Procedure for IMS framework to support authorization and authentication of third-party user identities in IMS sessions
The IMS framework enhances authentication and authorization of third-party identities using a subscription profile and cryptographic verification, addressing inefficiencies and security issues in MMTEL services, ensuring secure and reliable communication.
Patent Information
- Application Number
- PCT/KR2025/000496
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-09
- Filing Date
- 2025-01-09
- Publication Date
- 2025-07-17
AI Technical Summary
Existing MMTEL services face challenges in managing employee subscriptions and authenticating third-party user identities, leading to inefficiencies and security issues in business communications, particularly in dynamic environments with global presence and increased fraudulent call rejections.
The proposed solution involves enhancing the IMS framework to selectively authenticate and authorize third-party user identities by incorporating a subscription profile in the Home Subscriber Server (HSS) that indicates the need for authentication, using a Signing server at the originating side and a Verification server at the terminating side to ensure secure communication, and employing cryptographic techniques to verify the authenticity of third-party identities.
This approach ensures secure and reliable communication by authenticating authorized third-party identities, reducing fraudulent activities and enhancing trustworthiness in multimedia sessions, thereby improving operational efficiency and customer relations.
Smart Images

Figure KR2025000496_17072025_PF_FP_ABST
Abstract
Description
PROCEDURE FOR IMS FRAMEWORK TO SUPPORT AUTHORIZATION AND AUTHENTICATION OF THIRD-PARTY USER IDENTITIES IN IMS SESSIONS
[0001] The proposed embodiments relate to an IP Multimedia Subsystem (IMS) framework. More particularly, the present disclosure relates to a procedure for the IMS framework to support authorization and authentication of third-party user identities in IMS sessions.
[0002] 5G mobile communication technologies define broad frequency bands such that high transmission rates and new services are possible, and can be implemented not only in "Sub 6GHz" bands such as 3.5GHz, but also in "Above 6GHz" bands referred to as mmWave including 28GHz and 39GHz. In addition, it has been considered to implement 6G mobile communication technologies (referred to as Beyond 5G systems) in terahertz bands (for example, 95GHz to 3THz bands) in order to accomplish transmission rates fifty times faster than 5G mobile communication technologies and ultra-low latencies one-tenth of 5G mobile communication technologies.
[0003] At the beginning of the development of 5G mobile communication technologies, in order to support services and to satisfy performance requirements in connection with enhanced Mobile BroadBand (eMBB), Ultra Reliable Low Latency Communications (URLLC), and massive Machine-Type Communications (mMTC), there has been ongoing standardization regarding beamforming and massive MIMO for mitigating radio-wave path loss and increasing radio-wave transmission distances in mmWave, supporting numerologies (for example, operating multiple subcarrier spacings) for efficiently utilizing mmWave resources and dynamic operation of slot formats, initial access technologies for supporting multi-beam transmission and broadbands, definition and operation of BWP (BandWidth Part), new channel coding methods such as a LDPC (Low Density Parity Check) code for large amount of data transmission and a polar code for highly reliable transmission of control information, L2 pre-processing, and network slicing for providing a dedicated network specialized to a specific service.
[0004] Currently, there are ongoing discussions regarding improvement and performance enhancement of initial 5G mobile communication technologies in view of services to be supported by 5G mobile communication technologies, and there has been physical layer standardization regarding technologies such as V2X (Vehicle-to-everything) for aiding driving determination by autonomous vehicles based on information regarding positions and states of vehicles transmitted by the vehicles and for enhancing user convenience, NR-U (New Radio Unlicensed) aimed at system operations conforming to various regulation-related requirements in unlicensed bands, NR UE Power Saving, Non-Terrestrial Network (NTN) which is UE-satellite direct communication for providing coverage in an area in which communication with terrestrial networks is unavailable, and positioning.
[0005] Moreover, there has been ongoing standardization in air interface architecture / protocol regarding technologies such as Industrial Internet of Things (IIoT) for supporting new services through interworking and convergence with other industries, IAB (Integrated Access and Backhaul) for providing a node for network service area expansion by supporting a wireless backhaul link and an access link in an integrated manner, mobility enhancement including conditional handover and DAPS (Dual Active Protocol Stack) handover, and two-step random access for simplifying random access procedures (2-step RACH for NR). There also has been ongoing standardization in system architecture / service regarding a 5G baseline architecture (for example, service based architecture or service based interface) for combining Network Functions Virtualization (NFV) and Software-Defined Networking (SDN) technologies, and Mobile Edge Computing (MEC) for receiving services based on UE positions.
[0006] As 5G mobile communication systems are commercialized, connected devices that have been exponentially increasing will be connected to communication networks, and it is accordingly expected that enhanced functions and performances of 5G mobile communication systems and integrated operations of connected devices will be necessary. To this end, new research is scheduled in connection with eXtended Reality (XR) for efficiently supporting AR (Augmented Reality), VR (Virtual Reality), MR (Mixed Reality) and the like, 5G performance improvement and complexity reduction by utilizing Artificial Intelligence (AI) and Machine Learning (ML), AI service support, metaverse service support, and drone communication.
[0007] Furthermore, such development of 5G mobile communication systems will serve as a basis for developing not only new waveforms for providing coverage in terahertz bands of 6G mobile communication technologies, multi-antenna transmission technologies such as Full Dimensional MIMO (FD-MIMO), array antennas and large-scale antennas, metamaterial-based lenses and antennas for improving coverage of terahertz band signals, high-dimensional space multiplexing technology using OAM (Orbital Angular Momentum), and RIS (Reconfigurable Intelligent Surface), but also full-duplex technology for increasing frequency efficiency of 6G mobile communication technologies and improving system networks, AI-based communication technology for implementing system optimization by utilizing satellites and AI (Artificial Intelligence) from the design stage and internalizing end-to-end AI support functions, and next-generation distributed computing technology for implementing services at levels of complexity exceeding the limit of UE operation capability by utilizing ultra-high-performance communication and computing resources.
[0008] In an embodiment, a method performed by an originating IMS network for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided. The method may include receiving an INVITE from a User Equipment (UE). The method may include obtaining a subscription information of the UE from a Home Subscriber Server (HSS). The method may include identifying whether the UE is authorized to use the third-party user identity based on the subscription information. The method may include obtaining the third-party user identity from the HSS, based on identifying that the UE is authorized to use the third-party user identity. The method may include transmitting the INVITE that includes a signed third-party user identity to a terminating IMS network.
[0009] In an embodiment, a method performed by a terminating IMS network for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided. The method may include receiving an INVITE that includes a signed third-party user identity from an originating IMS network. The method may include transmitting the INVITE that includes the signed third-party user identity to a verification server. The method may include receiving a result of verification of the signed third-party user identity from the verification server, wherein the result can be successful or unsuccessful. The method may include transmitting an INVITE that includes a verified third-party user identity to a receiver UE, based on successful verification of the signed third-party user identity.
[0010] In an embodiment, a method performed by a Home Subscriber Server (HSS) for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided. The method may include receiving a third-party user identity usage parameter, the third-party user identity from a third-party apparatus, wherein the third-party is at least one of a trusted application function or untrusted application function. The method may include storing the third-party user identity usage parameter, the third-party user identity received from the third-party apparatus.
[0011] In an embodiment, an originating IMS network apparatus for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided. The originating IMS network apparatus may include a processor and an IMS session controller communicatively coupled with the processor. The IMS session controller may receive an INVITE from a User Equipment (UE). The IMS session controller may obtain a subscription information of the UE from a Home Subscriber Server (HSS). The IMS session controller may identify whether the UE is authorized to use the third-party user identity based on the subscription information. The IMS session controller may obtain the third-party user identity from the HSS, based on identifying that the UE is authorized to use the third-party user identity. The IMS session controller may transmit the INVITE that includes a signed third-party user identity to a terminating IMS network apparatus.
