Session Security Gatekeeper for VoIP Admission Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional admission control methods in packetized voice communication networks are inadequate for securely allowing traffic from un-trusted networks to enter trusted networks, particularly for devices without dedicated authentication means, such as off-the-shelf IP phones or soft-phones, which complicates voice communication while compromising network security.
Innovation Solution
Implementing a Session Security Gatekeeper (SSG) that examines call control messages based on pre-determined criteria, such as caller identity, call destination, server identity, content type, and media protocols, to control traffic admission into the trusted network, using a Traffic Identification Procedure (TIP) to ensure only authorized traffic is admitted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traffic from un-trusted networks is allowed to enter trusted networks, then communication flexibility is improved, but network security is compromised
Solution Approach 1:
A Session Security Gatekeeper (SSG) is introduced as an intermediary component between un-trusted networks and trusted VoIP networks. The SSG performs pre-admission authentication by examining call control messages (such as SIP INVITE) and media descriptions before allowing traffic to enter the trusted network. This mediator approach enables flexible communication while maintaining security through centralized authentication control.
Solution Approach 2:
The system performs authentication and security checks before admission into the trusted network. The SSG examines call control messages and media descriptions in advance to verify caller identity, authentication status, and protocol compliance. Only after successful preliminary verification is traffic allowed to enter the trusted VoIP network, preventing security breaches while enabling authorized communication.
2Object-affected harmful factors
If pre-admission authentication is implemented for devices without dedicated authentication means, then network security is improved, but device complexity increases
Solution Approach 1:
The authentication mechanism leverages existing SIP call control messages and media descriptions that are already part of the VoIP communication protocol. Devices without dedicated authentication means can still be authenticated by utilizing the standard SIP INVITE message structure and SDP media descriptions, eliminating the need for additional authentication hardware or complex custom protocols.
Solution Approach 2:
The SSG performs multiple authentication functions using a single approach: examining call control messages for caller identity verification, checking authentication status from previous SIP interactions, and validating media descriptions for protocol compliance. This universal authentication method handles multiple security requirements through one unified mechanism, reducing overall system complexity.
3Reliability
If VLAN segregation is implemented to separate voice and data traffic, then network reliability is improved, but communication between trusted and un-trusted devices is restricted
Solution Approach 1:
The Session Security Gatekeeper acts as a mediator that bridges the segregated trusted and un-trusted networks. It receives call control messages from un-trusted networks, performs authentication, and forwards authorized traffic to the trusted VoIP network. This enables communication between devices on different VLANs while maintaining the security benefits of network segmentation.
Solution Approach 2:
The system operates at the Session Layer (Layer 5 of OSI model) rather than attempting to bridge at lower layers. By performing authentication and traffic control at the session level, the SSG enables communication between segregated networks without compromising the VLAN-based segmentation at the data link and network layers, thus maintaining reliability while enabling controlled communication.
Data Source
AI summary
Admission control means for controlling admission of traffic into a voice communication network, the admission control means comprises means for examining a call control message of a call control dialogue when admission of said traffic into said voice communication network is requested, the admission control means admit a traffic into said voice communication network only if the call control message accompanying the traffic admission request satisfies a pre-determined admission criterion.


