Method and apparatus for digital identity creation and verification
The PASSporT extension for rich call data with a private key certificate enables secure communication sessions by authenticating user identities, addressing challenges in wireless systems where direct trusted relationships are absent.
Patent Information
- Application Number
- PCT/IB2025/051742
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-21
- Filing Date
- 2025-02-19
- Publication Date
- 2025-08-28
AI Technical Summary
Existing wireless communication systems face challenges in securely establishing sessions between user equipment, particularly in scenarios where originating and terminating parties lack a direct trusted relationship, leading to issues with authenticating caller identities and filtering out unauthorized communications.
The implementation of a PASSporT extension for rich call data, which includes a private key certificate, allows for the creation and verification of digital identities through a network system, using a signature process to authenticate users and establish secure communication sessions.
This approach ensures secure and reliable communication sessions by verifying the authenticity of the originating user, effectively filtering out unauthorized calls and enhancing security in wireless communication systems.
Smart Images

Figure IB2025051742_28082025_PF_FP_ABST
Abstract
Description
METHOD AND APPARATUS FOR DIGITAL IDENTITY CREATION AND VERIFICATIONPRIORITY CLAIM
[0001] The present application claims priority to U.S. provisional application No. 63 / 556,375, filed on February 21, 2024, the entire contents of which are incorporated herein.TECHNICAL FIELD
[0002] The present disclosure relates to wireless communications, and more specifically to establishing a wireless communication session with originating user identification.BACKGROUND
[0003] A wireless communications system may include one or multiple network communication devices, such as base stations, that may support wireless communications for one or multiple user communication devices, which are also called user equipment (UE) or other suitable terminology. The wireless communications system may support wireless communications with one or multiple user communication devices by utilizing resources of the wireless communications system, including time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers, or the like). Additionally, the wireless communications system may support wireless communications across various radio access technologies, such as including third generation (3G) radio access technology, fourth generation (4G) radio access technology, fifth generation (5G) radio access technology, and other suitable radio access technologies beyond 5G (e.g., sixth generation (6G)).SUMMARY
[0004] Some implementations of the method and apparatuses described herein may include performing wireless communications at a network system that establishes a session that provides authenticating a user of an originating user equipment with digital identity creation and verification. In one or more embodiments, the network system includes at least one memory containing personal assertion token (PASSporT) extension for rich call dataprogram code that defines at least one of a first network entity, and at least one processor coupled with the at least one memory. The at least one processor is configured to cause the network system to receive, by the first network entity via the transceiver from an originating user equipment, a first message containing a user identifier that is previously Internet Protocol Multimedia Subsystem (IMS) registered and associated with a PASSporT extension for rich call data and a private key certificate maintained by a second network entity. The first message indicates preparation for an IMS session with a terminating user equipment. The at least one processor is configured to cause the network system to obtain, from a second network entity based on the user identifier contained in the first message, headers and payload with token claims of the PASSporT extension for rich call data and the private key certificate associated with a user of the originating user equipment. The at least one processor is configured to cause the network system to create a signature by the first network entity, using the private key certificate and at least one header of the PASSporT extension for rich call data. The PASSporT extension for rich call data comprises headers, payload claims, and the signature, included in a first Session Initiation Protocol (SIP) header, and the first SIP header is included with the first message. The at least one processor is configured to cause the network system to transmit the first message with the header to a third network entity to prompt the third network entity to verify, using a public key certificate, the signature in the first SIP header. In response to verifying the signature, the network system forwards the first message with a second SIP header to the terminating user equipment to establish an IMS session with the originating user equipment.
[0005] In some implementations of the method and apparatuses described herein, a user equipment supports wireless communication including triggering establishment of a session as an originating user equipment. In one or more embodiments, the originating user equipment includes at least one memory containing a communication application, and at least one processor coupled with the at least one memory. The at least one processor is configured to cause the originating user equipment to generate a first message containing a user identifier that is previously IMS registered for and associated with a PASSporT extension for rich call data and a private key certificate maintained by a network system. The first message indicates preparation for an IMS session with a terminating user equipment. The at least one processor is configured to cause the originating user equipment to transmit, via the transceiver, the firstmessage to a network system to prompt the network system to: (i) obtain, from a second network entity, based on the user identifier contained in the first message, headers and payload with token claims of the PASSporT extension for rich call data and the private key certificate associated with a user of the originating user equipment; (ii) create, by a first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature including a header that is added to the first message; and (iii) transmit the first message with the header as a prompt to a third network entity. In response to receipt of the message, the third network entity verifies, using a public key certificate, the signature in the header. In response to verifying the signature in the header, the third network entity forwards the first message with the header to the terminating user equipment to verify a user of the originating user equipment. The at least one processor is configured to cause the originating user equipment to establish, with the terminating user equipment, a communication session.
[0006] As utilized herein, an article “a” before an element is unrestricted and understood to refer to “at least one” of those elements or “one or more” of those elements. The terms “a,” “at least one,” “one or more,” and “at least one of one or more” may be interchangeable. As used herein, including in the claims, “or” as used in a list of items (e.g., a list of items prefaced by a phrase such as “at least one of’ or “one or more of’ or “one or both of’) indicates an inclusive list such that, for example, a list of at least one of A, B, or C means A or B or C or AB or AC or BC or ABC (i.e., A and B and C). Also, as used herein, the phrase “based on” shall not be construed as a reference to a closed set of conditions. For example, an example step that is described as “based on condition A” may be based on both a condition A and a condition B without departing from the scope of the present disclosure. In other words, as used herein, the phrase “based on” shall be construed in the same manner as the phrase “based at least in part on. Further, as used herein, including in the claims, a “set” may include one or more elements.BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Figure 1 illustrates an example of a wireless communications system in accordance with aspects of the present disclosure.
[0008] Figure 2A illustrates internal operating modules of a home application server of a network system in accordance with aspects of the present disclosure.
[0009] Figure 2B illustrates internal operating modules of a terminating application server of a network system in accordance with aspects of the present disclosure.
[0010] Figure 3 is communication diagram of a communication system that supports establishment of a session between originating and terminating user equipment (UE), in accordance with aspects of the present disclosure.
[0011] Figure 4 illustrates an example of a network equipment (NE) in accordance with aspects of the present disclosure.
[0012] Figure 5 illustrates an example of UE in accordance with aspects of the present disclosure.
[0013] Figure 6 illustrates an example of a processor in accordance with aspects of the present disclosure.
[0014] Figure 7 illustrates a flowchart of a method performed by an NE in accordance with aspects of the present disclosure.
[0015] Figure 8 illustrates a flowchart of a method performed by a UE in accordance with aspects of the present disclosure.DETAILED DESCRIPTION
[0016] A procedure is specified at an Application Server (AS) for signing and verifying Real-Time Communication (RTC) services over Ms reference point. The AS and Interconnection Border Control Function (IBCF) communicate Hypertext Transfer Protocol (HTTP) signing request / response with AS for signing. The AS and IBCF communicate HTTP verification request / response with AS for verification. In particular, assertion verification uses an identity header field as specified. The procedure describes how a session initiation protocol (SIP) request is signed and verified, in addition to other information that is signed and verified.
[0017] A personal assertion token (PASSporT) has generally been proposed for cryptographically signing and for verifying an originating identity (e.g., a uniform resource identifier or telephone number) representing an originator of personal communications. The cryptographic signature enables a destination or terminating party to confidently verify the originating person even when the cryptographic signature is sent over an insecure channel. PASSporT may be particularly useful for many personal-communications applications over Internet Protocol (IP) networks and other multi-hop interconnection scenarios where the originating and destination parties may not have a direct trusted relationship. Study continues for RTC services that include filtering out robocalls associated with an unauthenticated caller identification.