[0012] In an embodiment, a terminating IMS network apparatus for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided. The terminating IMS network apparatus may include a processor and an IMS session controller communicatively coupled with the processor. The IMS session controller may receive an INVITE that includes a signed third-party user identity from an originating IMS network apparatus. The IMS session controller may transmit the INVITE that includes the signed third-party user identity to a verification server. The IMS session controller may receive a result of verification of the signed third-party user identity from the verification server, wherein the result can be successful or unsuccessful. The IMS session controller may transmit an INVITE that includes a verified third-party user identity to a receiver UE, based on successful verification of the signed third-party user identity information.
[0013] In an embodiment, a Home Subscriber Server (HSS) for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided. The HSS may include a processor and an IMS session controller communicatively coupled with the processor. The IMS session controller may receive a third-party user identity usage parameter, the third-party user identity from a third-party apparatus, wherein the third-party is at least one of a trusted application function or untrusted application function. The IMS session controller may store the third-party user identity usage parameter, the third-party user identity received from the third-party apparatus.
[0014] These and other aspects of the embodiments herein will be better appreciated and understood when considered in conjunction with the following description and the accompanying drawings. It should be understood, however, that the following descriptions, while indicating preferred embodiments and numerous specific details thereof, are given by way of illustration and not of limitation. Many changes and modifications can be made within the scope of the embodiments herein.
[0015] These and other features, aspects, and advantages of the present embodiments are illustrated in the accompanying drawings, throughout which like reference letters indicate corresponding parts in the various figures. The embodiments herein will be better understood from the following description with reference to the drawings, in which:
[0016] Fig. 1 is a block diagram of an IMS originating network apparatus for authorization and authentication of a third-party user identity in an IMS session according to an embodiment of the disclosure.
[0017] Fig. 2 is a block diagram of an IMS terminating network apparatus for authorization and authentication of a third-party user identity in an IMS session according to an embodiment of the disclosure.
[0018] Fig. 3 is a flow diagram that illustrates a method of authorization and authentication of a third-party user identity in an IMS session by an IMS originating network apparatus according to an embodiment of the disclosure.
[0019] Fig. 4 is a flow diagram that illustrates a method of authorization and authentication of a third-party user identity in an IMS session by an IMS terminating network apparatus according to an embodiment of the disclosure.
[0020] Fig. 5A is a block diagram of HSS for authorization and authentication of a third-party user identity in an IMS session by HSS according to an embodiment of the disclosure.
[0021] Fig. 5B is a flow diagram that illustrates a method of authorization and authentication of a third-party user identity in an IMS session by HSS according to an embodiment of the disclosure.
[0022] Fig. 6 is a sequence diagram that illustrates a process of authorization and authentication of a third-party user identity in an IMS session according to an embodiment of the disclosure.
[0023] Fig. 7 is a sequence diagram that illustrates a process of signing and verification of third-party user identity information in the IMS according to an embodiment of the disclosure.
[0024] Fig. 8 is a sequence diagram that illustrates a process of provisioning IMS user-specific properties according to an embodiment of the disclosure.
[0025] It may be noted that, to the extent possible, like reference numerals have been used to represent like elements in the drawing. Furthermore, those of ordinary skill in the art will appreciate that elements in the drawing are illustrated for simplicity and may not necessarily have been drawn to scale. For example, the dimensions of some of the elements in the drawing may be exaggerated relative to other elements to improve the understanding of aspects of the disclosure. Further, the elements may have been represented in the drawing by conventional symbols, and the drawings may show only those specific details that are pertinent to understanding the embodiments of the disclosure so as not to obscure the drawing with details that will be readily apparent to those of ordinary skill in the art having the benefit of the description herein.
[0026] As is traditional in the field, embodiments are described and illustrated in terms of blocks that carry out a described function or functions. These blocks, which are referred to herein as managers, units, modules, hardware components, or the like, are physically implemented by analog and / or digital circuits such as logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive electronic components, active electronic components, optical components, hardwired circuits, and the like, and may optionally be driven by firmware and software. The circuits, for example, may be embodied in one or more semiconductor chips or on substrate supports such as printed circuit boards and the like. The circuits constituting a block may be implemented by dedicated hardware or by a processor (e.g., one or more programmed microprocessors and associated circuitry) or by a combination of dedicated hardware to perform some functions of the block and a processor to perform other functions of the block. Each block of the embodiments may be physically separated into two or more interacting and discrete blocks without departing from the scope of the proposed method. Likewise, the blocks of the embodiments may be physically combined into more complex blocks without departing from the scope of the proposed method.
[0027] The accompanying drawings are used to help easily understand various technical features, and it is understood that the embodiments presented herein are not limited by the accompanying drawings. As such, the proposed method is construed to extend to any alterations, equivalents, and substitutes in addition to those which are particularly set out in the accompanying drawings. Although the terms "first," "second," etc. are used herein to describe various elements, these elements are not limited by these terms. These terms are generally used to distinguish one element from another.
[0028] The evolution of communication technologies has significantly transformed the way businesses operate, with Multimedia Telephony (MMTEL) services playing a pivotal role in this transformation. MMTEL services extend beyond traditional voice calls, encompassing a wide range of functionalities such as online meetings, messaging, and advanced applications like Augmented Reality (AR) and Virtual Reality (VR) calls. These services have become integral to various business functions, including internal communications, sales interactions, customer support, and contact center operations. Despite the apparent benefits, businesses face several challenges when leveraging MMTEL services.
[0029] One of the primary challenges involves managing internal communications. Organizations utilize MMTEL for voice calls, online meetings, and collaborative features like screen sharing and messaging. However, the administration of individual employee subscriptions can be cumbersome, particularly in dynamic business environments where employees frequently join, leave, or relocate internationally. This complexity can lead to inefficiencies and increased operational costs, especially in large organizations with a global presence.
[0030] Another significant issue arises in communications with current and potential customers. While MMTEL services provide features before, during, and after calls, businesses often encounter problems with call authenticity. A concern is the rejection of legitimate business calls as fraudulent or robocalls. This not disrupts communication and affects customer relations and business reputations.
[0031] Addressing these challenges involves enhancing the authentication and authorization processes within the IP Multimedia Subsystem (IMS) architecture. The 3rd Generation Partnership Project (3GPP), in its Release 19, is investigating the authentication and authorization of third-party user identities in IMS sessions. This includes developing mechanisms for the serving IMS network to authorize third-party user identities and enabling the terminating IMS network to verify such identities. Enhancements are also being studied for IMS procedures related to authentication, authorization, signing, and verification of third-party user identities, including potential impacts on existing standards like STIR / SHAKEN.
[0032] Furthermore, there is a need to enhance IMS subscription data to support third-party user identities across multiple use cases, such as verifying identities in Originating Identification Presentation (OIP) services and using identities in IMS Avatar communications. These enhancements are used for ensuring secure and reliable communication, necessitating coordination with security working groups to address associated security aspects comprehensively. Theretofore, while MMTEL services offer substantial advantages for business communications, they also present several challenges that need to be addressed to ensure efficient, secure, and reliable use of these services.
[0033] Thus, it is desired to address the above-mentioned disadvantages, issues, or other shortcomings, or at least provide a useful alternative.
[0034] The principal object of the embodiments herein relates to the IMS framework to support authorization and authentication of third-party user identities in IMS sessions.
[0035] The object of the disclosure may be to authorize and authenticate the calling party when the IMS network uses third-party specific identities.
[0036] The object of the disclosure may be to ensure a called party receives the call from an intended user.
[0037] The object of the disclosure may be to provision third-party information to HSS by AF.
