Method of and apparatus for authenticating control messages in a signaling network
    7.
    发明授权
    Method of and apparatus for authenticating control messages in a signaling network 失效
    用于在信令网络中认证控制消息的方法和装置

    公开(公告)号:US07360090B1

    公开(公告)日:2008-04-15

    申请号:US09767292

    申请日:2001-01-18

    IPC分类号: H04L9/00

    摘要: A communication network includes an SS7 Security Gatekeeper that authenticates and validates network control messages within, transiting, entering and leaving an overlying control fabric such as an SS7 network. The SS7 Security Gatekeeper incorporates several levels of checks to ensure that messages are properly authenticated, valid, and consistent with call progress and system status. In addition to message format, message content is checked to ensure that the originating node has the proper authority to send the message and to invoke the related functions. Predefined sets of templates may be used to check the messages, each set of templates being associated with respective originating point codes and/or calling party addresses. The templates may also be associated with various system states such that messages corresponding to a particular template cause a state transition along a particular edge to a next state node at which another set of templates are defined. Thus, system and call state is maintained. The monitor also includes signaling point authentication using digital signatures and timestamps. Timestamps are also used to initiate appropriate timeouts and so that old or improperly sequenced message may be ignored, corrected or otherwise processed appropriately. The SS7 Security Gatekeeper may be located at the edge of a network to be protected so that all messaging to and from the protected network most egress by way of the Gatekeeper. Alternatively, the SS7 Security Gatekeeper may be internal to the protected network and configured as a “pseudo switch” so that ISUP messaging is routed through the Gatekeeper while actual traffic is trunked directly between the associated SSPs, bypassing the Gatekeeper.

    摘要翻译: 通信网络包括SS7安全网守,用于对网络控制消息进行身份验证和验证,例如SS7网络,覆盖,进入和离开上层控制架构。 SS7安全网闸包含几个级别的检查,以确保消息被正确认证,有效,并与呼叫进度和系统状态一致。 除了消息格式之外,检查消息内容以确保始发节点具有发送消息的适当权限并调用相关功能。 可以使用预定义的模板集来检查消息,每组模板与相应的起始点代码和/或主叫方地址相关联。 模板还可以与各种系统状态相关联,使得对应于特定模板的消息导致沿着特定边缘的状态转换到另一组模板被定义的下一个状态节点。 因此,维持系统和呼叫状态。 监视器还包括使用数字签名和时间戳的信令点认证。 时间戳也用于启动适当的超时,从而可能会忽略,纠正或以其他方式适当地处理旧的或不正确排序的消息。 SS7安全网守可能位于要保护的网络的边缘,以便所有来自受保护网络的消息通过网守大部分出口。 或者,SS7安全网守可能在受保护网络内部,并被配置为“伪交换机”,以便通过网闸路由ISUP消息传递,而实际流量在关联的SSP之间直接中继,而不需要网守。