Optimized security algorithm negotiation for IP multimedia subsystem registration
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2026-02-06
- Publication Date
- 2026-08-13
Smart Images

Figure CN2026077455_13082026_PF_FP_ABST
Abstract
Description
OPTIMIZED SECURITY ALGORITHM NEGOTIATION FOR IP MULTIMEDIA SUBSYSTEM REGISTRATIONINCORPORATION BY REFERENCE
[0001] This application claims the benefit of U.S. Provisional Application No. 63 / 755,386, filed on February 7, 2025, which is incorporated herein by reference in its entirety.TECHNICAL FIELD
[0002] The present disclosure relates to security mechanism negotiation for an IP Multimedia Subsystem in a wireless communication system.BACKGROUND
[0003] The IP Multimedia Subsystem (IMS) is an architectural framework for delivering IP multimedia services to user equipment (UE) over packet-switched networks. When a UE registers with an IMS network, it establishes secure communication with a Proxy Call Session Control Function (P-CSCF) entity, which serves as the UE’s first point of contact with the IMS network. During the registration process, the UE and the P-CSCF may negotiate one or more security mechanisms to protect signaling communication. Security mechanism negotiation may be performed through an exchange of signaling messages.SUMMARY
[0004] Aspects of the disclosure provide methods and apparatus for optimizing security algorithm negotiation during the IP multimedia subsystem (IMS) registration.
[0005] In one aspect, the method includes determining whether the UE is accessing a wireless network over a low bit rate access type. In response to determining the UE is accessing the wireless network over a low bit rate access type, the method further includes transmitting a first session initiation protocol (SIP) register request message to a network entity in an IP multimedia subsystem (IMS) in the wireless network. The SIP register request message including a security-client header field that contains a predetermined minimal subset of security algorithms for integrity and confidentiality protection.
[0006] In some implementations of the method, the network entity comprises a proxy call session control function (P-CSCF) entity.
[0007] In some implementations of the method, the method further includes in response to determining the UE is accessing the network entity via an access type other than the low bitrate access type, transmitting a second SIP register request message including all security algorithms for integrity and confidentiality protection supported by the UE.
[0008] In some implementations of the method, the low bitrate access type is a satellite access.
[0009] In some implementations of the method, the satellite access comprises access via a geostationary (GEO) satellite.
[0010] In some implementations of the method, the low bitrate access type is a narrowband internet of things (NB-IoT) access.
[0011] In some implementations of the method, the security-client header field comprises two sets of IPsec security parameters associated with the set of security algorithms for integrity and confidentiality protection, and in response to determining the UE is accessing the network entity via an access type other than the low bitrate access type, the security-client header field comprises more than two sets of IPsec security parameters.
[0012] In some implementations of the method, each set of IPsec security parameters comprises an encryption algorithm parameter and an integrity algorithm parameter.
[0013] In another aspect, a UE includes circuitry configured to determine whether the UE is accessing a wireless network over a low bit rate access type. In response to determining the UE is accessing the wireless network over a low bit rate access type, the circuitry is further configured to transmit a first session initiation protocol (SIP) register request message to a network entity in an IP multimedia subsystem (IMS) in the wireless network. The SIP register request message including a security-client header field that contains a predetermined minimal subset of security algorithms for integrity and confidentiality protection.
[0014] In some embodiments, the network entity is configured to support the predetermined minimal subset of security algorithms by determining the UE is accessing the wireless network over the low bit rate access type.
[0015] In a further aspect, a non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method, the method includes determining whether the UE is accessing a wireless network over a low bit rate access type. In response to determining the UE is accessing the wireless network over a low bit rate access type, the method further includes transmitting a first session initiation protocol (SIP) register request message to a network entity in an IP multimedia subsystem (IMS) in the wireless network. The SIP register request message including a security-client header field that contains a predetermined minimal subset of security algorithms for integrity and confidentiality protection.BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Various embodiments of this disclosure that are proposed as examples will be described in detail with reference to the following figures, wherein like numerals reference like elements, and wherein:
[0017] FIG. 1 shows an example architecture of an IP Multimedia Subsystem (IMS) .
[0018] FIG. 2 shows an example security agreement message flow for IMS registration according to some embodiments of the present disclosure.