[0038] The object of the disclosure may be to sign by the signing server at the originating side and verify by the verification server at the terminating side for third-party user identities.
[0039] The present disclosure proposes solution for IMS network to authorize the user when user uses third party identity in the IMS session. The following are the main principles of the solution.
[0040] Authentication and Authorization of third party identity in each session irrespective of it is needed or not will add delay to the call setup time. Hence, IMS network shall selectively identify the session during which this third party identity authentication and authorization is needed.
[0041] It is proposed that the third party which provides third party identity to its users to use during IMS session will provide this information to operator and operator will have this information in the subscription profile.
[0042] The subscription profile in the Home Subscriber Server (HSS) for the subscriber / user (e.g., IP Multimedia Public Identity (IMPU)) will have one parameter which will indicate whether the authentication and authorization of third party identity is needed. In addition, subscription profile will contain the third party identities, which will be used by the user (IMPU). When the third party identities are common / same for all the users, then the third party may create a group with the list of the third party users / IMPUs along with the third party identity and provide it to HSS through Network Exposure Function (NEF).
[0043] During IMS session when originating Serving Call Session Control Function (S-CSCF) receives the INVITE from User Equipment (UE), it shall check the subscription information. When the parameter indicates that, the third party identity authentication and authorization is needed then the S-CSCF will proceed.
[0044] The third party identity information may be retrieved from the PAI / from header or some Call-Info header (some other SIP header using which UE has sent the third party identity) by S-CSCF and then compared against the stored third party identities from the subscription profile.
[0045] Upon a successful match, S-CSCF will invoke the Signing server (STI-AS). This Signing server address network get it from subscription information.
[0046] Then Signing server after receiving the INVITE from IMS originating network / S-CSCF, will add identity header and sign it as per the TS 24.229.
[0047] Then IMS terminating network / S-CSCF will invoke verification server based on the presence of identity header. Verification server address is configured at S-CSCFs / IBCFs.
[0048] Then Verification server will provide the validation status as per TS 24.229.
[0049] Referring now to the drawings, and more particularly to Fig. 1 through Fig. 8 where similar reference characters denote corresponding features consistently throughout the figures, there are shown preferred embodiments.
[0050] Fig. 1 is a block diagram of IMS originating network apparatus for authorization and authentication of a third-party user identity in an IMS session, according to an embodiment of the disclosure. The IMS originating network apparatus (101) may include a processor (103), memory (105), an I / O interface (107), and an IMS session controller (109). The IMS originating network apparatus (101) can include network entities such as Originating Serving-Call Session Control Function (O-S-CSCF) and Secure Telephone Identity - Authentication Server (STI-AS). Furthermore, the processor (103) of the IMS originating network apparatus (101) may communicate with the memory (105), the I / O interface (107), and the IMS session controller (109). The processor (103) may be configured to execute instructions stored in the memory (105) and to perform various processes. The processor (103) can include one or a plurality of processors, can be a general-purpose processor such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0051] Furthermore, the memory (105) of the IMS originating network apparatus (101) may include storage locations that can be addressed through the processor (103). The memory (105) is not limited to volatile or non-volatile memory and can include one or more computer-readable storage media. Non-volatile storage elements such as magnetic hard disks, optical discs, floppy discs, flash memories, EPROM, or EEPROM memories can also be included in the memory (105). Further, the memory (105) of the IMS originating network apparatus (101) can store various information received from UE and IMS terminating network apparatus (201). The IMS originating network apparatus (101) can store several pieces of information such as subscription information received from HSS, RCD (Rich Call Data) information and the like.
[0052] The I / O interface (107) may transmit information between the memory (105) and external peripheral devices, which are input-output devices associated with the IMS originating network apparatus (101). The I / O interface (107) may receive various information from the UE, HSS and IMS terminating network apparatus (201). This interface may be used to maintain seamless communication between the IMS originating network apparatus (101) and external devices, ensuring that data is transmitted and received. Additionally, the I / O interface (107) may facilitate the integration of the IMS originating network apparatus (101) with other network components, enhancing its capability to authorize and authenticate third-party user identity in IMS session.
[0053] The IMS session controller (109) may communicate with the I / O interface (107) and the memory (105) for authorization and authentication of a third-party user identity in IMS session. The IMS session controller (109) may be an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0054] Upon receiving a call setup message from the User Equipment (UE), the IMS session controller (109) may initiate a series of authentication and authorization procedures to ensure secure and legitimate use of network resources. Further, the IMS session controller (109) may retrieve the subscription information of the UE from the HSS. The HSS may serve as a central database that stores user profiles, subscription details, and authentication credentials, enabling the IMS session controller (109) to verify the identity and service entitlements of the UE.
[0055] Once the subscription information is obtained, the IMS session controller (109) may determine whether the UE is authorized to use the third-party user identity information based on the subscription information. This determination may be performed for maintaining the integrity and security of the network, as unauthorized use of third-party user identities could lead to fraudulent activities or breaches of privacy. The authorization decision may be based on the subscription information retrieved from the HSS, which outlines the specific permissions and restrictions associated with the UE's account. Further, the IMS session controller (109) may retrieve the third-party user identity information from the HSS, when the UE is successfully authorized to use the third-party user identity information, ensuring that the UE can legitimately represent or interact with the third-party during the session.
[0056] In cases, where the UE is not successfully authorized to use the third-party user identity information, the IMS session controller (109) may reject the call setup message received from the UE. This rejection may serve as a protective measure, preventing unauthorized access and potential misuse of network resources. Further, if authorization is granted, the IMS session controller (109) may construct and transmit an INVITE message to the IMS terminating network apparatus (201). This INVITE message may include signed third-party information, thereby validating the UE's authority to engage in the session using the specified identity. By incorporating signed third-party information, the IMS session controller (109) may ensure that the communication session adheres to security protocols and maintains the trustworthiness of the IMS environment.
[0057] In an embodiment, the IMS originating network apparatus (101) can be, but is not limited to, a S-CSCF or IMS Application Server (AS). The S-CSCF may act as the central node in the signaling plane. It may be responsible for session control and management, ensuring that multimedia sessions are established, maintained, and terminated efficiently. The S-CSCF may interact with various other components within the IMS, such as the Home Subscriber Server (HSS) for retrieving user profiles and the Media Resource Function (MRF) for managing media-related tasks. By serving as the originating network apparatus, the S-CSCF may ensure seamless initiation and control of multimedia sessions, providing users with reliable and high-quality communication services.
[0058] Further, the IMS AS may extend the capabilities of the IMS by hosting and executing value-added services and applications. It may be a versatile component that can support a wide range of services, from basic call handling to complex multimedia applications. The IMS AS can be customized to meet specific service requirements, enabling service providers to offer innovative and differentiated services to their customers. By acting as the originating network apparatus, the IMS AS can initiate service-specific logic and processes, ensuring that users receive tailored and context-aware communication experiences. This flexibility may allow service providers to quickly adapt to changing market demands and introduce new services without significant infrastructure changes.
[0059] In addition to the S-CSCF and IMS AS, the IMS originating network apparatus (101) may also encompass other components or configurations, depending on the specific requirements of the network and services being offered. For instance, it could include elements like the Proxy Call Session Control Function (P-CSCF) or the Interrogating Call Session Control Function (I-CSCF), which play supportive roles in the IMS architecture. The P-CSCF may act as the first point of contact for users within the IMS, handling initial signaling and security functions, while the I-CSCF may assist in routing and session initiation processes. By incorporating these components, the IMS originating network apparatus can provide a comprehensive and robust framework for managing multimedia communications, ensuring that users experience seamless connectivity and access to a wide array of services.