[0018] Aspects of the present disclosure provide for storing information elements of PASSporT extension for rich call data and for fetching and using information elements that are necessary, including those of PASSporT extension for rich call data at the time of Internet Protocol Multimedia Subsystem (IMS) registration or IMS session establishment. Home Subscriber Server (HSS) stores the PASSporT extension for rich call data and the private certificate from the user's previous IMS registrations, prior to the user's current IMS registration. The PASSporT extension for rich call data and the private certificate may be updated due to the HSS: (i) subscription to the issuer to an appropriate event; or (ii) frequent fetches from the issuer. If the HSS does not have any stored PASSporT extension, the HSS fetches the information of PASSporT extension for rich call data directly or indirectly from the issuer. A further assumption is that the application server in this context is assumed to be a combination of: (i) an IMS-AS and a Signing AS in an originating or home domain; or (ii) an IMS-AS and a Verifying AS in a terminating domain.
[0019] Various aspects of the present disclosure relate to a network system, UE, method, and processor for wireless communication that supports rich data call establishment. In response to the network system receiving a message from an originating UE, a first network entity obtains, from a second network entity, headers, payload, with token claims of a PASSporT extension for rich call data, and a private key certificate associated with a user identifier contained in a message from originating UE, as new XML tags for Data information element, used in the Sh-Pull Resp message. The first network entity creates a signature byusing the private key and one of the headers of PASSporT extension for rich call data and adds PASSporT extension for rich call data now containing headers, payload with token claims and the signature in a first Session Initiation Protocol (SIP) header to the message and transmits the message with the SIP header to a third network entity for verification. When the PASSporT extension for rich call data is verified, the message with a second SIP header containing the verified information is forwarded to a terminating UE to establish an IMS session with the originating UE.
[0020] Figure 1 illustrates an example of a wireless communications system 100 in accordance with aspects of the present disclosure. The wireless communications system 100 may include one or more network entity (NE) 102, one or more user equipment (UE) 104, and a core network (CN) 106. The wireless communications system 100 may support various radio access technologies. In some implementations, the wireless communications system 100 may be a fourth generation (4G) network, such as an LTE network or an LTE- Advanced (LTE-A) network. In some other implementations, the wireless communications system 100 may be a new radio (NR) network, such as a fifth generation (5G) network, a 5G- Advanced (5G-A) network, or a 5G ultrawideband (5G-UWB) network. In other implementations, the wireless communications system 100 may be a combination of a 4G network and a 5G network, or other suitable radio access technology including Institute of Electrical and Electronics Engineers (IEEE) 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), and IEEE 802.20. The wireless communications system 100 may support radio access technologies beyond 5G, for example, 6G. Additionally, the wireless communications system 100 may support different technologies, such as time division multiple access (TDMA), frequency division multiple access (FDMA), or code division multiple access (CDMA), etc.
[0021] The one or more NE 102 may be dispersed throughout a geographic region to form the wireless communications system 100. One or more of the NE 102 described herein may be, or may include, or may be referred to as a network node, a base station, a network element, a network function, a network equipment, a network entity, a radio access network (RAN), a NodeB, an eNodeB (eNB), a next-generation NodeB (gNB), or other suitable terminology. An NE 102 and a UE 104 may communicate via a communication link, whichmay be a wireless or wired connection. For example, an NE 102 and a UE 104 may perform wireless communication (e.g., receive signaling, transmit signaling) over a Uu interface.
[0022] An NE 102 may provide a geographic coverage area for which the NE 102 may support services for one or more UEs 104 within the geographic coverage area. For example, an NE 102 and a UE 104 may support wireless communication of signals related to services (e.g., voice, video, packet data, messaging, broadcast, etc.) according to one or multiple radio access technologies. In some implementations, an NE 102 may be moveable, for example, a satellite associated with a non-terrestrial network (NTN). In some implementations, different geographic coverage areas associated with the same or different radio access technologies may overlap, but the different geographic coverage areas may be associated with different NE 102.
[0023] The one or more UE 104 may be dispersed throughout a geographic region of the wireless communications system 100. A UE 104 may include or may be referred to as a remote unit, a mobile device, a wireless device, a remote device, a subscriber device, a transmitter device, a receiver device, or some other suitable terminology. In some implementations, the UE 104 may be referred to as a unit, a station, a terminal, or a client, among other examples. Additionally, or alternatively, the UE 104 may be referred to as an Internet-of-Things (loT) device, an Internet-of-Everything (loE) device, or machine-type communication (MTC) device, among other examples.
[0024] A UE 104 may be able to support wireless communication directly with other UEs 104 over a communication link. For example, a UE 104 may support wireless communication directly with another UE 104 over a device-to-device (D2D) communication link. In some implementations, such as vehicle -to- vehicle (V2V) deployments, vehicle-to-everything (V2X) deployments, or cellular- V2X deployments, the communication link may be referred to as a sidelink. For example, a UE 104 may support wireless communication directly with another UE 104 over a PC5 interface.
[0025] An NE 102 may support communications with the CN 106, or with another NE 102, or both. For example, an NE 102 may interface with other NE 102 or the CN 106 through one or more backhaul links (e.g., SI, N2, N2, or network interface). In some implementations, the NE 102 may communicate with each other directly. In some other implementations, theNE 102 may communicate with each other or indirectly (e.g., via the CN 106). In some implementations, one or more NE 102 may include subcomponents, such as an access network entity, which may be an example of an access node controller (ANC). An ANC may communicate with the one or more UEs 104 through one or more other access network transmission entities, which may be referred to as radio heads, smart radio heads, or transmission-reception points (TRPs).
[0026] The CN 106 may support user authentication, access authorization, tracking, connectivity, and other access, routing, or mobility functions. The CN 106 may be an evolved packet core (EPC), or a 5G core (5GC), which may include a control plane entity that manages access and mobility (e.g., a mobility management entity (MME) and / or an access and mobility management functions (AMF)) and a user plane entity that routes packets or interconnects to external networks (e.g., a serving gateway (S-GW), a Packet Data Network (PDN) gateway (P-GW), or a user plane function (UPF)). In some implementations, the control plane entity may manage non-access stratum (NAS) functions, such as mobility, authentication, and bearer management (e.g., data bearers, signal bearers, etc.) for the one or more UEs 104 served by the one or more NE 102 associated with the CN 106.
[0027] The CN 106 may communicate with a packet data network over one or more backhaul links (e.g., via an SI, N2, N2, or another network interface). The packet data network may include an application server. In some implementations, one or more UEs 104 may communicate with the application server. A UE 104 may establish a session (e.g., a protocol data unit (PDU) session, or the like) with the CN 106 via an NE 102. The CN 106 may route traffic (e.g., control information, data, and the like) between the UE 104 and the application server using the established session (e.g., the established PDU session). The PDU session may be an example of a logical connection between the UE 104 and the CN 106 (e.g., one or more network functions of the CN 106).
[0028] According to aspects of the present disclosure, CN 106 supports sessions that handle PASSporT extensions for rich call data between originating and terminating UEs 104. CN 106 includes home network system 116 (“Home Domain”) having home application server (AS) 118, call session control function (CSCF) 120, home subscription server (HSS) 122, and unified data management (UDM) 124. CN 106 includes terminating network system126 having terminating AS 128 and CSCF 130. CN 106 may fetch PASSporT extensions for rich call data and private key certificates from a trusted domain 132 that includes an issuer 134 and a credential repository 136.