[0019] FIG. 3 shows a block diagram of an example apparatus.DETAILED DESCRIPTION OF EMBODIMENTS
[0020] Optimized security algorithm negotiation in IP Multimedia Subsystem (IMS)
[0021] IMS and related IP-based communication systems employ security mechanisms to protect signaling exchanged between user equipment (UE) and network entities during registration and session establishment procedures. Such security mechanisms typically involve negotiation of integrity and confidentiality algorithms, protocol modes, and associated parameters, which are conveyed from the UE to the network during an initial registration procedure.
[0022] In some implementations, a UE indicates all supported security algorithms and associated parameters when initiating a secure connection with the network. This approach may result in signaling messages that include lengthy security-related headers. The resulting message size can be inefficient or problematic in access environments characterized by limited bitrate, long round-trip delays, or constrained bandwidth, such as satellite-based communication systems, narrowband access technologies, or other non-terrestrial networks.
[0023] In such constrained access scenarios, transmitting extensive security negotiation information may increase signaling overhead, prolong registration procedures, and adversely impact system efficiency. Accordingly, there exists a need for improved techniques that reduce signaling overhead associated with security mechanism negotiation while maintaining adequate security protection.
[0024] The present disclosure provides techniques for optimizing security algorithm negotiation between a UE and a network when communication is performed over a bandwidth-constrained or high-latency access network. For example, a UE can be configured to determine an access type over which it is communicating with the network. When the access type corresponds to a low-bitrate, long-delay, or otherwise constrained communication environment, the UE selectively indicates only a reduced subset of supported security algorithms during a registration or signaling procedure. The subset of security algorithms may be predefined, standardized, preconfigured within the user equipment, or previously agreed upon with the network.
[0025] In contrast, when the UE communicates over an access network that is not subject to such constraints, the user equipment may indicate a broader set of supported security algorithms, thereby enabling full security negotiation consistent with conventional operation.
[0026] By limiting the number of security algorithm combinations indicated during registration over constrained access networks, the length of security-related signaling messages is reduced. This reduction improves signaling efficiency, decreases transmission overhead, and enhances performance in environments such as satellite-based or narrowband communication systems, while still enabling secure communication between the user equipment and the network.
[0027] Architecture of IP Multimedia Subsystem (IMS)
[0028] FIG. 1 shows an example architecture of an IMS 100 in a wireless communication system. The IMS 100 is divided into a Visited Network 110 and a Home Network 120. The visited network 110 is the network in which a UE 112 is physically located and through which the UE 112 gains initial network access. The visited network 110 may be different from the user’s home network 120, such as when the user is roaming. As shown in FIG. 1, the visited network includes a Proxy Call and Session Control Function (P-CSCF) 114.
[0029] The UE 112 is a user device or terminal that accesses the IMS. The UE 112 establishes IP connectivity through an access network 115, which may include low bitrate access networks such as satellite access via geostationary (GEO) , Low Earth Orbit (LEO) , or Medium Earth Orbit (MEO) satellites, or narrowband Internet of Things (NB-IoT) access.
[0030] The P-CSCF 114 serves as an initial point of contact between a UE 112 and an IMS network. In some embodiments, an address of the P-CSCF 114 is preconfigured at the UE 112, while in other embodiments the address is obtained dynamically through network discovery or configuration procedures. In other examples, the P-CSCF 114 may alternatively be located in a home network rather than a visited network.
[0031] During a registration procedure, the P-CSCF 114 can perform one or more security-related functions. For example, the P-CSCF 114 may receive an initial registration request 201 from the UE 112 that includes information identifying one or more security mechanisms supported by the UE 112. The P-CSCF 114 may store the received security mechanism information for subsequent verification and may forward the registration request toward one or more network control entities.
[0032] In response to an authentication challenge generated by the network, the P-CSCF 114 can obtain security key material associated with the UE 112 and may include, in a response message, information identifying security mechanisms supported by the P-CSCF 114, along with parameters for establishing secure communication.
[0033] The P-CSCF 114 may establish one or more temporary secure communication associations with the UE 112 using the obtained security key material and may verify that subsequent registration messages include verification information consistent with the previously indicated security mechanisms, thereby mitigating unauthorized modification or interception of signaling messages. The P-CSCF 114 may further perform integrity verification on protected messages received from the UE 112 and, upon successful completion of registration, may maintain one or more long-term secure communication associations with the UE 112.