[0060] In an embodiment, the IMS session controller (109) may determine whether the UE is authorized to use the third-party user identity information by checking the third-party user identity information usage parameter in the subscription information for the UE. When the third-party user identity information usage parameter is enabled, the IMS session controller (109) may conclude that the UE is authorized to use the third-party user identity information. Further, when the third-party user identity information usage parameter is disabled, the IMS session controller (109) may determine that the UE is unauthorized to use the third-party user identity information.
[0061] The third-party user identity information may ensure the integrity and authenticity of communication within the IMS framework. By verifying the authorization status of the UE, the IMS session controller (109) may uphold the security protocols that protect sensitive identity information from unauthorized access or misuse. This verification process may safeguard the identity of the third-party and enhance the trustworthiness of the communication network by ensuring that the authorized entities can represent third-party user identities. The IMS session controller (109) may act as a gatekeeper, checking the subscription information to ensure compliance with the established security standards.
[0062] In an embodiment, the third-party information can include, but is not limited to, caller name, organization information, title information, and email information per IMPU or per group of IMPUs. This information may provide comprehensive profile that can be used to authenticate the UE's claim to a third-party user identity. By incorporating a wide range of identity attributes, the IMS session controller (109) can perform a more thorough verification, reducing the risk of identity spoofing or other fraudulent activities. This multi-faceted approach to identity verification may ensure that the communication network remains robust and secure, even as it accommodates a diverse array of identity information.
[0063] In an embodiment, to transmit the INVITE message that includes the signed third-party information to the IMS terminating network apparatus (201), the IMS session controller (109) may transmit the INVITE message to the signing server to sign the third-party user identity information. Further, the IMS session controller (109) may receive the signed third-party information from the signing server. Once the third-party user identity information is signed, it may provide a cryptographic assurance of its authenticity, allowing the IMS session controller (109) to confidently forward the INVITE message to the IMS terminating network apparatus (201). By leveraging cryptographic techniques, the IMS session controller (109) may ensure that the third-party user identity information remains tamper-proof and verifiable, thus maintaining the overall security and reliability of the IMS communication system.
[0064] Fig. 2 is a block diagram of IMS terminating network apparatus for authorization and authentication of third-party user identity in IMS session, according to an embodiment of the disclosure.
[0065] The IMS terminating network apparatus (201) may include a processor (203), memory (205), an I / O interface (207), and an IMS session controller (209). The IMS terminating network apparatus (201) can be, but not limited to S-CSCF and IMS AS. Furthermore, the processor (203) of the IMS terminating network apparatus (201) may communicate with the memory (205), the I / O interface (207), and the IMS session controller (209). The processor (203) may be configured to execute instructions stored in the memory (205) and to perform various processes. The processor (203) can include one or a plurality of processors, can be a general-purpose processor such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0066] Furthermore, the memory (205) of the IMS terminating network apparatus (201) may include storage locations that can be addressed through the processor (203). The memory (205) is not limited to volatile or non-volatile memory and can include one or more computer-readable storage media. Non-volatile storage elements such as magnetic hard disks, optical discs, floppy discs, flash memories, EPROM, or EEPROM memories can also be included in the memory (205). Further, the memory (205) of the IMS terminating network apparatus (201) can store various information received from the IMS originating network apparatus (101). The IMS terminating network apparatus (201) can store several information such as signed RCD information, RCD URL (Universal Resource Locator) in the INVITE message and the like.
[0067] The I / O interface (207) may transmit information between the memory (205) and external peripheral devices, which are input-output devices associated with the IMS terminating network apparatus (201). The I / O interface (207) may receive various information from the UE. This interface may be used to maintain seamless communication between the IMS terminating network apparatus (201) and external devices, ensuring that data is transmitted and received. Additionally, the I / O interface (207) may facilitate the integration of the IMS terminating network apparatus (201) with other network components, enhancing its capability to authorize and authenticate third-party user identity in IMS session.
[0068] The IMS session controller (209) may communicate with the I / O interface (207) and the memory (205), for authorizing and authenticating third-party user identity in IMS session. The IMS session controller (209) may be an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0069] The IMS session controller (209) may receive the INVITE message that includes the signed third-party user identity information from the IMS originating network apparatus (101). This INVITE message may be typically formatted according to the Session Initiation Protocol (SIP) standards, ensuring compatibility across various network components. The signed third-party user identity information may be encapsulated within a secure token, which may utilize cryptographic algorithms such as RSA or ECC to ensure its integrity and authenticity. Further, the IMS session controller (209) may transmit the verification request message that includes the signed third-party user identity information to the verification server. The verification server may be equipped with a public key infrastructure (PKI) that allows it to decrypt and authenticate the signature, ensuring that the identity information has not been tampered with during transmission.
[0070] Further, the IMS session controller (209) may receive the result of verification of the signed third-party user identity information from the verification server. The result can be successful or unsuccessful, depending on whether the signature matches the expected cryptographic parameters. Further, the IMS session controller (209) may transmit the INVITE message that includes a verified third-party user identity information to the receiver UE upon successful verification of the signed third-party user identity information. This transmission may involve additional security measures, such as Transport Layer Security (TLS), to protect the data in transit.
[0071] Further, the IMS session controller (209) may reject the INVITE message request by providing appropriate response with reject cause to the IMS originating network apparatus (101) upon unsuccessful verification of the signed third-party user identity information. The reject cause may be selected from a predefined set of SIP response codes, which may include codes such as 403 (Forbidden) or 488 (Not Acceptable Here), providing clear feedback to the IMS originating network apparatus (101).
[0072] Fig. 3 is a flow diagram that illustrates a method for authorization and authentication of third-party user identity in an IMS session by IMS originating network apparatus, according to an embodiment of the disclosure.
[0073] At block 301, the method may include receiving the call setup message from the UE during the IMS session. The call setup message may include initial signaling information required to establish a session, such as the UE's identity and requested service parameters. The IMS originating network apparatus (101) may process this message to initiate the authentication sequence, ensuring that the UE's request aligns with network policies and security protocols.
[0074] At block 303, the method may include retrieving the subscription information of the UE from the HSS. By accessing the HSS, the IMS originating network apparatus (101) can verify the UE's subscription status and determine the applicable service conditions.
[0075] At block 305, the method may include determining whether the UE is authorized to use the third-party user identity information based on the subscription information. For example, the IMS originating network apparatus (101) may determine whether the third-party user identity information usage parameter is enabled or disabled in the subscription information. This may involve checking specific flags or attributes within the subscription profile that indicate the UE's permissions regarding third-party user identity usage. The decision logic may also consider additional factors such as the UE's current service context or any applicable regulatory requirements.
[0076] At block 307, the method may include retrieving the third-party user identity information from the HSS when the UE is successfully authorized to use the third-party user identity information. The UE may be successfully authorized when the third-party user identity information usage parameter is enabled in the subscription information. However, when the third-party user identity information usage parameter is disabled, then the UE may be said to be unsuccessfully authorized, and the call request message received from the UE may be rejected. In cases of successful authorization, the retrieved third-party user identity information may be securely stored and prepared for inclusion in subsequent signaling messages. This may ensure that the identity information is protected against unauthorized access or tampering during transmission.
[0077] At block 309, the method may include transmitting the INVITE message that includes signed third-party user identity information to the IMS terminating network apparatus (201). The signing process may involve applying a digital signature to the third-party user identity information, which provides a cryptographic guarantee of its authenticity and integrity. The IMS terminating network apparatus can then verify the signature to confirm that the identity information has not been altered and is indeed authorized for use by the originating UE.
[0078] Fig 4 is a flow diagram that illustrates a method of authorization and authentication of third-party user identity in an IMS session by IMS terminating network apparatus according to an embodiment of the disclosure.