[0029] Figure 2A illustrates the home AS 118 of home network system 116 that may include an IMS-AS 202 communicating via HTTP with signing AS 204. Figure 2B illustrates the terminating AS 128 of the terminating network system 126. The terminating AS 128 includes an IMS-AS 206 communicating via HTTP with a verifying AS 208. Home AS 118 receives SIP messages from CSCF 120 that initiate session establishment. Terminating AS 128 receives SIP messages from CSCF 130 to participate in session establishment. It is assumed that the signing AS 204 (FIG. 2A) and the verifying AS 208 (FIG. 2B) use DIAMETER protocol to communicate with HSS. DIAMETER protocol, which is defined by Internet Engineering Task Force (IETF), provides authentication, authorization, and accounting (AAA) protocol for network access and data mobility applications protocol. DIAMETER protocol is used in Third Generation Partnership Program (3GPP) telecom networks in the IP Multimedia Subsystem (IMS), in Long Term Evolution (LTE) for mobility management, and for policy and charging control (PCC). The protocol is used in telecom networks (3G, LTE, 4G, and IMS). The 3rd Generation Partnership Project (3GPP) IMS enhances the DIAMETER protocol.
[0030] With continued reference to FIG. 1, in the wireless communications system 100, the NEs 102 and the UEs 104 may use resources of the wireless communications system 100, including time resources (e.g., symbols, slots, subframes, frames, or the like) or frequency resources (e.g., subcarriers, carriers) to perform various operations (e.g., wireless communications). In some implementations, the NEs 102 and the UEs 104 may support different resource structures. For example, the NEs 102 and the UEs 104 may support different frame structures. In some implementations, such as in 4G, the NEs 102 and the UEs 104 may support a single frame structure. In some other implementations, such as in 5G and among other suitable radio access technologies, the NEs 102 and the UEs 104 may support various frame structures (i.e., multiple frame structures). The NEs 102 and the UEs 104 may support various frame structures based on one or more numerologies.
[0031] One or more numerologies may be supported in the wireless communications system 100, and a numerology may include a subcarrier spacing and a cyclic prefix. A first numerology (e.g., / r=0) may be associated with a first subcarrier spacing (e.g., 15 kHz) and a normal cyclic prefix. In some implementations, the first numerology (e.g., / r=0) associated with the first subcarrier spacing (e.g., 15 kHz) may utilize one slot per subframe. A second numerology (e.g., / r=l) may be associated with a second subcarrier spacing (e.g., 30 kHz) and a normal cyclic prefix. A third numerology (e.g., / r=2) may be associated with a third subcarrier spacing (e.g., 60 kHz) and a normal cyclic prefix or an extended cyclic prefix. A fourth numerology (e.g., / r=3) may be associated with a fourth subcarrier spacing (e.g., 120 kHz) and a normal cyclic prefix. A fifth numerology (e.g., / r=4) may be associated with a fifth subcarrier spacing (e.g., 240 kHz) and a normal cyclic prefix.
[0032] A time interval of a resource (e.g., a communication resource) may be organized according to frames (also referred to as radio frames). Each frame may have a duration, for example, a 10 millisecond (ms) duration. In some implementations, each frame may include multiple subframes. For example, each frame may include 10 subframes, and each subframe may have a duration, for example, a 1 ms duration. In some implementations, each frame may have the same duration. In some implementations, each subframe of a frame may have the same duration.
[0033] Additionally, or alternatively, a time interval of a resource (e.g., a communication resource) may be organized according to slots. For example, a subframe may include a number (e.g., quantity) of slots. The number of slots in each subframe may also depend on the one or more numerologies supported in the wireless communications system 100. For instance, the first, second, third, fourth, and fifth numerologies (i.e., / r=0, / r=l, / r=2, / r=3, / r=4) associated with respective subcarrier spacings of 15 kHz, 30 kHz, 60 kHz, 120 kHz, and 240 kHz may utilize a single slot per subframe, two slots per subframe, four slots per subframe, eight slots per subframe, and 16 slots per subframe, respectively. Each slot may include a number (e.g., quantity) of symbols (e.g., OFDM symbols). In some implementations, the number (e.g., quantity) of slots for a subframe may depend on a numerology. For a normal cyclic prefix, a slot may include 14 symbols. For an extended cyclic prefix (e.g., applicable for 60 kHz subcarrier spacing), a slot may include 12 symbols.The relationship between the number of symbols per slot, the number of slots per subframe, and the number of slots per frame for a normal cyclic prefix and an extended cyclic prefix may depend on a numerology. It should be understood that reference to a first numerology (e.g., =0) associated with a first subcarrier spacing (e.g., 15 kHz) may be used interchangeably between subframes and slots.
[0034] In the wireless communications system 100, an electromagnetic (EM) spectrum may be split, based on frequency or wavelength, into various classes, frequency bands, frequency channels, etc. By way of example, the wireless communications system 100 may support one or multiple operating frequency bands, such as frequency range designations FR1 (410 MHz - 7.125 GHz), FR2 (24.25 GHz - 52.6 GHz), FR3 (7.125 GHz - 24.25 GHz), FR4 (52.6 GHz - 114.25 GHz), FR4a or FR4-1 (52.6 GHz - 71 GHz), and FR5 (114.25 GHz - 300 GHz). In some implementations, the NEs 102 and the UEs 104 may perform wireless communications over one or more of the operating frequency bands. In some implementations, FR1 may be used by the NEs 102 and the UEs 104, among other equipment or devices for cellular communications traffic (e.g., control information, data). In some implementations, FR2 may be used by the NEs 102 and the UEs 104, among other equipment or devices for short-range, high data rate capabilities.
[0035] FR1 may be associated with one or multiple numerologies (e.g., at least three numerologies). For example, FR1 may be associated with a first numerology (e.g., / r=0), which includes 15 kHz subcarrier spacing, a second numerology (e.g., / r=l), which includes 30 kHz subcarrier spacing, and a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing. FR2 may be associated with one or multiple numerologies (e.g., at least 2 numerologies). For example, FR2 may be associated with a third numerology (e.g., / r=2), which includes 60 kHz subcarrier spacing, and a fourth numerology (e.g., / r=3), which includes 120 kHz subcarrier spacing.
[0036] Figure 3 is a communication diagram of the wireless communications system 100 that supports establishment of an IMS session between an originating UE 104a and a terminating UE 104b, in accordance with aspects of the present disclosure. In particular, the wireless communications system 100 handles PASSporT extension of rich call data to authenticate user 301 of originating UE 104a.
[0037] At 310, the PASSporT extension for rich call data and the private certificate are issued by the issuer 134 and stored in the credential repository 136 and the Home Subscriber Server (HSS) 122 / Unified Data Management (UDM) 124. If there is any change or update of the PASSporT extension for rich call data and the private certificate, the issuer 134 updates the stored data in the credential repository 136 and the HSS 122 / UDM 124.
[0038] At 312, the user 301 of the originating UE104a registers for IMS services using a user identity which may be IP Multimedia Public User identity (IMPU), IP Multimedia Private Identity (IMPI), home network domain name, IP address, or instance identifier, if supporting Globally Routable UA URI (GRUU). In case the originating UE 104a belongs to an enterprise PBX, the registration message may contain a wildcarded IMPU to register the number range of the enterprise.
[0039] At 314, the S-CSCF 120 gets the Initial Filter Criteria (IFC) from the HSS 122 as part of the user profile. The IFC includes information about services that should be triggered for the user 301. Based on the IFC, the S-CSCF 120 sends the registration information to a service control platform via IMS Service Control (ISC) reference point.
[0040] At 316, upon receipt of registration information, the home Application Server (AS) 118, which may be a combination of an IMS-AS and a Signing AS, sends the information flow Sh-Pull including information about the user of the originating UE 104a to the HSS 122. The information flow Sh-Pull includes the information element as specified, and the information flow Sh-Pull is implemented as DIAMATER application User-Data- Request (UDR) Command, as specified.