[0034] The home network 120 is a network associated with a subscriber and includes a plurality of multimedia subsystem functional entities, such as a Home Subscriber Server (HSS) 122, an Interrogating Call and Session Control Function (I-CSCF) 124, a Serving Call and Session Control Function (S-CSCF) 126, and one or more application servers 128. The home network 120 is responsible for authenticating users, managing user profiles and subscription information, and providing access to subscribed multimedia services.
[0035] The HSS 122 operates as a centralized repository in the home network 120 and stores subscription information and authentication-related data associated with users. The HSS 122 maintains user profiles including one or more user identities, service authorization information, and security-related parameters. The HSS 122 also provides subscriber information to the I-CSCF 124 to facilitate selection of a serving session control entity and provides authentication-related information to the S-CSCF 126 during a registration or authentication procedure. The HSS 122 can further maintain information identifying which S-CSCF 126 is currently serving a registered user.
[0036] The I-CSCF 124 operates as an entry point for signaling messages associated with a subscriber of the home network 120. Upon receiving a registration request forwarded from a proxy session control entity, the I-CSCF 124 may obtain subscriber-related information from the HSS 122 and may select an appropriate serving session control entity to process the registration request. The I-CSCF 124 may forward the registration request to the selected S-CSCF 126 and may relay responses generated by the S-CSCF 126 toward the proxy session control entity. In some embodiments, the I-CSCF 124 may further conceal internal network topology information from external networks.
[0037] The S-CSCF 126 performs session control and registration management functions for registered users. During a registration procedure, the S-CSCF 126 receives a registration request from the I-CSCF 124, identifies the user based on information included in the registration request, and determines whether authentication information is available. If authentication information is unavailable or invalid, the S-CSCF 126 may obtain authentication-related data from the HSS 122 and generate an authentication challenge for delivery to the UE 112.
[0038] Additionally, the S-CSCF 126 verifies an authentication response received from the UE 112 and, upon successful authentication, obtains a user profile from the HSS 122. The S-CSCF 126 determines registration parameters, maintains registration state information for the user, and generate a registration success response. Further, the S-CSCF 126 routes subsequent signaling messages associated with the user toward one or more application servers 128 based on the user profile.
[0039] One or more application servers 128, i.e., AS-1 through AS-N, provide multimedia services to users. The number and type of application servers may vary depending on implementations. The S-CSCF 126 determines which application servers 128 a user is authorized to access based on subscription information obtained from the HSS 122. The application servers 128 provide services such as communication services, messaging services, presence-related services, conferencing services, multimedia content delivery, and third-party application services.
[0040] As illustrated in FIG. 1, a registration procedure includes the following operations. A UE 112 initiates a registration request toward a P-CSCF 114, which forwards the registration request to the home network 120. The I-CSCF 124 receives the registration request and interacts with the HSS 122 to identify an appropriate S-CSCF 126. The registration request is forwarded to the selected S-CSCF 126, which performs authentication and registration processing with assistance from the HSS 122. Upon successful registration, the UE 112 is permitted to access multimedia services provided by one or more application servers 128 through a secure communication path established within the multimedia subsystem.
[0041] Security Agreement Message Flow
[0042] FIG. 2 illustrates a message flow 200 of a security mechanism agreement procedure performed between the UE 112 and the P-CSCF 114 during registration with the IMS 100. The security mechanism agreement procedure enables establishment of a secure signaling relationship between the UE and the IMS network and mitigates security threats, including man-in-the-middle (MITM) attacks, during session initiation signaling.
[0043] During a registration procedure, a Session Initiation Protocol (SIP) user agent and a next-hop SIP entity negotiate security mechanisms, cryptographic algorithms, and associated parameters to be applied to subsequent SIP signaling. Absent a protected negotiation mechanism, SIP signaling is susceptible to attacks in which an adversary alters proposed security capabilities to force the communicating entities to operate using weaker security mechanisms than those otherwise supported.
[0044] The security mechanism agreement procedure addresses these vulnerabilities through a multi-stage negotiation and verification process. In an initial stage, the UE 112 transmits an indication of one or more supported security mechanisms in a first signaling message. The P-CSCF 114 responds by challenging the UE 112 and providing a corresponding indication of security mechanisms supported by the network. The UE then selects a preferred security mechanism from the intersection of the respective supported mechanisms and activates the selected mechanism. Thereafter, the UE 112 retransmits a signaling message protected by the selected security mechanism and includes a verification indication corresponding to the security mechanisms previously provided by the P-CSCF 114. The P-CSCF 114 compares the verification indication with the previously transmitted indication to confirm that the negotiation information was not altered during transmission, thereby detecting the presence of any MITM attack.