[0079] At block 401, the method may include receiving the INVITE message that includes a signed third-party user identity information from the IMS originating network apparatus (101). The signed third-party user identity information may be typically encapsulated within a SIP header, such as the P-Asserted-Identity or From header, and may be digitally signed using a private key associated with the third-party user identity provider. This may ensure the integrity and authenticity of the identity information as it traverses the network. The IMS originating network apparatus may also include additional metadata, such as a timestamp or nonce, to prevent replay attacks.
[0080] At block 403, the method may include transmitting the verification request message that includes the signed third-party user identity information to the verification server to verify the signed third-party user identity information. The verification server, often referred to as Secure Telephone Identity-Verification Service (STI-VS), may utilize a PKI to validate the digital signature. It may check the signature against a trusted certificate authority (CA) to ensure that the identity information has not been tampered with. The verification process may also involve checking the certificate revocation status to ensure that the signing certificate is still valid.
[0081] At block 405, the method may include receiving the result of verification of the signed third-party user identity information from the verification server. The result can be successful or unsuccessful. A successful verification may indicate that the signature is valid and the identity information is authentic, while an unsuccessful verification may trigger additional security measures, such as logging the event for further analysis. The verification server may also provide additional information, such as the identity of the certificate authority that issued the signing certificate, to aid in the decision-making process.
[0082] At block 407, the method may include transmitting the INVITE message that includes the verified third-party user identity information to the receiver UE upon successful verification of the signed third-party user identity information. The IMS terminating network apparatus (201) may also include additional headers or parameters in the INVITE message to indicate the successful verification to the receiving UE. This may ensure that the receiving UE can trust the identity information and proceed with the session establishment. The transmission may also involve updating session state information to reflect the successful verification.
[0083] At block 409, the method may include rejecting the INVITE message request by providing an appropriate response with a reject cause code to the IMS originating network apparatus (101) upon unsuccessful verification of the signed third-party user identity information. The reject cause code may be typically a SIP response code, such as 403 Forbidden, which indicates that the request is not authorized. The IMS terminating network apparatus may also include additional diagnostic information in the response to aid in troubleshooting and resolution. This rejection process may help maintain the security and integrity of the IMS network by preventing unauthorized access.
[0084] Fig. 5A is the block diagram of the HSS for the authorization and authentication of third-party user identity in IMS session by the HSS according to an embodiment of the disclosure.
[0085] The HSS (501) may include a processor (503), memory (505), an I / O interface (507), and an IMS session controller (509). Furthermore, the processor (503) of the HSS (501) may communicate with the memory (505), the I / O interface (507), and the IMS session controller (509). The processor (503) may be configured to execute instructions stored in the memory (505) and to perform various processes. The processor (503) can include one or a plurality of processors, can be a general-purpose processor such as a central processing unit (CPU), an application processor (AP), or the like, a graphics-only processing unit such as a graphics processing unit (GPU), a visual processing unit (VPU), and / or an Artificial Intelligence (AI) dedicated processor such as a neural processing unit (NPU).
[0086] Furthermore, the memory (505) of the HSS (501) may include storage locations that can be addressed through the processor (503). The memory (505) is not limited to volatile or non-volatile memory and can include one or more computer-readable storage media. Non-volatile storage elements such as magnetic hard disks, optical discs, floppy discs, flash memories, EPROM, or EEPROM memories can also be included in the memory (505). Further, the memory (505) of the HSS (501) can store various information received from the third-party. The various information can include the third-party user identity information and third-party user identity information usage parameter.
[0087] The I / O interface (507) may transmit information between the memory (505) and external peripheral devices, which are input-output devices associated with the HSS (501). The I / O interface (507) may receive various information from the third-party apparatus.
[0088] The IMS session controller (509) may communicate with the I / O interface (507) and the memory (505), for authorizing and authenticating third-party user identity in IMS session. The IMS session controller (509) may be an innovative hardware that is realized through the physical implementation of both analog and digital circuits, including logic gates, integrated circuits, microprocessors, microcontrollers, memory circuits, passive and active electronic components, as well as optical components.
[0089] The IMS session controller (509) may receive by a HSS (501) the third-party user identity information from the third-party apparatus (613). The third-party may be at least one of a trusted application function or untrusted application function. Further, the IMS session controller (509) may store third-party user identity information usage parameter, the third-party user identity information received from the third-party apparatus (613). Further, the IMS session controller (509) may receive third-party user identity information usage parameter, the third-party user identity information through Network Exposure Function (NEF) (803), when the third-party apparatus (613) is the untrusted application function. Further, the IMS session controller (509) may receive third-party user identity information usage parameter, the third-party user identity information directly from the third-party apparatus (613), when the third-party is the trusted application function.
[0090] Fig. 5B is a flow diagram that illustrates a method of authorization and authentication of third-party user identity in IMS session by the HSS according to an embodiment of the disclosure.
[0091] At block 511, the method may include receiving the third-party user identity information usage parameter and third-party user identity information from the third-party apparatus (613). The third-party can be, but is not limited to, the trusted application function or untrusted application function. The usage parameter may specify conditions or constraints under which the third-party user identity can be used, such as time-of-day restrictions or specific service types. This information may ensure that the third-party user identity is used in compliance with policy and regulatory requirements.
[0092] At block 513, the method may include storing the third-party user identity information usage parameter and the third-party user identity information received from the third-party apparatus (613). The HSS (Home Subscriber Server) (501) may maintain this information in a secure database, ensuring that it is accessible for future authorization checks. The storage process may involve encrypting the data to protect it from unauthorized access and ensuring that it is replicated across multiple nodes for redundancy and reliability.
[0093] In an embodiment, when the third-party apparatus (613) is the untrusted application function, then the HSS (501) may receive the third-party user identity information usage parameter and the third-party user identity information through the NEF (803). The NEF (803) may act as a secure gateway, providing a controlled interface for untrusted applications to interact with the HSS (501). It may also perform additional validation checks to ensure that the information being provided is legitimate and conforms to expected formats.
[0094] Also, when the third-party apparatus (613) is the trusted application function, then the HSS (501) may receive the third-party user identity information usage parameter and the third-party user identity information through the trusted application function. The trusted application function may have a direct interface with the HSS (501), allowing for more efficient and streamlined communication. This setup may ensure that trusted applications can quickly and securely update identity information as needed.
[0095] Fig 6 is a sequence diagram that illustrates a process of authorization and authentication of third-party user identity in IMS session according to an embodiment of the disclosure.
[0096] At step S1, the third-party apparatus (613) may provision the list of IMPUs along with the third-party user identity to the HSS (501), which is common for all the IMPUs. When the IMPUs use unique third-party identities, which is different for each IMPU, then this information will be shared by the third-party apparatus (613) to the operator. Further, the operator will provision in the subscription profile for each IMPU in the HSS (501). The provisioning process may involve the use of secure APIs or interfaces to ensure that the data is transmitted and stored securely. The operator may also perform additional checks to verify the accuracy and completeness of the information being provisioned.
[0097] At step S2, consider the UE1 (601) may be already registered with O-S-CSCF (101) (The O-S-CSCF is interchangeably used as the IMS originating network apparatus). The registration process may involve the UE1 (601) authenticating itself with the IMS network, typically using credentials such as a username and password or a SIM-based authentication mechanism. Once registered, the UE1 (601) may be assigned a unique session identifier that is used for tracking and managing its interactions with the network.
[0098] At step S3, the UE1 (601) may initiate an IMS session with the O-S-CSCF (101) in the call request message by sending INVITE with UE2 (615) for making a call. The INVITE message may include various headers and parameters that specify the details of the call, such as the codec to be used, the quality of service, and any additional features or services requested. The O-S-CSCF may process this information to determine the appropriate routing and handling of the call request.