[0041] At 318, based on the user's identity, the HSS 122 returns the information flow Sh- Pull Resp to the AS. The information is provided by the information elements as specified and implemented as DIAMETER application User-Data-Answer (UDA) Command. The information flow Sh-Pull Resp also includes the user's PASSporT extension of rich call data and the private certificate for the user signature. The UDA Command may include: (a) a new XML tag for PASSporT extension of rich call data; and (b) as a new XML tag for private key certificate in an XML document describing data information elements. The home AS 118 may store the PASSporT extension rich call data and the private key certificate associated with the user’s identity in a user profile.
[0042] At 320, the S-CSCF 120, based on the filter criteria of the IFC, registers to services and a “200 OK” SIP response code via LCSCF and P-CSCF. At 322, if the originating UE 104a in the home domain attempts to establish an IMS session, the originating UE 104a sends a SIP INVITE containing SDP with a list of media towards the S-CSCF 120. At 324, the S-CSCF 120 sends SIP INVITE to the home AS 118, which is the combination of the IMS-AS 202 and the Signing AS 204 (FIG. 2A).
[0043] At 326, if the home AS 118 has not stored the PASSporT extension for rich call data and the private certificate, the home AS 118 sends the information flow Sh-Pull, including information about the user 301 who uses the originating UE 104a, to the HSS 122. The information flow Sh-Pull includes the information element and is implemented as DIAMATER application User-Data-Request (UDR) Command.
[0044] At 328, the HSS 122 returns the information flow Sh-Pull Resp to the home AS 118. The information flow Sh-Pull Resp includes the user's Personal Assertion Token (PASSporT) extension of rich call data and the private certificate for the user signature in UDA Command. The UDA Command includes: (a) a new XML tag for PASSporT extension of rich call data; and (b) as a new XML tag for private key certificate in an XML document describing data information elements.
[0045] At 330, the home AS 118 adds a PASSporT extension of rich call data and uses the private key certificate for signature in the PASSporT extension of rich call data for the inclusion (or exclusion) of specific token claims in the payload and their values, so that the content can be verified to be accurate at the terminating party. The home AS 118 inserts the new information in a P-Asserted-Identity header field and transmits the SIP INVITE toward the S-CSCF 120.
[0046] At 332, the S-CSCF 120 sends the SIP INVITE towards the Terminating CSCF 130. At 334, the terminating CSCF 130 forwards the SIP INVITE to the terminating AS 128.
[0047] At 336, upon receipt of the INVITE by the terminating AS 128, which is a combination of an IMS-AS 206 and a verifying AS 208 (FIG. 2B), the terminating AS 128 gets the information for the location of where to obtain the certificate from the PASSporT extension of rich call data.
[0048] At 338, the terminating AS 128 identifies the credential repository 136 holding the public key certificate and obtains the public key. At 340, the credential repository 136 provides the public key certificate. At 342, the terminating AS 128 uses the public key certificate to verify the user 301 and forwards the INVITE to CSCF and also towards the terminating UE 104b at 344. At 346, an IMS session is established for the IMS application.
[0049] At the time of IMS registration or during the IMS session establishment, the homeAS 118 requests the PASSporT extension for rich call data from the HSS 122 via the Sh interface. The procedure requires new XML tags for the Data information element.
[0050] The new XML tags for the data information element contain: (i) private key certificate; and (ii) PASSporT extension for rich call data comprising the location for the public key certificate, where the private key certificate is used for digital signature while public key certificate is used for verifying the signature. The PASSporT extension for rich call data also comprises other claims, including the rich call data claim.
[0051] Normative data: XML tag for PASSporT extension of rich call data may include (i) PASSporT protected header: (a) "typ": type which is set to "passport"; (b) "alg": algorithm which includes an ability to specify the use of a cryptographic algorithm for the signature part and may be at least ES256; and (c) "x5u": a URI referring to the resource for the X.509 public key certificate or certificate chain. The XML tag for PASSporT extension of rich call data may include (ii) PASSporT pay load with token claims that need to be verified at the destination, such as: (a) "iat" (Issued At) Claim; (b) "dest" (Destination) Claim; (c) "orig" (Origination) Claim; (d) "red" (Rich call data) Claim; and (e) "origid" (Origination ID) Claim. XML tag for private key certificate may include URI referring to the resource for the private key certificate or the actual private key certificate.
[0052] In one or more embodiments, the present disclosure may provide a method that includes transmitting by a first device to a first network entity a first message, wherein the first message is targeted to a second device. The method may include transmitting by the first network entity to a second network entity a second message comprising an identity. The method may include transmitting by the second network entity to the first network entity a third message including: (i) a PASSporT extension for rich call data; and (ii) a private key certificate. The method may include creating a signature by the second network entity. Thesignature is added in a new added header to the first message and forwarded to a third network entity. The method may include verifying the signature in the new added header by the third network entity. The method may include forwarding the first message to the targeted device to establish a session.
[0053] In one or more particular embodiments, a PASSporT extension for rich call data and a private key certificate are new XML tags for an information element of Sh reference point. In one or more particular embodiments, the first, second, and third network entities are respectively a signing Application Server (AS) 204 (FIG. 2A) for signing a signature, an HSS 122, and a verifying Application Server (AS) 208 (FIG. 2B) for verifying the signature. The signing AS 204 (FIG. 2A) and the verifying AS 208 (FIG. 2B) are provided to confirm that identity of a user 301 who is using the originating UE 104a. The HSS 122 is provided to store the PASSporT extension rich call data and the private key certificate.
[0054] Figure 4 illustrates an example of a NE 400 in accordance with aspects of the present disclosure. The NE 400 may include a processor 402, a memory 404, a controller 406, and a transceiver 408. The processor 402, the memory 404, the controller 406, or the transceiver 408, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0055] The processor 402, the memory 404, the controller 406, or the transceiver 408, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0056] The processor 402 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 402 may be configured to operate the memory 404. In some other implementations, the memory 404 may be integrated into the processor 402. Theprocessor 402 may be configured to execute computer-readable instructions stored in the memory 404 to cause the NE 400 to perform various functions of the present disclosure.
[0057] The memory 404 may include volatile or non-volatile memory. The memory 404 may store computer-readable, computer-executable code including instructions when executed by the processor 402, cause the NE 400 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium such the memory 404 or another type of memory. Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or specialpurpose computer.
[0058] In some implementations, the processor 402 and the memory 404 coupled with the processor 402 may be configured to cause the NE 400 to perform one or more of the functions described herein (e.g., executing, by the processor 402, instructions stored in the memory 404). For example, the processor 402 may support wireless communication at the NE 400 in accordance with examples as disclosed herein.
[0059] The controller 406 may manage input and output signals for the NE 400. The controller 406 may also manage peripherals not integrated into the NE 400. In some implementations, the controller 406 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 406 may be implemented as part of the processor 402.
[0060] In some implementations, the NE 400 may include at least one transceiver 408. In some other implementations, the NE 400 may have more than one transceiver 408. The transceiver 408 may represent a wireless transceiver. The transceiver 408 may include one or more receiver chains 410, one or more transmitter chains 412, or a combination thereof.
[0061] A receiver chain 410 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 410 may include one or more antennas for receiving the signal over the air or wireless medium. The receiver chain 410 may include at least one amplifier (e.g., a low-noise amplifier (LNA))configured to amplify the received signal. The receiver chain 410 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data by reversing the modulation technique applied during transmission of the signal. The receiver chain 410 may include at least one decoder for decoding and processing the demodulated signal to receive the transmitted data.