[0045] In the IMS registration, the security mechanism agreement procedure is coordinated with an authentication and key agreement process, through which mutual authentication is performed and security associations are established between the UE 112 and the P-CSCF 114. The resulting security associations are subsequently applied to protect SIP signaling exchanged between the UE 112 and the P-CSCF 114.
[0046] FIG. 2 shows the message flow 200 exchanged between the UE 112 and the P-CSCF 114 through signaling steps S211 through S215, collectively illustrating the security mechanism negotiation, verification, authentication, and registration procedures.
[0047] Step S211: Initial Registration Request
[0048] At step S211, the UE 112 initiates a registration procedure with the P-CSCF 114 by transmitting an initial registration request 201. Prior to transmission of the registration request, the UE 112 has established an IP connectivity bearer for session initiation signaling, obtained an IP address, and determined an address of the P-CSCF 114. In addition, and in accordance with the present disclosure, the UE 112 has determined the access network type prior to initiating registration. For example, a lower layer (s) of the UE 112 responsible for establishing an IP connection through an access network may provide information of the access network type to an upper layer responsible for establishing a SIP session. If the UE 112 determines it is accessing the P-CSCF 114 via a non-low bitrate access, the Security-Client header field contains a list of security mechanisms that the UE 112 supports. If the UE 112 determined the P-CSCF 114 via a low bitrate access type such as satellite access (including geostationary (GEO) , Low Earth Orbit (LEO) , or Medium Earth Orbit (MEO) satellites) , narrowband Internet of Things (NB-IoT) access, and the like, the UE 112 would indicate only a predetermined subset of security algorithms in the subsequent Security-Client header field.
[0049] The UE 112 transmits an unprotected initial registration request 201 to the P-CSCF 114. The registration request includes identification information identifying a user to be registered, routing information indicating a network address and port at which the UE 112 expects to receive responses, and contact information indicating an address at which the UE 112 is reachable for subsequent signaling. The registration request further includes authentication-related parameters in an initial state indicating that the request is not integrity-protected.
[0050] The initial registration request 201 includes a Security-Client header field, which is set to specify signaling-plane security mechanisms supported by the UE 112, Internet Protocol Security (IPsec) layer algorithms for integrity protection and confidentiality protection supported by the UE 112, and parameter values required for establishment of two new pairs of security associations between the UE 112 and the P-CSCF 114. The parameter values include identifiers and port information to be used for protecting subsequent signaling traffic in both transmission directions.
[0051] Non-low Bitrate Access
[0052] In some implementations, when the UE 112 determines that the access network does not correspond to a low-bitrate access type, the initial registration request 201 includes a full set of supported IPsec security parameter sets in the Security-Client header field.
[0053] For example, the parameter sets may include:
[0054] A protocol parameter (e.g., “prot” ) indicating that an encapsulating security payload protocol is used to provide integrity protection and, optionally, confidentiality protection for signaling messages;
[0055] A mode parameter (e.g., “mod” ) indicating an IPsec operating mode, including a transport mode for direct signaling protection or a UDP-encapsulated tunnel mode for traversal of network address translation devices;
[0056] Security parameter indexes (e.g., “spi-c” and “spi-s” ) identifying security associations for signaling transmitted from the UE to the network entity and from the network entity to the UE;
[0057] A client port parameter (e.g., “port-c” ) and a server port parameter (e.g., “port-s” ) , identifying protected transport ports at which the UE and the network entity, respectively, transmit and receive protected signaling messages;
[0058] An integrity algorithm parameter (e.g., “alg” ) identifying a cryptographic algorithm used to provide message authentication and integrity protection; and
[0059] An encryption algorithm parameter (e.g., “ealg” ) identifying a cryptographic algorithm used to provide confidentiality protection, including an option specifying that no encryption is applied.
[0060] The Security-Client header field may include multiple parameter sets, each parameter set corresponding to a distinct combination of integrity and encryption algorithms supported by the UE 112. Each parameter set is usable to establish a respective pair of security associations for bidirectional signaling protection.