[0099] At step S4, the O-S-CSCF (101) may download the subscription information of the IMPU from HSS (501). This information may include details such as the user's service entitlements, any applicable usage restrictions, and the current status of the user's subscription. The O-S-CSCF (101) may use this information to ensure that the call request is in compliance with the user's subscription terms and conditions.
[0100] At step S5, the O-S-CSCF (101) may check the subscription information to determine whether the user associated with UE1 (601) is authorized to use the third-party user identity service. For example, the O-S-CSCF (101) may check the subscription information to verify the third-party identity usage. When the third-party user identity information usage parameter is enabled, the O-S-CSCF (101) may extract the third-party user identity information from the PAI / From / Call-Info header and validate it against the stored third-party identities for the IMPUs in the subscription profile.
[0101] At step S6, upon a successful match, the O-S-CSCF (101) may invoke the signing server (STI-AS) (605). The O-S-CSCF (101) can retrieve the signing server address from the subscription information. The signing server may be responsible for generating a digital signature for the third-party user identity information, ensuring its integrity and authenticity as it is transmitted through the network.
[0102] At step S7, the signing server (605), after receiving the INVITE from the IMS originating network apparatus / O-S-CSCF (101), may add an identity header and sign it as per the TS 24.229. The identity header may include the signed third-party user identity information, along with any additional metadata required for verification. The signing server (605) may also include a timestamp or other information to prevent replay attacks and ensure the freshness of the signature. The signing server (605) may give the INVITE back to the O-S-CSCF (101).
[0103] At step S8, the O-S-CSCF (101) may forward the INVITE to the IMS terminating network apparatus / T-S-CSCF (201) (hereinafter the T-S-CSCF is interchangeably used). The forwarding process may involve routing the INVITE message through the IMS network, ensuring that it reaches the correct terminating network apparatus. The O-S-CSCF (101) may also perform additional checks to ensure that the INVITE message is complete and correctly formatted before forwarding it.
[0104] At step S9, the T-S-CSCF (201) at the terminating side will invoke the verification server / STI-VS (609) based on the presence of the Identity header and forward the INVITE request to the STI-VS (609). The verification server may be responsible for validating the digital signature on the identity header, ensuring that the third-party user identity information is authentic and has not been tampered with. The verification process may involve checking the signature against a trusted certificate authority and verifying the certificate's revocation status.
[0105] At step S10, the verification server (609) will verify the Identity header using certificates and provide the validity status along with the INVITE to the T-S-CSCF (201). The validity status may indicate whether the signature is valid and the identity information is authentic. The verification server (609) may also provide additional information, such as the identity of the certificate authority that issued the signing certificate, to aid in the decision-making process.
[0106] At step S11, the T-S-CSCF (201) at the terminating side may send the INVITE towards UE2 (615) based on the successful validation result. Also, the T-S-CSCF (201) can reject the call for the unsuccessful result received from the verification server (609). The T-S-CSCF (201) may include additional headers or parameters in the INVITE message to indicate the successful validation to the receiving UE (615). This may ensure that the receiving UE (615) can trust the identity information and proceed with the session establishment.
[0107] At step S12, a successful call may happen between the UE1 (601) and the UE2 (615). The call setup process may involve establishing a media path between the two UEs, negotiating the codec and quality of service parameters, and exchanging any additional information required for the call. The IMS network may ensure that the call is routed efficiently and securely, providing a high-quality communication experience for the users.
[0108] Fig. 7 is a sequence diagram that illustrates a process of signing and verification of third-party user identity information in IMS, according to an embodiment of the disclosure.
[0109] At step A1, the UE1 (601) may send a SIP INVITE message to IMS originating network apparatus (101) to initiate a call with UE2 (615).
[0110] At step A2, the IMS originating network apparatus (101) may determine whether the UE1 (601) is authorized to use the third-party user identity information based on the subscription information. The subscription information can be downloaded by the IMS originating network apparatus (101) from the HSS (501). The subscription information can include the third-party user identity information usage parameter that indicates whether the UE1 (601) is authorized or not authorized to use the third-party user identity information. Particularly when the third-party user identity information usage parameter is enabled or set to 1, then the UE1 (601) may be authorized. However, when the third-party user identity information usage parameter is disabled or set to 0, then the UE1 (601) may be unauthorized to use the third-party user identity information.
[0111] At step A3, upon successful authorization, the IMS originating network apparatus (101) may retrieve RCD information, RCD URL, or RCD server address from the HSS (501).
[0112] At step A4, the IMS originating network apparatus (101) may receive the RCD information (hereinafter RCD information is interchangeably used as third-party user identity information), RCD URL, or the RCD server address.
[0113] At step A5, the IMS originating network apparatus (101) may retrieve the RCD information using RCD URL or RCD server address, originating IMPU, or wildcarded IMPU from the RCD server (701). The retrieval process may involve accessing external servers or databases where the RCD information is stored, using secure communication protocols to ensure data confidentiality. The use of IMPU or wildcarded IMPU may allow for flexible and efficient retrieval of RCD information, accommodating various user scenarios and network configurations.
[0114] At step A6, the IMS originating network apparatus (101) may request the AS for signing (605) of RCD information or RCD URL. The signing process may involve cryptographic operations that generate a digital signature, which serves as proof of authenticity and integrity for the RCD information.
[0115] At step A7, the IMS originating network apparatus (101) may receive the signed RCD information or the signed RCD URL. For example, the AS for signing (605) may return a PASSP (Personalized Authentication Secure Signature Protocol) or a T / Token (Trusted Token) to the IMS originating network apparatus (101). The signed data may be then stored securely within the network apparatus, ready to be included in subsequent communication messages. The receipt of the signed information may mark the completion of the signing process, allowing the network apparatus to proceed with sending the INVITE message to the IMS terminating network apparatus (201).
[0116] At step A8, the IMS originating network apparatus (101) may send a SIP INVITE message with signed RCD information or signed RCD URL to the IMS terminating network apparatus (201). The inclusion of the signed RCD information in the INVITE message may provide the terminating network with the data to verify the authenticity of the communication session.
[0117] At step A9, the IMS terminating network apparatus (201) may invoke a request with AS for verification (609) of the signed RCD information or the signed RCD URL. The verification process may involve checking the digital signature against the original RCD information, using cryptographic algorithms to confirm the integrity and authenticity of the data.
[0118] At step A10, the AS for verification (609) may send the results of the verification of the signed RCD information or the signed RCD URL to the IMS terminating network apparatus (201). The result or the status of the verification can be successful or unsuccessful. A successful verification may indicate that the RCD information is authentic and has not been tampered with, allowing the communication session to proceed. Further, an unsuccessful verification may trigger security measures, such as rejecting the session or alerting network administrators.
[0119] At Step A11, the IMS terminating network apparatus (201) may send the SIP INVITE message to the UE2 (615) with the verified RCD information or RCD URL when the status of the verification is successful. The inclusion of verified RCD information in the INVITE message may provide the UE2 (615) with the data to establish a secure and trusted communication session.
[0120] At step A12, the UE2 (615) may retrieve the RCD information using the RCD URL from the RCD server (701). The retrieval process may involve accessing the RCD server (701) using secure communication protocols, ensuring the confidentiality and integrity of the data. The RCD information may provide the UE2 (615) with enhanced communication capabilities, such as caller identification and multimedia content sharing, improving the overall user experience.
[0121] Fig. 8 is a sequence diagram that illustrates process of provisioning an IMS user specific properties, according to an embodiment of the disclosure.
[0122] At step B1, the AF (Application Function) (805) may provision the third-party user identity information for an IMS user to the NEF (803), e.g., when the AF (805) is the untrusted AF (805). The provisioning process may involve securely transmitting the third-party user identity information from the AF (805) to the NEF (803), using encryption and authentication mechanisms to ensure data confidentiality and integrity. The NEF (803) may act as an intermediary, facilitating the secure exchange of information between the AF (805) and other network entities.