[0062] A transmitter chain 412 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 412 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM).
[0063] According to one or more aspects of the present disclosure, NE 400 supports establishment of a wireless communication session between originating and terminating UEs 104a-104b (FIG. 3) with the benefits of verifying the originating user to the terminating user. The processor 402 configures NE 400 to receive, by a first network entity via the transceiver 508 from an originating user equipment, a first message containing a user identifier that is previously IMS registered and associated with a PASSporT extension for rich call data and a private key certificate maintained by a second network entity. The first message indicates preparation for a session with a terminating user equipment. The processor 402 configures NE 400 to obtain, from a second network entity based on the user identifier contained in the first message, the PASSporT for rich call data and the private key certificate associated with a user of the originating user equipment. The processor 402 configures NE 400 to create, by the first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature comprising a header that is added to the first message. The processor 402 configures NE 400 to transmit the first message with the header to a third network entity to prompt the third network entity. In response, the third network entity verifies, using a public key certificate, the signature in the header. In response to verifying the signature in the header, the NE 400 forwards the first message with the header to the terminating user equipment to establish an IMS session with the originating userequipment. In response to not verifying the signature in the header, the NE 400 may refuse to forward the first message and may return a refusal SIP code to the originating UE.
[0064] In one or more embodiments, a first extensible markup language (XML) tag comprises PASSporT extension for rich call data containing: a) one or more header for (i) a type; (ii) an algorithm, which includes an ability to specify the use of a cryptographic algorithm for the signature; and (iii) a location for public key certificate; and b) one or more token claims of a group comprising at least: (i) issued at claim; (ii) destination claim; (iii) origination claim; (iv) rich call data claim; and (iv) origination identifier claim
[0065] The processor 402 configures NE 400 to obtain, from the second network entity, the private key certificate via a second XML tag containing the private key certificate. In one or more particular embodiments, the processor 402 configures NE 400 to create, by the first network entity using the private key certificate and algorithm header "alg" of PASSporT extension for rich call data, a signature for the PASSporT extension for rich call data. The PASSporT extension for rich call data comprising the headers, the payload with token claims, and the signature are added to the first message by using a first SIP header and used for verification of the originating user at a destination. At the destination, the third network entity determines a location of a public key certificate based on the first SIP header included with the first message. The third network entity verifies the signature by using the public key certificate. In response to verifying the signature, the third network entity forwards the first message with a second SIP header towards the terminating UE.
[0066] In one or more embodiments, the first network entity includes a home application server having a home Internet Protocol Multimedia Subsystem (IMS) application server and a signing application server. The second network entity includes a home subscription server communicatively coupled to a credential repository. The third network entity includes a terminating IMS application server and a verifying application server. In one or more particular embodiments, at least one base station is communicatively couplable to the originating user equipment and is communicatively coupled to the home application server. The home application server receives the first message via the at least one base station.
[0067] In one or more particular embodiments, the memory 404 contains PASSporT extension for rich call data program code that defines a serving call session control function (S-CSCF) that configures the NE 400 to perform a session initiation protocol (SIP). The first message includes a SIP request indicating IMS registration or IMS session establishment. In one or more specific embodiments, in response to receiving the SIP request, the S-CSCF retrieves, from the home subscription server, an Initial Filter Criteria (IFC) of a user profile associated with the user identifier. The IFC indicates registration information of one or more applications that are triggered for the user of the originating user equipment. The S-CSCF sends the registration information to a service control platform via an IMS service control (ISC) reference point.
[0068] Figure 5 illustrates an example of a UE 500 in accordance with aspects of the present disclosure. The UE 500 may include a processor 502, a memory 504, a controller 506, and a transceiver 508. The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations thereof or various components thereof may be examples of means for performing various aspects of the present disclosure as described herein. These components may be coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces.
[0069] The processor 502, the memory 504, the controller 506, or the transceiver 508, or various combinations or components thereof may be implemented in hardware (e.g., circuitry). The hardware may include a processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), or other programmable logic device, or any combination thereof configured as or otherwise supporting a means for performing the functions described in the present disclosure.
[0070] The processor 502 may include an intelligent hardware device (e.g., a general- purpose processor, a DSP, a CPU, an ASIC, an FPGA, or any combination thereof). In some implementations, the processor 502 may be configured to operate the memory 504. In some other implementations, the memory 504 may be integrated into the processor 502. The processor 502 may be configured to execute computer-readable instructions stored in the memory 504 to configure the UE 500 to perform various functions of the present disclosure.
[0071] The memory 504 may include volatile or non-volatile memory. The memory 504 may store computer-readable, computer-executable code including instructions when executed by the processor 502 cause the UE 500 to perform various functions described herein. The code may be stored in a non-transitory computer-readable medium, such as the memory 504 or another type of memory. Computer-readable media includes both non- transitory computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. A non-transitory storage medium may be any available medium that may be accessed by a general-purpose or specialpurpose computer.
[0072] In some implementations, the processor 502 and the memory 504 coupled with the processor 502 may be configured to cause the UE 500 to perform one or more of the functions described herein (e.g., executing, by the processor 502, instructions stored in the memory 504). For example, the processor 502 may support wireless communication at the UE 500 in accordance with examples as disclosed herein. The UE 500 may be configured to support a means for establishing communication session, such as an IMS session, between originating and terminating user equipment. The controller 506 may manage input and output signals for the UE 500. The controller 506 may also manage peripherals not integrated into the UE 500. In some implementations, the controller 506 may utilize an operating system such as iOS®, ANDROID®, WINDOWS®, or other operating systems. In some implementations, the controller 506 may be implemented as part of the processor 502.
[0073] In some implementations, the UE 500 may include at least one transceiver 508. In some other implementations, the UE 500 may have more than one transceiver 508. The transceiver 508 may represent a wireless transceiver. The transceiver 508 may include one or more receiver chains 510, one or more transmitter chains 512, or a combination thereof.
[0074] A receiver chain 510 may be configured to receive signals (e.g., control information, data, packets) over a wireless medium. For example, the receiver chain 510 may include one or more antennas for receiving the signal over the air or wireless medium. The receiver chain 510 may include at least one amplifier (e.g., a low-noise amplifier (LNA)) configured to amplify the received signal. The receiver chain 510 may include at least one demodulator configured to demodulate the receive signal and obtain the transmitted data byreversing the modulation technique applied during transmission of the signal. The receiver chain 510 may include at least one decoder for decoding and processing the demodulated signal to receive the transmitted data.
[0075] A transmitter chain 512 may be configured to generate and transmit signals (e.g., control information, data, packets). The transmitter chain 512 may include at least one modulator for modulating data onto a carrier signal, preparing the signal for transmission over a wireless medium. The at least one modulator may be configured to support one or more techniques such as amplitude modulation (AM), frequency modulation (FM), or digital modulation schemes like phase-shift keying (PSK) or quadrature amplitude modulation (QAM). The transmitter chain 512 may also include at least one power amplifier configured to amplify the modulated signal to an appropriate power level suitable for transmission over the wireless medium. The transmitter chain 512 may also include one or more antennas for transmitting the amplified signal into the air or wireless medium.