[0061] Low Bitrate Access
[0062] In some implementations, when the UE 112 determines that the access network corresponds to a low bitrate access type, the UE 112 restricts the Security-Client header field to include only a predetermined subset of supported IPsec security parameter sets. By limiting the indicated security mechanisms to the predetermined subset, signaling overhead and computational burden are reduced while maintaining adequate protection for low bitrate access conditions.
[0063] For example, the Security-Client header field includes two distinct sets of IPsec security parameters, each set corresponding to a respective combination of cryptographic algorithms for protecting signaling traffic at the IPsec layer. The two sets of IPsec security parameters are associated with integrity protection and, selectively, confidentiality protection for session initiation signaling exchanged between the UE 112 and the P-CSCF 114.
[0064] In some example, each set of IPsec security parameters includes an encryption algorithm parameter (ealg) and an integrity algorithm parameter (alg) . The encryption algorithm parameter specifies whether and how payload confidentiality is provided for protected signaling messages, and the integrity algorithm parameter specifies a cryptographic message authentication algorithm applied to detect modification of signaling messages and to authenticate the source of the messages.
[0065] In some implementations, a first set of the two sets of IPsec security parameters specifies that no encryption algorithm is applied to signaling messages, as indicated by a null encryption parameter value. In the first set, integrity protection is provided by a Hash-based Message Authentication Code (HMAC) -based integrity algorithm, where a hash-based message authentication code is computed over protected signaling messages using a shared secret key and a designated cryptographic hash function. The resulting message authentication code is included in each protected signaling message to enable verification of message integrity and authenticity at the receiving entity, while minimizing processing and bandwidth overhead.
[0066] In some implementations, a second set of the two sets of IPsec security parameters specifies application of an Advanced Encryption Standard (AES) -based encryption algorithm to provide confidentiality protection for signaling messages, in combination with an HMAC-based integrity algorithm. In the second set, signaling message payloads are encrypted using the AES algorithm, and a message authentication code is generated and appended to each encrypted message to ensure integrity and authentication. The combination of AES encryption and HMAC-based integrity protection provides both confidentiality and integrity for signaling traffic transmitted over the signaling plane.
[0067] Each of the two sets of IPsec security parameters is configured to establish a corresponding pair of IPsec security associations, including a first security association for signaling transmitted from the UE 112 to the P-CSCF 114 and a second security association for signaling transmitted from the P-CSCF 114 to the UE 112.
[0068] Upon receiving the initial registration request 201, the P-CSCF 114 detects and stores the contents of the Security-Client header field for subsequent verification, associates the stored security capability information with the registration transaction, and forwards the initial registration request 201 toward the home network 120 for authentication and assignment of a serving control function. The stored security capability information is subsequently used to verify that negotiated security mechanisms have not been altered during signaling exchange.
[0069] Step S212: Server Security Capability Challenge
[0070] At step S212, the P-CSCF 114 transmits a challenge response 202 to the UE 112 in response to receipt of the initial, unprotected initial registration request 201. The challenge response 202 indicates that authentication and security agreement procedures are required before registration can be completed. The challenge response 202 is transmitted without signaling-plane protection and is routed to the UE 112 based on transport and addressing information associated with the initial registration request 201.
[0071] Generation of the challenge response 202 is performed through coordinated processing between the S-CSCF 126 and the P-CSCF 114. Upon receipt of the initial registration request 201, the S-CSCF 126 identifies the user based on user identity information included in the request and retrieves authentication material from a subscriber database. The authentication material includes a random challenge value, a network authentication token, an expected authentication response, and cryptographic keys for integrity protection and confidentiality protection.
[0072] Using the retrieved authentication material, the S-CSCF 126 generates a challenge response 202 that includes authentication challenge information enabling the UE 112 to authenticate the network and compute a response. The challenge response 202 further includes cryptographic key material intended for use by the P-CSCF 114 in establishing signaling security associations.
[0073] Upon receiving the challenge response 202 from the S-CSCF 126, the P-CSCF 114 performs security-related processing prior to forwarding the response to the UE 112. In particular, the P-CSCF 114 extracts cryptographic key material associated with integrity protection and confidentiality protection and prevents exposure of the extracted key material outside a trusted network domain. The P-CSCF 114 associates the extracted cryptographic keys with a user identity corresponding to the initial registration request 201 for subsequent establishment of signaling security associations.
