VoIP Border Security Controller Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Session Border Controllers (SBCs) in Next Generation Networks (NGN) and Voice over Internet Protocol (VoIP) networks are vulnerable to malicious attacks due to complex signaling protocol stacks and inability to ensure security, particularly from malformed packets and unauthorized resource occupation.

Innovation Solution

A method and system for controlling communication border security that performs security processing on data packets by determining their type, querying active session and registered user information tables, and performing integrity detection and source authentication to discard unauthorized packets, while updating tables based on processing results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security control is performed via SBC with complex signaling protocol stack, then security control capability is provided, but the SBC is susceptible to malicious attacks and resource occupation

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidmalicious attacks and resource occupation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the SBC functionality into two separate components: a security control device that performs packet filtering and authentication, and a protocol processing device that handles signaling protocols. This segmentation isolates the complex protocol stack from direct packet processing, preventing malicious packets from directly attacking the protocol processing components while maintaining security control capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security control device positioned between the network and the SBC. This intermediary performs preliminary security checks, authentication, and packet filtering before packets reach the SBC's protocol stack, acting as a protective mediator that blocks malicious traffic without requiring the SBC itself to handle security processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the SBC processes all packets through its protocol stack, then protocol processing capability is provided, but malformed packets can break down the SBC

Engineering Contradiction:
Improveprotocol processing capabilityVSAvoiddevice stability against malformed packets
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by performing security validation, authentication, and packet structure verification before packets are forwarded to the protocol processing device. This preliminary filtering ensures that only well-formed, authenticated packets reach the protocol stack, preventing malformed packets from causing device breakdown while maintaining full protocol processing capability.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the SBC performs both security control and protocol processing, then comprehensive functionality is provided, but the device complexity increases

Engineering Contradiction:
Improvecomprehensive functionalityVSAvoiddevice structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the comprehensive SBC functionality into separate specialized devices: a security control device for security policies, authentication, and packet filtering, and a protocol processing device for signaling protocol handling. This segmentation maintains comprehensive functionality while reducing device complexity by allowing each component to be optimized independently and managed separately.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7904954B2Method, device and security control system for controlling communication border security
Publication Date: 2011.03.08 HUAWEI TECH CO LTD
  • US7904954B2 patent drawing
  • US7904954B2 patent drawing
  • US7904954B2 patent drawing

AI summary

The present invention provides a method, a device and a system for controlling VoIP border security. The system includes: a border security controller, which includes two dynamic information tables, an active session information table and a registered user information table, acting as the basis of security control; and a security policy server, in communication with the border security controller, adapted to provide a security policy to the border security controller and check the security of a signaling packet forwarded by the border security controller. The border security control system first checks the security and processes the packets of a user datagram received according to the active session information table and the registered user information table, and allows a packet which passed the security processing to pass, and then performs protocol processing on the media packet and signaling packet which are allowed to pass.