SIP Signaling Decryption via Gm Cx Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing SIP signaling decryption methods in LTE networks increase operating costs for operators while failing to meet operational requirements, as they render the signaling monitoring system incapable of monitoring encrypted SIP-VOIP services.
Innovation Solution
A method and apparatus that acquire authentication information from Gm and Cx interfaces to generate a Security Association (SA) decryption table, allowing for the decryption of SIP signaling without additional monitoring systems, thereby enabling the monitoring of SIP-VOIP services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIP signaling is encrypted using IPSec ESP mechanism, then security of IMS access is improved, but the signaling monitoring system becomes incapable of decrypting and monitoring the SIP signaling
Solution Approach 1:
The patent introduces an intermediary component (signaling monitoring system with decryption capability) that acts as a mediator between the encrypted SIP signaling and the monitoring requirements. This intermediary obtains decryption parameters through the AKA authentication process and uses them to decrypt and monitor SIP signaling without compromising security, thus resolving the contradiction between encryption security and monitoring capability
Solution Approach 2:
The patent applies preliminary action by obtaining decryption parameters during the AKA authentication phase before actual SIP signaling encryption occurs. The signaling monitoring system proactively captures authentication information and generates decryption parameter tables in advance, enabling subsequent monitoring of encrypted SIP signaling without real-time decryption delays or security compromises
2Loss of information
If a signaling collection system is deployed in the IMS system, then SIP-VOIP service monitoring capability is improved, but the operating cost of the operator increases
Solution Approach 1:
The patent makes the signaling monitoring system multi-functional by enabling it to perform both traditional signaling monitoring and SIP signaling decryption/monitoring through obtained decryption parameters. This universal system serves multiple purposes (general signaling monitoring, encrypted SIP monitoring, security analysis) without requiring separate dedicated systems, thereby reducing overall operating costs while maintaining comprehensive monitoring capability
Solution Approach 2:
The patent merges the SIP signaling decryption functionality with the existing signaling monitoring system rather than deploying a separate collection system in the IMS. By combining these functions into a unified system that operates within the EPS architecture, the patent eliminates redundant infrastructure and reduces operating costs while achieving comprehensive SIP-VOIP service monitoring
3Loss of information
If an additional monitoring system is set in the IMS system, then SIP signaling decryption capability is improved, but the device complexity and system integration difficulty increase
Solution Approach 1:
The patent segments the decryption functionality into modular components that can be independently obtained and integrated. The decryption parameter table is separated from the authentication process, and the signaling monitoring system independently acquires necessary parameters through standardized interfaces. This segmentation reduces integration complexity by allowing incremental implementation and independent testing of each component
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Disclosed in the embodiment of the present invention is a method for acquiring session initiation protocol (SIP) signaling decryption parameters and the method comprises the following steps: the authentication information of the Gm interface and the authentication information of the Cx interface are acquired; a security association (SA) decryption table is created according to the acquired authentication information of the Cx interface and authentication information of the Gm interface, wherein the SA decryption table comprises SIP signaling decryption parameters. A device for acquiring SIP signaling decryption parameters is also disclosed in the embodiments of the present invention.