[0074] The P-CSCF 114 further inserts into the challenge response 202 a Security-Server header field indicating security mechanisms supported by the network entity for protecting subsequent signaling traffic. The Security-Server header field specifies one or more IPsec-based signaling security mechanisms and includes security parameters defining protocol type, operating mode, security parameter indices, protected transport ports, encryption algorithms, and integrity algorithms.
[0075] In accordance with the present disclosure, the contents of the Security-Server header field are selected based on access network conditions are aligned with the security parameter sets indicated by the UE 112. When the access network corresponds to a low-bitrate access type, the Security-Server header field includes a predetermined subset of security parameter sets, each parameter set defining a respective combination of encryption and integrity algorithms consistent with reduced signaling overhead requirements. When the access network does not correspond to a low-bitrate access type, the Security-Server header field includes a broader set of supported security mechanisms.
[0076] The P-CSCF 114 further establishes a temporary set of IPsec security associations using the extracted cryptographic keys, where the temporary security associations are maintained for a limited duration sufficient to allow completion of authentication and security agreement procedures. The temporary security associations provide integrity protection and confidentiality protection for subsequent signaling exchanged during the registration procedure.
[0077] After completing the prior processing, the P-CSCF 114 forwards the modified challenge response 202, including the Security-Server header field and excluding the cryptographic key material, to the UE 112. The forwarded challenge response 202 enables the UE 112 to authenticate the network and to select a mutually supported signaling security mechanism for establishment of permanent signaling security associations.
[0078] Step S213: Activation of Negotiated Signaling Security
[0079] At step S213, the UE 112 processes the received challenge response 202 and activates signaling security in accordance with a negotiated security agreement. Upon receipt of the challenge response 202, the UE 112 performs authentication processing and establishes security associations for protecting subsequent signaling exchanged with the P-CSCF 114.
[0080] The UE 112 extracts authentication challenge information from the received response and performs network authentication by validating an authentication token derived from a random challenge value. Network authentication is completed by verifying message authentication data and freshness information associated with the challenge. When authentication fails, the UE 112 terminates the registration attempt and initiates a new registration procedure.
[0081] The UE 112 further verifies the presence and validity of a Security-Server header field included in the challenge response 202 received from the P-CSCF 114. The Security-Server header field is examined to confirm that it contains security parameter information required for establishment of signaling security associations. If the Security-Server header field is absent or incomplete, the UE 112 abandons the authentication procedure and refrains from activating signaling security.
[0082] Upon successful authentication and verification, the UE 112 computes an authentication response and derives cryptographic key material, including an integrity key and a cipher key, based on the received challenge information and a long-term subscriber key stored in the UE 112. The derived cryptographic keys are used for signaling security association establishment with the P-CSCF 114.
[0083] Subsequently, the UE 112 selects a signaling security mechanism from an intersection of security parameter sets indicated in a Security-Client header field previously transmitted by the UE 112 and a Security-Server header field received from the P-CSCF 114. Selection is performed based on a defined preference ordering among mutually supported security mechanisms. When the UE 112 operates over a non-low-bitrate access network, the Security-Client and Security-Server header fields include a broader set of supported security parameter sets, and the UE 112 selects a security mechanism from the broader intersection based on the preference ordering. When the UE 112 operates over a low-bitrate access network, both the Security-Client and Security-Server header fields contain a predetermined subset of security parameter sets, thereby constraining selection to that subset and reducing negotiation complexity. The selected security mechanism specifies an integrity protection algorithm and, optionally, an encryption algorithm.
[0084] Following selection, the UE 112 establishes a temporary set of IPsec security associations for signaling protection with the P-CSCF 114 using the selected security mechanism. The temporary security associations include a first security association for signaling transmitted from the UE 112 to the P-CSCF 114 and a second security association for signaling transmitted from the P-CSCF 114 to the UE 112. The security associations are configured using derived cryptographic keys, security parameter identifiers, protected transport ports, and address selectors corresponding to signaling traffic exchanged between the UE 112 and the P-CSCF 114. Integrity protection is applied using the derived integrity key, and confidentiality protection is applied using the derived cipher key when encryption is enabled.
