EP2725762B1

Deciphering internet protocol (IP) security in an IP multimedia subsystem (IMS) using a monitoring system

Abstract

This record has no abstract on file.

EP2725762B1, drawing sheet 1
Sheet 1 of 5

Term

7.1 yearsleft in the term

Expires 25 October 2033.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

16 claims: 3 independent, 13 dependent

  1. 1
    A method, comprising:performing, by a telecommunications monitoring system (103): identifying a Security Association, SA, between a User Equipment, UE, and a Proxy Call Session Control Function, P-CSCF, of an Internet Protocol, IP, Multimedia Subsystem, IMS, over a Gm interface during a registration procedure;correlating the SA with a ciphering key, CK, exchanged between the P-CSCF and a Serving CSCF, S-CSCF, of the IMS over an Mw interface during the registration procedure, wherein correlating the SA with the CK includes matching a user identity from a message exchanged between the UE and the P-CSCF during the registration procedure against another message exchanged between the P-CSCF and the S-CSCF during the registration;storing an indication of the correlated SA and CK in a deciphering record;after the registration procedure, receiving a ciphered packet exchanged between the UE and the P-CSCF over the Gm interface;ascertaining an SA associated with the ciphered packet;identifying a CK corresponding to the ascertained SA in the deciphering record;and deciphering the ciphered packet, at least in part, using the identified CK.
  2. 9
    A telecommunications monitoring system (103), comprising:a processor (910A);and a memory (920) coupled to the processor, the memory configured to store program instructions executable by the processor to cause the telecommunications monitoring system to: identify a Security Association, SA, between a User Equipment, UE, and a Proxy Call Session Control Function, P-CSCF, of an Internet Protocol, IP, Multimedia Subsystem, IMS, over a Gm interface during an authentication procedure;correlate the SA with a ciphering key, CK, exchanged between the P-CSCF and a Serving CSCF, S-CSCF, of the IMS over an Mw interface during the authentication procedure, wherein to correlate the SA with the CK, the program instructions are further executable by the processor to cause the telecommunications monitoring system to match a user identity from a message exchanged between the UE and the P-CSCF during the authentication procedure against another message exchanged between the P-CSCF and the S-CSCF during the authentication procedure;store an indication of the correlated SA and CK in a deciphering record;receive a ciphered packet exchanged between the UE and the P-CSCF after the authentication procedure, the ciphered packet following an Encapsulating Security Payload, ESP, protocol in Transport Mode;ascertain an SA associated with the ciphered packet;identify a CK corresponding to the ascertained SA in the deciphering record;and decipher the ciphered packet, at least in part, using the identified CK.
  3. 13
    A tangible computer-readable storage medium having program instructions stored thereon that, upon execution by a processor (910A) within a computer system (900), cause the computer system (900) to:identify a Security Association, SA, between a User Equipment, UE, and a Proxy Call Session Control Function, P-CSCF, of an Internet Protocol, IP, Multimedia Subsystem, IMS, over a Gm interface during an authentication procedure, wherein to correlate the SA with the CK, the program instructions are further executable by the processor to cause the computer system to match a user identity from a message exchanged between the UE and the P-CSCF during the authentication procedure against another message exchanged between the P-CSCF and the S-CSCF during the authentication procedure;correlate the SA with a ciphering key, CK, exchanged between the P-CSCF and a Serving CSCF, S-CSCF, of the IMS over an Mw interface during the authentication procedure;store an indication of the correlated SA and CK in a deciphering record;receive a ciphered packet exchanged between the UE and the P-CSCF after the authentication procedure, the ciphered packet following an Encapsulating Security Payload, ESP, protocol in Transport Mode;ascertain an SA associated with the ciphered packet;identify a CK corresponding to the ascertained SA in the deciphering record;and decipher the ciphered packet, at least in part, using the identified CK.