SIP Signaling Decryption via Gm Cx Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing SIP signaling decryption methods in LTE networks increase operating costs for operators while failing to meet operational requirements, as they render the signaling monitoring system incapable of monitoring encrypted SIP-VOIP services.

Innovation Solution

A method and apparatus that acquire authentication information from Gm and Cx interfaces to generate a Security Association (SA) decryption table, allowing for the decryption of SIP signaling without additional monitoring systems, thereby enabling the monitoring of SIP-VOIP services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIP signaling is encrypted using IPSec ESP mechanism, then security of IMS access is improved, but the signaling monitoring system becomes incapable of decrypting and monitoring the SIP signaling

Engineering Contradiction:
Improvesecurity of IMS accessVSAvoidmonitoring capability of SIP signaling
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an intermediary component (signaling monitoring system with decryption capability) that acts as a mediator between the encrypted SIP signaling and the monitoring requirements. This intermediary obtains decryption parameters through the AKA authentication process and uses them to decrypt and monitor SIP signaling without compromising security, thus resolving the contradiction between encryption security and monitoring capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by obtaining decryption parameters during the AKA authentication phase before actual SIP signaling encryption occurs. The signaling monitoring system proactively captures authentication information and generates decryption parameter tables in advance, enabling subsequent monitoring of encrypted SIP signaling without real-time decryption delays or security compromises

Inventive Principle:
Principle #10Preliminary action

2Loss of information

If a signaling collection system is deployed in the IMS system, then SIP-VOIP service monitoring capability is improved, but the operating cost of the operator increases

Engineering Contradiction:
Improvemonitoring capability of SIP-VOIP serviceVSAvoidoperating cost
Core Design Contradiction:
Loss of informationVSQuantity of substance

Solution Approach 1:

The patent makes the signaling monitoring system multi-functional by enabling it to perform both traditional signaling monitoring and SIP signaling decryption/monitoring through obtained decryption parameters. This universal system serves multiple purposes (general signaling monitoring, encrypted SIP monitoring, security analysis) without requiring separate dedicated systems, thereby reducing overall operating costs while maintaining comprehensive monitoring capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the SIP signaling decryption functionality with the existing signaling monitoring system rather than deploying a separate collection system in the IMS. By combining these functions into a unified system that operates within the EPS architecture, the patent eliminates redundant infrastructure and reduces operating costs while achieving comprehensive SIP-VOIP service monitoring

Inventive Principle:
Principle #5Merging (Combining)

3Loss of information

If an additional monitoring system is set in the IMS system, then SIP signaling decryption capability is improved, but the device complexity and system integration difficulty increase

Engineering Contradiction:
ImproveSIP signaling decryption capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent segments the decryption functionality into modular components that can be independently obtained and integrated. The decryption parameter table is separated from the authentication process, and the signaling monitoring system independently acquires necessary parameters through standardized interfaces. This segmentation reduces integration complexity by allowing incremental implementation and independent testing of each component

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3197235B1Method and device for acquiring sip signaling decryption parameters
Publication Date: 2020.08.05 ZTE CORP
  • EP3197235B1 patent drawingFigure 1
  • EP3197235B1 patent drawingFigure 2
  • EP3197235B1 patent drawingFigure 3~4

AI summary

Disclosed in the embodiment of the present invention is a method for acquiring session initiation protocol (SIP) signaling decryption parameters and the method comprises the following steps: the authentication information of the Gm interface and the authentication information of the Cx interface are acquired; a security association (SA) decryption table is created according to the acquired authentication information of the Cx interface and authentication information of the Gm interface, wherein the SA decryption table comprises SIP signaling decryption parameters. A device for acquiring SIP signaling decryption parameters is also disclosed in the embodiments of the present invention.