[0085] The temporary security associations are activated for a limited duration sufficient to complete authentication and registration procedures. Upon activation of the security associations, all subsequent signaling exchanged between the UE 112 and the P-CSCF 114 is protected in accordance with the selected signaling security mechanism.
[0086] Step 213 completes the security activation phase, where negotiated signaling security is enabled and enforced between the UE 112 and the P-CSCF 114 in a manner interoperable with compliant network implementations.
[0087] Step 214: Integrity-Protected Server List Return
[0088] At Step S214, after establishment of one or more temporary security associations, a UE 112 transmits a second registration request 204 to a P-CSCF 114. The second registration request 204 is transmitted using integrity protection and confidentiality protection, provided by an IPsec encapsulating security payload (ESP) mechanism negotiated during a preceding security agreement procedure.
[0089] The second registration request 204 is transmitted from a protected client port of the UE 112 to a protected server port of the P-CSCF 114, wherein the protected client port and the protected server port are specified by corresponding Security-Client and Security-Server header fields exchanged during the security agreement procedure. The second registration request 204 is protected using selected integrity and confidentiality algorithms defined by an established pair of IPsec security associations.
[0090] The second registration request 204 includes substantially the same header fields as an initial registration request 201 transmitted prior to authentication, and further includes an Authorization header field containing authentication parameters generated by the UE 112 in response to a received authentication challenge. The Authorization header field includes a username parameter identifying a private user identity, a realm parameter identifying a home network domain, a URI parameter identifying a SIP uniform resource identifier associated with the home network domain, a nonce parameter obtained from a WWW-Authenticate header field, a response parameter containing an authentication response value computed by the UE 112, an algorithm parameter identifying an authentication algorithm corresponding to the authentication challenge, and an integrity-protected parameter indicating that the second registration request 204 is integrity-protected.
[0091] When the second registration request 204 is protected by an established security association, a Contact header field and a Via header field of the second registration request 204 include a protected server port value corresponding to the established security association, thereby enabling correct routing of protected signaling messages between the UE 112 and the P-CSCF 114.
[0092] The second registration request 204 further includes a Security-Client header field that is identical to a Security-Client header field transmitted by the UE 112 in a previously challenged registration request. Inclusion of the identical Security-Client header field enables the P-CSCF 114 to verify that client-supported security mechanisms and parameters have not been modified between the challenged registration request and the integrity-protected second registration request 204. When the UE 112 operates over a low-bitrate access network, the Security-Client header field included in the second registration request 204 contains only a predetermined subset of security parameter sets selected to reduce signaling overhead. When the UE 112 operates over an access network other than a low-bitrate access network, the Security-Client header field contains a broader set of supported security parameter sets.
[0093] The second registration request 204 additionally includes a Security-Verify header field containing contents that mirror a Security-Server header field previously received from the P-CSCF 114. The Security-Verify header field includes the same security mechanisms, parameter values, and ordering as the received Security-Server header field, thereby enabling the P-CSCF 114 to verify that server-supported security mechanisms and parameters were not altered during transmission. When the UE 112 operates over a low-bitrate access network, the Security-Verify header field includes only the predetermined subset of security parameter sets. When the UE 112 operates over an access network other than a low-bitrate access network, the Security-Verify header field includes all security parameter sets received from the P-CSCF 114.
[0094] The second registration request 204 further includes Require and Proxy-Require header fields indicating support for a security agreement mechanism, and includes a Call-ID header field having a value that matches a Call-ID header field of an authentication challenge response 202 previously received by the UE 112.
[0095] S215: Verification and Final Registration Response
[0096] At step S215, after receipt of the second registration request 204, the P-CSCF 114 performs verification processing and generates a final response 206 toward the UE 112, the final response 206 comprising either a success response indicating completion of registration or an error response indicating registration failure.
[0097] Upon receiving the second registration request 204, the P-CSCF 114 verifies integrity protection applied to the second registration request 204 using one or more temporary IPsec security associations previously established between the UE 112 and the P-CSCF 114. When integrity verification fails, the P-CSCF 114 rejects the second registration request 204 and generates an error response.
[0098] The P-CSCF 114 compares a Security-Client header field included in the second registration request 204 with a Security-Client header field stored in association with a previously challenged registration request (referring to the initial registration request 201) . When the Security-Client header fields do not match, the P-CSCF 114 determines that the second registration request 204 is invalid and rejects the request.
