Use Case

Protecting Remote Users of UCaaS and SaaS Voice with Cloud Communications Access Security

The Challenge

A cloud communications platform is reached from everywhere: desk phones in an office, soft clients on laptops, apps on the phones of people working from home. Every one of those connections crosses the public internet to get to the platform, and every one needs to be encrypted, NAT-traversed, and authenticated.

Building that security into the cloud application itself means implementing and maintaining TLS and SRTP for every remote connection, handling NAT for home and branch routers, and absorbing scanning and attack traffic from the internet. That is specialized work that a UCaaS, contact center, or collaboration platform was not designed to do.

The Solution

How Access Security Works

Cloud communications access security is the use of an SBC to secure the connections between remote users and a cloud voice platform. The SBC sits at the boundary, handling SIP over TLS encryption, SRTP media encryption, and NAT traversal on the platform’s behalf.

A recurring pattern is that the cloud application prefers not to handle encryption directly. The SBC takes responsibility for it: communication between the remote device and the SBC is encrypted, and the SBC decrypts it and passes it in the clear to the UCaaS or CPaaS application inside the trusted cloud environment. This encryption offload lets the platform focus on serving users while the SBC handles the security of getting to it.

This is the access-security counterpart to the carrier-facing side of running voice in the cloud. Where connecting the platform to its carriers is covered in cloud communications trunking, this page is about securing the users who connect to the platform. The two are opposite edges of the same cloud platform.

Cloud communications access security topology: remote phones and soft clients connect over encrypted SIP-TLS and SRTP through a ProSBC, which decrypts and passes traffic in the clear to the cloud UCaaS platform

Cloud communications access security: remote phones and soft clients connect over encrypted SIP-TLS and SRTP to the SBC, which decrypts and passes traffic in the clear to the cloud platform. Click to enlarge.

Key Capabilities

What the SBC Does for Access Security

Encryption and Encryption Offload

The SBC terminates SIP over TLS and SRTP from each remote device, so signaling and media are encrypted across the internet. It then passes traffic in the clear to the application inside the trusted cloud, meaning the platform never has to implement encryption itself.

Remote and Work-from-Home Access

Users connecting from untrusted home and branch networks reach the platform through the SBC as a controlled entry point. It authenticates them, handles the NAT traversal their connections require, and ensures a soft client at home reaches the platform as reliably as a phone in the office.

Cloud-Native Protection

Being software, the SBC deploys in the same cloud environment as the UCaaS or CPaaS application, protecting it from within the same cloud rather than from separate infrastructure. This keeps the security boundary close to what it is protecting.

Deployment Options

Deploy It Your Way

Access security can be operated in whatever model the platform prefers:

Self-Managed

Run ProSBC in your own cloud or on-premises infrastructure: AWS, Azure, VMware, KVM, or bare metal. Full control over encryption policies, access rules, and scaling.

Managed Service

Hand deployment and day-to-day operation to TelcoBridges through the ProSBC managed service. Includes 1+1 HA, 24/7 support, setup, integration, and monitoring.

Fully Hosted

TelcoBridges hosts and manages the SBC entirely. The platform gets encrypted, NAT-traversed remote access without building the security layer itself.

Why ProSBC

ProSBC for Access Security

ProSBC is a carrier-grade, software-based session border controller built on more than 20 years of SIP deployment experience, and it is cloud-native. For the access security use case, it delivers:

SIP over TLS and SRTP termination from remote devices, with encryption offload so the cloud application receives traffic in the clear inside the trusted environment.
350,000 endpoint registrations per server, enough to secure remote access for a large user base from a single deployment.
NAT traversal and DoS/DDoS protection at the access edge, shielding the platform from scanning and attack traffic.
Cloud-native deployment on AWS, Azure, VMware, KVM, or bare metal, with annual subscription pricing and no upfront hardware investment.

Evaluate it with the free, permanent three-session ProSBC Lab, run a full 30-day trial, or start with the managed service.

FAQ

Frequently Asked Questions

What is cloud communications access security?

It is the use of an SBC to secure connections between remote users and a cloud voice platform, handling SIP over TLS encryption, SRTP media, and NAT traversal on the platform’s behalf. It applies to UCaaS, contact center, CPaaS, and collaboration services.

Why does the SBC handle encryption instead of the platform?

Cloud applications often prefer not to manage encryption directly. The SBC encrypts the connection between the remote device and itself, then passes traffic in the clear to the application inside the trusted cloud. This encryption offload lets the platform focus on serving users while the SBC secures access.

How does this protect work-from-home users?

Remote and work-from-home users connect from untrusted networks behind home routers. The SBC is the controlled entry point that encrypts and authenticates them with SIP-TLS and SRTP and handles the NAT traversal their connections need, so a soft client at home reaches the platform as securely as an office phone.

How is access security different from cloud communications trunking?

Access security is the user-facing side, protecting the remote devices and soft clients that connect to the platform. Cloud communications trunking is the carrier-facing side, connecting the platform to its operators. Both use an SBC but sit at opposite edges of the platform.

Secure Remote Access to Your Cloud Platform

Talk to a solutions architect about securing your cloud platform’s remote users with ProSBC, or start evaluating on your own.

Prefer to evaluate on your own first? Start your 30-day free trial.