[0123] At step B2, the NEF (803) may forward the third-party user identity information for the IMS user to IMS AS (801). The forwarding process may involve securely transmitting the information from the NEF (803) to the IMS AS (801), using secure communication protocols to ensure data confidentiality and integrity. The IMS AS (801) may be responsible for processing and validating the third-party user identity information.
[0124] At step B3, the IMS AS (801) may validate the third-party user identity information received from the NEF (803). The IMS AS (801) may also perform additional checks, such as verifying the authenticity of the information and ensuring that it has not been tampered with.
[0125] At step B4, the IMS AS (801) may store the third-party user identity information of the IMS user in the HSS (501) upon successful validation. The storage process may involve securely transmitting the information from the IMS AS (801) to the HSS (501), using encryption and authentication mechanisms to ensure data confidentiality and integrity. The HSS (501) may act as a central repository, storing the third-party user identity information along with other user-specific properties.
[0126] In an embodiment, the AF (805) can provision the third-party user identity information directly to the HSS (501). This direct provisioning process may involve securely transmitting the information from the AF (805) to the HSS (501), bypassing the NEF (803) and IMS AS (801).
[0127] In an embodiment, the AF (805) can provision the third-party user identity information directly to the HSS (501) through the NEF (803). This approach may involve securely transmitting the information from the AF (805) to the NEF (803), and then from the NEF (803) to the HSS (501). Hence the proposed solution provides an additional layer of security, as the NEF (803) can perform checks and validations before forwarding the information to the HSS (501).
[0128] In an embodiment, the objectives are achieved by providing a method for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) session. A third-party user in this context is a user belonging to a third-party network which can be e.g., an Enterprise or private network. The method may include receiving by an IMS originating network apparatus a call setup message from a UE during the IMS session. The method may include retrieving by the IMS originating network apparatus a subscription information of the UE from a Home Subscriber Server (HSS). The method may include determining by the IMS originating network apparatus whether the UE is authorized to use a third-party user identity information based on the subscription information. The method may include retrieving by the IMS originating network apparatus the third-party user identity information from the HSS based on determining that the UE is authorized to use the third-party user identity information. The method may include rejecting by the IMS originating network apparatus the call setup message received from the UE (601), based on determining that the UE (601) is not authorized to use the third-party user identity information. The method may include transmitting by the IMS originating network apparatus an INVITE message that includes a signed third-party information to an IMS terminating network apparatus.
[0129] In an embodiment, the method, wherein the IMS originating network apparatus may be at least one of a Serving-Call Session Control Function (S-CSCF) or IMS Application server (AS).
[0130] In an embodiment, the method, wherein determining whether the UE is authorized to use a third-party user identity information, may include determining, by the IMS originating network apparatus, whether a third-party user identity information usage parameter in the subscription information for the UE is enabled or disabled. The method, wherein determining whether the UE is authorized to use a third-party user identity information, may include determining, by the IMS originating network apparatus, that the UE is authorized to use the third-party user identity information when the third-party user identity information usage parameter is enabled. The method, wherein determining whether the UE is authorized to use a third-party user identity information, may include determining, by the IMS originating network apparatus, that the UE is unauthorized to use the third-party user identity information when the third-party user identity information usage is disabled.
[0131] In an embodiment, the method, wherein the third-party information may include at least one of a, caller name, organization information, title information, and an email information per IMPU or per group of IMPUs.
[0132] In an embodiment, the method, wherein transmitting the INVITE message that includes the signed third-party information to the IMS terminating network apparatus may include transmitting, by the IMS originating network apparatus, an INVITE message to a signing server to sign the third-party user identity information. The method, wherein transmitting the INVITE message that includes the signed third-party information to the IMS terminating network apparatus may include receiving, by the IMS originating network apparatus, a signed third-party information from the signing sever. The method, wherein transmitting the INVITE message that includes the signed third-party information to the IMS terminating network apparatus may include transmitting, by the IMS originating network apparatus, the INVITE message that includes the signed third-party information to the IMS terminating network apparatus.
[0133] In an embodiment, the objectives are achieved by providing a method for authorization and authentication of a third-party user identity in an IMS session. The method may include receiving by an IMS terminating network apparatus an INVITE message that includes a signed third-party user identity information from an IMS originating network apparatus. The method may include transmitting by the IMS terminating network apparatus a verification request message that includes the signed third-party user identity information to a verification server. The method may include receiving by the IMS terminating network apparatus a result of verification of the signed third-party user identity information from the verification server. The result can be successful or unsuccessful. The method may include transmitting an INVITE message that includes a verified third-party user identity information to a receiver UE upon successful verification of the signed third-party user identity information. The method may include rejecting the INVITE message request by providing an appropriate response with a reject cause code to the IMS originating network apparatus upon unsuccessful verification of the signed third-party user identity information.
[0134] In an embodiment, the method, wherein the IMS terminating network apparatus may be at least one of a S-CSCF or IMS AS.
[0135] In an embodiment, the objectives are achieved by providing a method for authorization and authentication of a third-party user identity in an IMS session. The method may include receiving by an HSS third-party user identity information usage parameter, a third-party user identity information from a third-party apparatus. The third-party user identity information usage parameter value may indicate whether the calling party is authorized to use third-party user identity during an IMS session. The third-party may be at least one of a trusted application function or untrusted application function. The method may include storing by the HSS third-party user identity information usage parameter, the third-party user identity information received from the third-party apparatus.
[0136] In an embodiment, the method, wherein receiving the third-party user identity information from the third-party apparatus may include receiving, by the HSS, third-party user identity information usage parameter, the third-party user identity information through NEF, when the third-party apparatus is the untrusted application function. The method, wherein receiving the third-party user identity information from the third-party apparatus may include receiving, by the HSS, third-party user identity information usage parameter, the third-party user identity information directly from the third-party apparatus, when the third-party is the trusted application function.
[0137] In an embodiment, the method may include receiving, by the HSS, third-party user identity information usage parameter and a third-party user identity information per IMPU or per group of IMPUs.
[0138] In an embodiment, the objectives are achieved by providing an IMS originating network apparatus for authorization and authentication of third-party user identities in an IP Multimedia Subsystem session. The IMS originating network apparatus may include a processor and an IMS session controller communicatively coupled to the processor. The IMS session controller may receive a call setup message from a UE during the IMS session. The IMS session controller may retrieve a subscription information of the UE from an HSS. The IMS session controller may determine whether the UE is authorized to use a third-party user identity information based on the subscription information. The IMS session controller may retrieve the third-party user identity information from the HSS when the UE is successfully authorized to use the third-party user identity information. The IMS session controller may transmit an INVITE message that includes a signed third-party information to an IMS terminating network apparatus.
[0139] In an embodiment, the objectives are achieved by providing an IMS terminating network apparatus for authorization and authentication of third-party identities in an IP Multimedia Subsystem session. The IMS terminating network apparatus may include a processor and an IMS session controller communicatively coupled to the processor. The IMS session controller may receive an INVITE message that includes a signed third-party user identity information from an IMS originating network apparatus. The IMS session controller may transmit a verification request message that includes the signed third-party user identity information to a verification server. The IMS session controller may receive a result of verification of the signed third-party user identity information from the verification server, wherein the result can be successful or unsuccessful. The IMS session controller may transmit an INVITE message that includes a verified third-party user identity information to a receiver UE upon successful verification of the signed third-party user identity information. The IMS session controller may reject the INVITE message request by providing an appropriate response with a reject cause code to the IMS originating network apparatus upon unsuccessful verification of the signed third-party user identity information.
