Protecting Remote Users of UCaaS and SaaS Voice with Cloud Communications Access Security
A cloud communications platform is reached from everywhere: desk phones in an office, soft clients on laptops, apps on the phones of people working from home. Every one of those connections crosses the public internet to get to the platform, and every one needs to be encrypted, NAT-traversed, and authenticated.
Building that security into the cloud application itself means implementing and maintaining TLS and SRTP for every remote connection, handling NAT for home and branch routers, and absorbing scanning and attack traffic from the internet. That is specialized work that a UCaaS, contact center, or collaboration platform was not designed to do.
How Access Security Works
Cloud communications access security is the use of an SBC to secure the connections between remote users and a cloud voice platform. The SBC sits at the boundary, handling SIP over TLS encryption, SRTP media encryption, and NAT traversal on the platform’s behalf.
A recurring pattern is that the cloud application prefers not to handle encryption directly. The SBC takes responsibility for it: communication between the remote device and the SBC is encrypted, and the SBC decrypts it and passes it in the clear to the UCaaS or CPaaS application inside the trusted cloud environment. This encryption offload lets the platform focus on serving users while the SBC handles the security of getting to it.
This is the access-security counterpart to the carrier-facing side of running voice in the cloud. Where connecting the platform to its carriers is covered in cloud communications trunking, this page is about securing the users who connect to the platform. The two are opposite edges of the same cloud platform.
Cloud communications access security: remote phones and soft clients connect over encrypted SIP-TLS and SRTP to the SBC, which decrypts and passes traffic in the clear to the cloud platform. Click to enlarge.
What the SBC Does for Access Security
Encryption and Encryption Offload
The SBC terminates SIP over TLS and SRTP from each remote device, so signaling and media are encrypted across the internet. It then passes traffic in the clear to the application inside the trusted cloud, meaning the platform never has to implement encryption itself.
Remote and Work-from-Home Access
Users connecting from untrusted home and branch networks reach the platform through the SBC as a controlled entry point. It authenticates them, handles the NAT traversal their connections require, and ensures a soft client at home reaches the platform as reliably as a phone in the office.
Deploy It Your Way
Access security can be operated in whatever model the platform prefers:
Self-Managed
Run ProSBC in your own cloud or on-premises infrastructure: AWS, Azure, VMware, KVM, or bare metal. Full control over encryption policies, access rules, and scaling.
Managed Service
Hand deployment and day-to-day operation to TelcoBridges through the ProSBC managed service. Includes 1+1 HA, 24/7 support, setup, integration, and monitoring.
Fully Hosted
TelcoBridges hosts and manages the SBC entirely. The platform gets encrypted, NAT-traversed remote access without building the security layer itself.
ProSBC for Access Security
ProSBC is a carrier-grade, software-based session border controller built on more than 20 years of SIP deployment experience, and it is cloud-native. For the access security use case, it delivers:
Evaluate it with the free, permanent three-session ProSBC Lab, run a full 30-day trial, or start with the managed service.
Frequently Asked Questions
What is cloud communications access security?
It is the use of an SBC to secure connections between remote users and a cloud voice platform, handling SIP over TLS encryption, SRTP media, and NAT traversal on the platform’s behalf. It applies to UCaaS, contact center, CPaaS, and collaboration services.
Why does the SBC handle encryption instead of the platform?
Cloud applications often prefer not to manage encryption directly. The SBC encrypts the connection between the remote device and itself, then passes traffic in the clear to the application inside the trusted cloud. This encryption offload lets the platform focus on serving users while the SBC secures access.
How does this protect work-from-home users?
Remote and work-from-home users connect from untrusted networks behind home routers. The SBC is the controlled entry point that encrypts and authenticates them with SIP-TLS and SRTP and handles the NAT traversal their connections need, so a soft client at home reaches the platform as securely as an office phone.
How is access security different from cloud communications trunking?
Access security is the user-facing side, protecting the remote devices and soft clients that connect to the platform. Cloud communications trunking is the carrier-facing side, connecting the platform to its operators. Both use an SBC but sit at opposite edges of the platform.
Secure Remote Access to Your Cloud Platform
Talk to a solutions architect about securing your cloud platform’s remote users with ProSBC, or start evaluating on your own.
Prefer to evaluate on your own first? Start your 30-day free trial.