[0076] In one or more aspects of the present disclosure, the UE 500 performs wireless communication via the transceiver 508 that supports PASSporT extension for rich call data. Controller 506 is coupled with memory 504 and is configured to cause the processor 502 to generate a first message containing a user identifier previously registered and associated with a personal assertion token extension for rich call data and a private key certificate maintained by a network system. The first message indicates preparation for a session with a terminating user equipment. The controller 506 is configured to cause the processor 502 to transmit, via the transceiver 508, the first message to a network system (NE 102 of FIG. 1) to prompt the network system to: (i) obtain, from a second network entity, based on the user identifier contained in the first message, the personal assertion token extension for rich call data and the private key certificate associated with an identity of a user of the user equipment; (ii) create, by the first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature comprising a header that is added to the first message; and (iii) transmit the first message with the header to a third network entity to prompt the third network entity. In response, the third network entity verifies, using a public key certificate, the signature in the header. In response to verifying the signature in the header, the network system forwards the first message with the header to the terminatinguser equipment to verify the user equipment. The controller 506 is configured to cause the processor 502 to establish, with the terminating user equipment, a communication session.
[0077] In one or more embodiments, in generating the first message, the controller 506 is configured to cause the processor 502 to generate a session initiation protocol (SIP) INVITE comprising session description protocol (SDP) having a list of media. In one or more embodiments, the user identifier is one identifier of a group including: (i) home network domain name Internet Protocol (IP) address; (ii) IP Multimedia Public User identity (IMPU); (iii) IP Multimedia Private Identity (IMPI); and (iv) instance identifier supporting Globally Routable User Agent Uniform Resource Identifier URI (GRUU). In one or more particular embodiments, the UE 500 belongs to an enterprise private branch exchange (PBX). The user identifier is the IMPU wildcarded to register a number range of the PBX.
[0078] Figure 6 illustrates an example of a processor 600 in accordance with aspects of the present disclosure. The processor 600 may be an example of a processor configured to perform various operations in accordance with examples as described herein. The processor 600 may include a controller 602 configured to perform various operations in accordance with examples as described herein. The processor 600 may optionally include at least one memory 604, which may be, for example, an L1 / L2 / L3 cache. Additionally, or alternatively, the processor 600 may optionally include one or more arithmetic-logic units (ALUs) 606. One or more of these components may be in electronic communication or otherwise coupled (e.g., operatively, communicatively, functionally, electronically, electrically) via one or more interfaces (e.g., buses).
[0079] The processor 600 may be a processor chipset and include a protocol stack (e.g., a software stack) executed by the processor chipset to perform various operations (e.g., receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) in accordance with examples as described herein. The processor chipset may include one or more cores, one or more caches (e.g., memory local to or included in the processor chipset (e.g., the processor 600) or other memory (e.g., random access memory (RAM), read-only memory (ROM), dynamic RAM (DRAM), synchronous dynamic RAM (SDRAM), static RAM (SRAM), ferroelectric RAM (FeRAM),magnetic RAM (MRAM), resistive RAM (RRAM), flash memory, phase change memory (PCM), and others).
[0080] The controller 602 may be configured to manage and coordinate various operations (e.g., signaling, receiving, obtaining, retrieving, transmitting, outputting, forwarding, storing, determining, identifying, accessing, writing, reading) of the processor 600 to cause the processor 600 to support various operations in accordance with examples as described herein. For example, the controller 602 may operate as a control unit of the processor 600, generating control signals that manage the operation of various components of the processor 600. These control signals include enabling or disabling functional units, selecting data paths, initiating memory access, and coordinating timing of operations.
[0081] The controller 602 may be configured to fetch (e.g., obtain, retrieve, receive) instructions from the memory 604 and determine subsequent instruction(s) to be executed to cause the processor 600 to support various operations in accordance with examples as described herein. The controller 602 may be configured to track memory address of instructions associated with the memory 604. The controller 602 may be configured to decode instructions to determine the operation to be performed and the operands involved. For example, the controller 602 may be configured to interpret the instruction and determine control signals to be output to other components of the processor 600 to cause the processor 600 to support various operations in accordance with examples as described herein. Additionally, or alternatively, the controller 602 may be configured to manage flow of data within the processor 600. The controller 602 may be configured to control transfer of data between registers, arithmetic logic units (ALUs), and other functional units of the processor 600.
[0082] The memory 604 may include one or more caches (e.g., memory local to or included in the processor 600 or other memory, such RAM, ROM, DRAM, SDRAM, SRAM, MRAM, flash memory, etc. In some implementations, the memory 604 may reside within or on a processor chipset (e.g., local to the processor 600). In some other implementations, the memory 604 may reside external to the processor chipset (e.g., remote to the processor 600).
[0083] The memory 604 may store computer-readable, computer-executable code including instructions that, when executed by the processor 600, cause the processor 600 toperform various functions described herein. The code may be stored in a non-transitory computer-readable medium such as system memory or another type of memory. The controller 602 and / or the processor 600 may be configured to execute computer-readable instructions stored in the memory 604 to cause the processor 600 to perform various functions. For example, the processor 600 and / or the controller 602 may be coupled with or to the memory 604, and the processor 600, the controller 602, and the memory 604 may be configured to perform various functions described herein. In some examples, the processor 600 may include multiple processors and the memory 604 may include multiple memories. One or more of the multiple processors may be coupled with one or more of the multiple memories, which may, individually or collectively, be configured to perform various functions herein.
[0084] The one or more ALUs 606 may be configured to support various operations in accordance with examples as described herein. In some implementations, the one or more ALUs 606 may reside within or on a processor chipset (e.g., the processor 600). In some other implementations, the one or more ALUs 606 may reside external to the processor chipset (e.g., the processor 600). One or more ALUs 606 may perform one or more computations such as addition, subtraction, multiplication, and division on data. For example, one or more ALUs 606 may receive input operands and an operation code, which determines an operation to be executed. One or more ALUs 606 be configured with a variety of logical and arithmetic circuits, including adders, subtractors, shifters, and logic gates, to process and manipulate the data according to the operation. Additionally, or alternatively, the one or more ALUs 606 may support logical operations such as AND, OR, exclusive-OR (XOR), not-OR (NOR), and not-AND (NAND), enabling the one or more ALUs 606 to handle conditional operations, comparisons, and bitwise operations.
[0085] The processor 600 may support wireless communication in accordance with examples as disclosed herein. The processor 600 may be configured to or operable to support PASSporT extension for rich call data for a means for establishing a session between user equipment to expose unauthenticated users. The UE 500 implements the processor 502, memory 504, controller 506 and transceiver 508 that performs the functionality described herein.
[0086] Figure 7 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a NE as described herein. In some implementations, the NE may execute a set of instructions to control the function elements of the NE to perform the described functions.
[0087] At 705, the method may include receiving, by a first network entity via a transceiver from an originating user equipment, a first message containing a user identifier that is previously Internet Protocol Multimedia Subsystem (IMS) registered and associated with a personal assertion token (PASSporT) extension for rich call data and a private key certificate maintained by a second network entity, the first message indicating preparation for a session with a terminating user equipment. The operations of 705 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 705 may be performed by a NE as described with reference to Figure 4.
[0088] At 710, the method may include obtaining, from a second network entity based on the user identifier contained in the first message, the personal assertion token extension for rich call data and the private key certificate associated with a user of the originating user equipment. The operations of 710 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 710 may be performed by a NE as described with reference to Figure 4.
[0089] At 715, the method may include creating, by the first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature for the PASSporT extension for rich call data, wherein the PASSporT extension for rich call data comprising the header, a payload with token claims, and the signature are included in a first Session Initiation Protocol (SIP) header that is added to the first message . The operations of 715 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 715 may be performed by a NE as described with reference to Figure 4.
[0090] At 720, the method may include transmitting the first message with the first SIP header to a third network entity to prompt the third network entity to: (i) verify, using a public key certificate, the signature; and (ii) in response to verifying the signature, forward, by the network system, the first message with a second SIP header to the terminating user equipmentto establish a session with the originating user equipment. In some implementations, aspects of the operations of 720 may be performed by a NE as described with reference to Figure 4.