[0140] In an embodiment, the objectives are achieved by providing an Home Subscriber Server (HSS) for authorization and authentication of third-party identities in an IP Multimedia Subsystem session. The HSS may include a processor and an IMS session controller communicatively coupled to the processor. The IMS session controller may receive third-party user identity information usage parameter, a third-party user identity information from a third-party apparatus, wherein the third-party is at least one of a trusted application function or untrusted application function. The IMS session controller may store third-party user identity information usage parameter, the third-party user identity information received from the third-party apparatus.
[0141] In an embodiment, a method performed by an originating IMS network for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided.
[0142] In an embodiment, the method, wherein the originating IMS network may include at least one of a Serving-Call Session Control Function (S-CSCF) or an IMS Application server (AS).
[0143] In an embodiment, the method, wherein identifying whether the UE is authorized to use the third-party user identity may include identifying whether a third-party user identity usage parameter in the subscription information for the UE is enabled. The method, wherein identifying whether the UE is authorized to use the third-party user identity may include determining that the UE is authorized to use the third-party user identity in case that the third-party user identity usage parameter is enabled.
[0144] In an embodiment, the method, wherein the third-party user identity may include at least one of a caller name, an email address, an organization information and a job title per IMPU or wildcarded IMPU.
[0145] In an embodiment, the method, wherein transmitting the INVITE that includes the signed third-party user identity to the terminating IMS network apparatus may include transmitting an INVITE to a signing server to sign the third-party user identity. The method, wherein transmitting the INVITE that includes the signed third-party user identity to the terminating IMS network apparatus may include receiving a signed third-party user identity from the signing sever. The method, wherein transmitting the INVITE that includes the signed third-party user identity to the terminating IMS network apparatus may include transmitting the INVITE that includes the signed third-party user identity to the terminating IMS network.
[0146] In an embodiment, the method may include rejecting the INVITE received from the UE, based on determining that the UE is not authorized to use the third-party user identity.
[0147] In an embodiment, a method performed by a terminating IMS network for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS) is provided.
[0148] In an embodiment, the method, wherein the terminating IMS network may include at least one of a S-CSCF or an IMS AS.
[0149] In an embodiment, the method, wherein receiving the third-party user identity from the third-party apparatus may include receiving the third-party user identity usage parameter, the third-party user identity through a Network Exposure Function (NEF), in case that the third-party apparatus is the untrusted application function. The method, wherein receiving the third-party user identity from the third-party apparatus may include receiving the third-party user identity usage parameter, the third-party user identity directly from the third-party apparatus, in case that the third-party is the trusted application function.
[0150] In an embodiment, the method may include receiving the third-party user identity usage parameter and the third-party user identity per IMPU or wildcarded IMPU.
[0151] The foregoing description of the specific embodiments will fully reveal the general nature of the embodiments herein such that others can readily modify and / or adapt such specific embodiments for various applications without departing from the generic concept. Therefore, such adaptations and modifications are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation. Thus, while the embodiments herein have been described in terms of preferred embodiments, those skilled in the art will recognize that the embodiments herein can be practiced with modifications within the scope of the embodiments as described herein.
Claims
1.A method performed by an originating IMS network for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS), the method comprising:receiving an INVITE from a User Equipment (UE);obtaining a subscription information of the UE from a Home Subscriber Server (HSS);identifying whether the UE is authorized to use the third-party user identity based on the subscription information;obtaining the third-party user identity from the HSS, based on identifying that the UE is authorized to use the third-party user identity; andtransmitting the INVITE that includes a signed third-party user identity to a terminating IMS network.2.The method of claim 1, wherein the originating IMS network comprises at least one of a Serving-Call Session Control Function (S-CSCF) or an IMS Application server (AS).3.The method of claim 1, wherein identifying whether the UE is authorized to use the third-party user identity comprises:identifying whether a third-party user identity usage parameter in the subscription information for the UE is enabled; anddetermining that the UE is authorized to use the third-party user identity in case that the third-party user identity usage parameter is enabled.4.The method of claim 1, wherein the third-party user identity comprises at least one of a caller name, an email address, an organization information and a job title per IMPU or wildcarded IMPU.5.The method of claim 1, wherein transmitting the INVITE that includes the signed third-party user identity to the terminating IMS network apparatus comprises:transmitting an INVITE to a signing server to sign the third-party user identity;receiving a signed third-party user identity from the signing sever;transmitting the INVITE that includes the signed third-party user identity to the terminating IMS network.6.The method of claim 1, the method comprising:rejecting the INVITE received from the UE, based on determining that the UE is not authorized to use the third-party user identity.7.A method performed by a terminating IMS network for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS), the method comprising:receiving an INVITE that includes a signed third-party user identity from an originating IMS network;transmitting the INVITE that includes the signed third-party user identity to a verification server;receiving a result of verification of the signed third-party user identity from the verification server, wherein the result can be successful or unsuccessful; andtransmitting an INVITE that includes a verified third-party user identity to a receiver UE, based on successful verification of the signed third-party user identity.8.The method of claim 7, wherein the terminating IMS network comprises at least one of a S-CSCF or an IMS AS.9.A method performed by a Home Subscriber Server (HSS) for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS), the method comprising:receiving a third-party user identity usage parameter, the third-party user identity from a third-party apparatus, wherein the third-party is at least one of a trusted application function or untrusted application function; andstoring the third-party user identity usage parameter, the third-party user identity received from the third-party apparatus.10.The method of claim 9, wherein receiving the third-party user identity from the third-party apparatus comprises:receiving the third-party user identity usage parameter, the third-party user identity through a Network Exposure Function (NEF), in case that the third-party apparatus is the untrusted application function; andreceiving the third-party user identity usage parameter, the third-party user identity directly from the third-party apparatus, in case that the third-party is the trusted application function.11.The method of claim 9, the method comprising:receiving the third-party user identity usage parameter and the third-party user identity per IMPU or wildcarded IMPU.12.An originating IMS network apparatus for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS), the originating IMS network apparatus comprises:a processor; andan IMS session controller communicatively coupled with the processor, wherein the IMS session controller:receive an INVITE from a User Equipment (UE);obtain a subscription information of the UE from a Home Subscriber Server (HSS);identify whether the UE is authorized to use the third-party user identity based on the subscription information;obtain the third-party user identity from the HSS, based on identifying that the UE is authorized to use the third-party user identity; andtransmit the INVITE that includes a signed third-party user identity to a terminating IMS network apparatus.13.A terminating IMS network apparatus for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS), the terminating IMS network apparatus comprises:a processor; andan IMS session controller communicatively coupled with the processor, wherein the IMS session controller:receive an INVITE that includes a signed third-party user identity from an originating IMS network apparatus;transmit the INVITE that includes the signed third-party user identity to a verification server;receive a result of verification of the signed third-party user identity from the verification server, wherein the result can be successful or unsuccessful; andtransmit an INVITE that includes a verified third-party user identity to a receiver UE, based on successful verification of the signed third-party user identity information.14.A Home Subscriber Server (HSS) for authorization and authentication of a third-party user identity in an IP Multimedia Subsystem (IMS), the HSS comprises:a processor; andan IMS session controller communicatively coupled with the processor, wherein the IMS session controller:receive a third-party user identity usage parameter, the third-party user identity from a third-party apparatus, wherein the third-party is at least one of a trusted application function or untrusted application function; andstore the third-party user identity usage parameter, the third-party user identity received from the third-party apparatus.
Citation Information
Patent Citations
Method for compensating robot control error of welding robot system using ai-based 3D vision module
KR1020230106288A
Method and system for implementing third-party authentication based on gray list
US20140130138A1
Method and apparatus for data management of third party services
US20160142904A1
Method and system for implementing third-party authentication based on gray list
US20170250991A1