enter trusted networks, particularly for devices without dedicated authentication means, such as off-the-shelf IP phones or soft-phones, which complicates voice communication while compromising network security.

Innovation Solution

Implementing a Session Security Gatekeeper (SSG) that examines call control messages based on pre-determined criteria, such as caller identity, call destination, server identity, content type, and media protocols, to control traffic admission into the trusted network, using a Traffic Identification Procedure (TIP) to ensure only authorized traffic is admitted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traffic from un-trusted networks is allowed to enter trusted networks, then communication flexibility is improved, but network security is compromised

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

A Session Security Gatekeeper (SSG) is introduced as an intermediary component between un-trusted networks and trusted VoIP networks. The SSG performs pre-admission authentication by examining call control messages (such as SIP INVITE) and media descriptions before allowing traffic to enter the trusted network. This mediator approach enables flexible communication while maintaining security through centralized authentication control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs authentication and security checks before admission into the trusted network. The SSG examines call control messages and media descriptions in advance to verify caller identity, authentication status, and protocol compliance. Only after successful preliminary verification is traffic allowed to enter the trusted VoIP network, preventing security breaches while enabling authorized communication.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If pre-admission authentication is implemented for devices without dedicated authentication means, then network security is improved, but device complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication mechanism
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication mechanism leverages existing SIP call control messages and media descriptions that are already part of the VoIP communication protocol. Devices without dedicated authentication means can still be authenticated by utilizing the standard SIP INVITE message structure and SDP media descriptions, eliminating the need for additional authentication hardware or complex custom protocols.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The SSG performs multiple authentication functions using a single approach: examining call control messages for caller identity verification, checking authentication status from previous SIP interactions, and validating media descriptions for protocol compliance. This universal authentication method handles multiple security requirements through one unified mechanism, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If VLAN segregation is implemented to separate voice and data traffic, then network reliability is improved, but communication between trusted and un-trusted devices is restricted

Engineering Contradiction:
Improvenetwork reliabilityVSAvoidcommunication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The Session Security Gatekeeper acts as a mediator that bridges the segregated trusted and un-trusted networks. It receives call control messages from un-trusted networks, performs authentication, and forwards authorized traffic to the trusted VoIP network. This enables communication between devices on different VLANs while maintaining the security benefits of network segmentation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system operates at the Session Layer (Layer 5 of OSI model) rather than attempting to bridge at lower layers. By performing authentication and traffic control at the session level, the SSG enables communication between segregated networks without compromising the VLAN-based segmentation at the data link and network layers, thus maintaining reliability while enabling controlled communication.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS7742463B2Security gatekeeper for a packetized voice communication network
Publication Date: 2010.06.22 HONG KONG APPLIED SCI & TECH RES INST
  • US7742463B2 patent drawing
  • US7742463B2 patent drawing
  • US7742463B2 patent drawing

AI summary

Admission control means for controlling admission of traffic into a voice communication network, the admission control means comprises means for examining a call control message of a call control dialogue when admission of said traffic into said voice communication network is requested, the admission control means admit a traffic into said voice communication network only if the call control message accompanying the traffic admission request satisfies a pre-determined admission criterion.