[0091] In accordance with aspects of the present disclosure, the PASSporT extension for rich call data may be a header including a location for the public key certificate. In one or more particular embodiments, an extensible markup language (XML) tag includes the PASSporT extension for rich call data containing information for a cryptographic algorithm and a location of a public key certificate or certificate chain. The method may further include obtaining, from the second network entity, the private key certificate via a second XML tag. In one or more specific embodiments, the method may further include creating a signature, by the first network entity using the private key certificate and information of the XML tag for "alg" header (i.e., identifying type of encryption algorithm) of the PASSporT extension for rich call data. The signature is included in an SIP header included with the first message. At the destination, the signature included in the SIP header enables verification using a public key certificate identified in the SIP header.
[0092] In one or more specific embodiments, the XML tag for PASSporT for rich call data contains the one or more headers for (i) a type of media; (ii) an algorithm, which includes an ability to specify the use of a cryptographic algorithm for the signature; and (iii) a location for a public key certificate. The XML tag for PASSporT for rich call data contains the one or more token claim of a group comprising at least: (i) issued at claim; (ii) destination claim; (iii) origination claim; (iv) rich call data claim; and (iv) origination identifier claim.
[0093] In one or more embodiments, the first network entity is or includes a home application server (HSS) having a home IMS application server and a signing application server. The second network entity is or includes a HSS communicatively coupled to a credential repository. The third network entity is or includes a terminating IMS application server and a verifying application server.
[0094] In one or more particular embodiments, the method may further include receiving the first message at the HSS via at least one base station. In one or more particular embodiments, the method may further include receiving, at a serving call session control function (S-CSCF) of the network system, the first message comprising a session initiationprotocol (SIP) request indicating IMS registration or IMS session establishment. The method may further include sending, by S-CSCF, the SIP request to the HSS.
[0095] In one or more specific embodiments, the method may further include: in response to receiving the SIP request, retrieving, by the S-CSCF from the home subscription server, an Initial Filter Criteria (IFC) of a user profile associated with the user identifier, the IFC indicating registration information of one or more applications that are triggered for the user of the originating user equipment; and sending, by S-CSCF, the registration information to a service control platform via an IMS service control (ISC) reference point.
[0096] Figure 8 illustrates a flowchart of a method in accordance with aspects of the present disclosure. The operations of the method may be implemented by a UE as described herein. In some implementations, the UE may execute a set of instructions to control the function elements of the UE to perform the described functions.
[0097] At 805, the method may include generating, by an originating user equipment, a first message containing a user identifier that is previously Internet Protocol Multimedia Subsystem (IMS) registered and associated with a personal assertion token (PASSporT) extension for rich call data and a private key certificate maintained by a network system, the first message indicating preparation for a session with a terminating user equipment. The operations of 805 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 805 may be performed by a UE as described with reference to FIG. 5.
[0098] At 810, the method may include transmitting, via a transceiver of the originating user equipment, the first message to a network system to prompt the network system to: (i) obtain, from a second network entity, based on the user identifier contained in the first message, the PASSporT extension for rich call data and the private key certificate associated with a user of the originating user equipment; (ii) create, by the first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature for the PASSporT extension for rich call data, where the PASSporT extension for rich call data comprises the header, the payload with token claims, and the created signature are included in a first Session Initiation Protocol (SIP) header that is added to the first message; and (iii) transmit the first message with the first SIP header to a third network entityto prompt the third network entity to: (a) verify, using a public key certificate, the signature; and (b) in response to verifying the signature in the header, forward, by the network system, the first message with a second SIP header to the terminating user equipment to verify the originating user equipment. The operations of 810 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 810 may be performed by a UE as described with reference to FIG. 5.
[0099] At 815, the method may include establishing a communication session with the terminating user equipment. The operations of 815 may be performed in accordance with examples as described herein. In some implementations, aspects of the operations of 815 may be performed by a UE as described with reference to FIG. 5.
[0100] According to aspects of the present disclosure, the PASSporT extension for rich call data may include a header containing a location for the public key certificate. In one or more embodiments, the method may further include generating the first message comprising a SIP INVITE using session description protocol (SDP) to incorporate a list of media.
[0101] In one or more embodiments, the user identifier may be one identifier of a group including: (i) home network domain name Internet Protocol (IP) address; (ii) IP Multimedia Public User identity (IMPU); (iii) IP Multimedia Private Identity (IMPI); and (iv) instance identifier supporting Globally Routable User Agent Uniform Resource Identifier URI (GRUU). In one or more particular embodiments, the originating user equipment may belong to an enterprise private branch exchange (PBX). The user identifier includes the IMPU wildcarded to register a number range of the PBX.
[0102] It should be noted that the method described herein describes a possible implementation, and that the operations and the steps may be rearranged or otherwise modified and that other implementations are possible.
[0103] The description herein is provided to enable a person having ordinary skill in the art to make or use the disclosure. Various modifications to the disclosure will be apparent to a person having ordinary skill in the art, and the generic principles defined herein may be applied to other variations without departing from the scope of the disclosure. Thus, thedisclosure is not limited to the examples and designs described herein but is to be accorded the broadest scope consistent with the principles and novel features disclosed herein.
Claims
CLAIMSWhat is claimed is:
1. A network system for wireless communication, the network system comprising: at least one memory; and at least one processor coupled with the at least one memory, and configured to cause the network system to: receive, by a first network entity from an originating user equipment (UE), a first message containing a user identifier associated with a personal assertion token (PASSporT) extension for rich call data that defines a first network entity and a private key certificate maintained by a second network entity, the first message indicating preparation for a communication session with a terminating UE; obtain, from a second network entity based on the user identifier contained in the first message, the PASSporT extension for rich call data and the private key certificate associated with a user of the originating UE; create, by the first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature of PASSporT extension for rich call data that is included in a first header included with the first message; and transmit the first message with the header to a third network entity to prompt the third network entity to: verify, using a public key certificate, the signature in the first header; and in response to verifying the signature, forward, by the network system, the first message with a second header to the terminating UE to establish a communication session with the originating UE.
2. The network system of claim 1, wherein: the user identifier is previously Internet Protocol Multimedia Subsystem (IMS) registered and associated with the PASSporT extension for rich call data and the private key certificate maintained by the second network entity;the PASSporT extension for rich call data comprises headers, payload claims and the signature; the first message indicates preparation for the communication session comprising an IMS session with the terminating UE; the first header comprises a first Session Initiation Protocol (SIP) header; and the second header comprises a second SIP header.
3. The network system of claim 2, wherein: a first extensible markup language (XML) tag specifies PASSporT extension for rich call data that comprises information for a cryptographic algorithm and a location of a public key certificate or certificate chain; wherein the first XML tag for PASSporT for rich call data comprises: one or more headers for (i) type, (ii) algorithm, which includes an ability to specify use of a cryptographic algorithm for the signature, and (iii) a location for a public key certificate; one or more token claims of a group comprising (i) issued at claim, (ii) destination claim, (iii) origination claim, (iv) rich call data claim, and (iv) origination identifier claim; and the signature; and the at least one processor is further configured to cause the network system to obtain, from the second network entity, the private key certificate via a second XML tag comprising a private key used to create the signature.
4. The network system of claim 3, wherein the at least one processor is further configured to cause the network system to create the signature, by the first network entity using the second XML tag for the private key certificate and information of the XML tag for algorithm header of PASSporT extension for rich call data, the signature added as a signature part of the PASSporT extension for rich call data to the first message by a SIP header for verification at a destination.
5. The network system of claim 2, wherein: the first network entity comprises a home application server having a home IMS application server and a signing application server;the second network entity comprises a home subscription server communicatively coupled to a credential repository; and the third network entity comprises a terminating IMS application server and a verifying application server.
6. The network system of claim 5, further comprising at least one base station communicatively couplable to the originating UE and communicatively coupled to the home application server, wherein the home application server receives the first message via the at least one base station.
7. The network system of claim 5, wherein: the at least one memory comprises rich call data program code that defines a serving call session control function (S-CSCF) that configures the network system to perform a session initiation protocol (SIP); the first message comprises a SIP request indicating one of IMS registration or IMS session establishment; and in response to receiving the SIP request, the at least one processor is further configured to cause the network system to, via the S-CSCF: retrieve, from the home subscription server, an Initial Filter Criteria (IFC) of a user profile associated with the user identifier, the IFC indicating registration information of one or more IMS applications that are triggered for the originating UE; and send the registration information to a service control platform via an IMS service control (ISC) reference point.
8. A method of wireless communication as an application server of a network system, the method comprising: receiving, by a first network entity from an originating UE, a first message containing a user identifier associated with a personal assertion token (PASSporT) extension for rich call data and containing a private key certificate maintained by a second network entity, thefirst message indicating preparation by the originating UE for a communication session with a terminating UE; obtaining, from a second network entity based on the user identifier contained in the first message, the PASSporT extension for rich call data and the private key certificate associated with a user of the originating UE; creating, by the first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature for the PASSporT extension for rich call data that is included in a first header added to the first message; and transmitting the first message with the first header to a third network entity to prompt the third network entity to: verify, using a public key certificate, the signature; and in response to verifying the signature, forward, by the network system, the first message with a second header to the terminating UE to establish the communication session with the originating UE.
9. The method of claim 8, wherein: the user identifier is previously Internet Protocol Multimedia Subsystem (IMS) registered and associated with the PASSporT extension for rich call data and the private key certificate maintained by the second network entity; the PASSporT extension for rich call data comprises the header comprising a location for the public key certificate, a payload with token claims, and the signature; the first message indicates preparation for the communication session comprising an IMS session with the terminating UE; the first header comprises a first Session Initiation Protocol (SIP) header; and the second header comprises a second SIP header.
10. The method of claim 9, wherein an extensible markup language (XML) tag comprises the PASSporT extension for rich call data containing information for a cryptographic algorithm and a location of a public key certificate or certificate chain, the method further comprises: obtaining, from the second network entity, the private key certificate via a second XML tag; and creating a signature, by the first network entity using the private key certificate and information of the XML tag for "alg" header of the PASSporT extension for rich call data.
11. The method of claim 8, wherein: the first network entity comprises a home application server having a home Internet Protocol Multimedia Subsystem (IMS) application server and a signing application server; the second network entity comprises a home subscription server communicatively coupled to a credential repository; the third network entity comprises a terminating IMS application server and a verifying application server; and the method further comprises: receiving, at a serving call session control function (S-CSCF) of the network system, the first message comprising a session initiation protocol (SIP) request indicating IMS registration or IMS session establishment; and sending, by the S-CSCF, the SIP request to the home application server.
12. The method of claim 11, further comprising: receiving the first message at the home application server via at least one base station.
13. A user equipment (UE) for wireless communication, the UE comprising: at least one memory; and at least one processor coupled with the at least one memory, and configured to cause the UE to: generate a first message containing a user identifier associated with a personal assertion token (PASSporT) extension for rich call data and a private key certificatemaintained by a network system, the first message indicating preparation for a session with a terminating UE; transmit the first message to a network system to prompt the network system to: obtain, from a second network entity, based on the user identifier contained in the first message, headers and payload with token claims of the PASSporT extension for rich call data and the private key certificate associated with a user of the UE; create, by a first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature for the PASSporT extension for rich call data, wherein the PASSporT extension for rich call data comprising the header, a payload with token claims, and the signature are included in a first header that is added to the first message; and transmit the first message with the first header to a third network entity to prompt the third network entity to: verify, using a public key certificate, the signature; and in response to verifying the signature, forward, by the network system, the first message with a second header to the terminating UE to verify the UE; and establish a communication session with the terminating UE, based on verification by the network system of the UE.
14. The UE of claim 13, wherein: the user identifier is previously Internet Protocol Multimedia Subsystem (IMS) registered and associated with the PASSporT extension for rich call data and the private key certificate maintained by the second network entity; the user identifier comprises one identifier of a group comprising: (i) home network domain name Internet Protocol (IP) address; (ii) IP Multimedia Public User identity (IMPU); (iii) IP Multimedia Private Identity (IMPI); (iv) instance identifier supporting Globally Routable User Agent Uniform Resource Identifier URI (GRUU);the PASSporT extension for rich call data comprises a header comprising a location for the public key certificate; the first message indicates preparation by the UE for the communication session, which comprises an IMS session with the terminating UE; the first header comprises a first Session Initiation Protocol (SIP) header; and the second header comprises a second SIP header.
15. The UE of claim 14, wherein the UE belongs to an enterprise private branch exchange (PBX), and the user identifier comprises the IMPU wildcarded to register a number range of the PBX.
16. The UE of claim 13, wherein, in generating the first message, the at least one processor causes the UE to generate a session initiation protocol (SIP) INVITE comprising session description protocol (SDP) having a list of media.
17. A processor for wireless communication by a user equipment (UE), the processor comprising: at least one controller coupled with at least one memory and configured to cause the processor to: generate a first message containing a user identifier associated with a personal assertion token (PASSporT) extension for rich call data and a private key certificate maintained by a network system, the first message indicating preparation for a communication session with a terminating user equipment; transmit the first message to a network system to prompt the network system to: obtain, from a second network entity, based on the user identifier contained in the first message, the PASSporT extension for rich call data and the private key certificate associated with a user of the UE; create, by a first network entity using the private key certificate and at least one header of the PASSporT extension for rich call data, a signature for the PASSporT extension for rich call data, wherein the PASSporT extensionfor rich call data comprising the header, a payload with token claims, and the signature are included in a first header that is added to the first message; and transmit the first message with the header to a third network entity to prompt the third network entity to: verify, using a public key certificate, the signature; and in response to verifying the signature, forward, by the network system, the first message with a second header to the terminating UE to verify the UE; and establish a communication session with the terminating UE, based on verification by the network system of the UE.
18. The processor of claim 17, wherein: the user identifier is previously Internet Protocol Multimedia Subsystem (IMS) registered and associated with the PASSporT extension for rich call data and the private key certificate maintained by the second network entity; the user identifier comprises one identifier of a group comprising: (i) home network domain name Internet Protocol (IP) address; (ii) IP Multimedia Public User identity (IMPU); (iii) IP Multimedia Private Identity (IMPI); (iv) instance identifier supporting Globally Routable User Agent Uniform Resource Identifier URI (GRUU); the PASSporT extension for rich call data comprises a header comprising a location for the public key certificate; the first message indicates preparation for the communication session comprising an IMS session with the terminating user equipment; the first header comprises a first Session Initiation Protocol (SIP) header; and the second header comprises a second SIP header.
19. The processor of claim 18, wherein the UE belongs to an enterprise private branch exchange (PBX), and the user identifier comprises the IMPU wildcarded to register a number range of the PBX.
20. The processor of claim 17, wherein the at least one controller is further configured to cause the processor to generate the first message comprising a SIP INVITE using session description protocol (SDP) to incorporate a list of media.
Citation Information
Patent Citations
Secure telephone identity (STI) certificate management system
US20200221302A1
Subscription-based techniques for communicating third-party information
WO2024031309A1
US202463556375P
Cited By
Method for validating radio frequency identification number
US12554948B2
Method for validating radio frequency identification number
US20210248328A1