[0099] The P-CSCF 114 further compares a Security-Verify header field included in the second registration request 204 with a Security-Server header field previously transmitted by the P-CSCF 114. The comparison is performed according to standardized header comparison rules. When the Security-Verify header field does not correspond to the Security-Server header field, the P-CSCF 114 determines that security negotiation information may have been modified and rejects the second registration request 204.
[0100] The P-CSCF 114 additionally verifies that a private user identity included in an Authorization header field of the second registration request 204 corresponds to a private user identity previously challenged during an authentication procedure. When the private user identities do not correspond, the P-CSCF 114 rejects the second registration request 204.
[0101] When all verification procedures at the P-CSCF 114 are successful, the P-CSCF 114 removes the Security-Client header field and the Security-Verify header field from the second registration request 204, retains an indication that the second registration request 204 is integrity-protected, and forwards the second registration request 204 toward a serving-call session control S-CSCF 126 via an interrogating-call session control function I-CSCF 124.
[0102] Upon receipt of the forwarded second registration request 204, the S-CSCF 126 verifies that an authentication timer associated with the authentication challenge has not expired, verifies that a Call-ID included in the second registration request 204 matches a Call-ID associated with the authentication challenge, and verifies that an integrity-protected indication is present.
[0103] The S-CSCF 126 computes an expected authentication response based on authentication vector information and compares the computed expected authentication response with an authentication response value included in the Authorization header field of the second registration request 204. When the authentication response values correspond, authentication is determined to be successful.
[0104] When authentication is successful, the S-CSCF 126 performs registration procedures including interaction with a home subscriber server to obtain user profile information, binding one or more public user identities to a contact address associated with the UE 112, and determining a registration duration based on network policy and requested expiration values.
[0105] The S-CSCF 126 generates a success response indicating successful registration, the success response including registration state information comprising one or more contact addresses with associated expiration values, one or more public user identities associated with the UE 112, routing information for subsequent signaling, and charging information. The success response is forwarded toward the UE 112 via the I-CSCF 124 and the P-CSCF 114.
[0106] Upon receiving the success response, the P-CSCF 114 converts the temporary IPsec security associations into established security associations and assigns a security association lifetime based on a registration lifetime. The P-CSCF 114 stores routing information associated with the registration and transmits the success response to the UE 112 protected by the established security associations. The UE 112 converts temporary security associations into established security associations, stores routing information for subsequent signaling, and determines that registration of one or more public user identities has been successfully completed for a corresponding registration duration.
[0107] When verification or authentication fails at any stage, an error response is generated in place of the success response. Upon receipt of an error response indicating registration failure, the UE 112 deletes the temporary security associations and refrains from retransmitting another registration request until a retry condition is satisfied or a retry interval has elapsed.
[0108] At a completion state following successful registration, the UE 112 and the P-CSCF 114 maintain established security associations that are used to protect subsequent session initiation protocol signaling exchanged between the UE 112 and the P-CSCF 114, thereby providing authentication, integrity protection, confidentiality protection when enabled, replay protection, and protection against man-in-the-middle attacks.
[0109] Apparatus and Computer-Readable Medium
[0110] FIG. 3 shows an exemplary apparatus 300 according to embodiments of the disclosure. The apparatus 300 can be configured to perform various functions in accordance with one or more embodiments or examples described herein. Thus, the apparatus 300 can provide means for implementation of techniques, processes, functions, components, and systems described herein. For example, the apparatus 300 can be used to implement the UE 112 or the network entities 114, 122, 124, 126, and 128 in various embodiments and examples described herein.
[0111] The apparatus 300 can include a general purpose processor or specially designed circuits to implement various functions, components, or processes described herein in various embodiments. The apparatus 300 can include processing circuitry 310 and a memory 320. The apparatus 300 can further include a radio frequency (RF) module 330 and an antenna array 340 in some implementations. The apparatus 300 can optionally include a network interface 350 in some implementations.
[0112] In various examples, the processing circuitry 310 can include circuitry configured to perform the functions and processes described herein in combination with software or without software. In various examples, the processing circuitry 310 can be a digital signal processor (DSP) , an application specific integrated circuit (ASIC) , programmable logic devices (PLDs) , field programmable gate arrays (FPGAs) , digitally enhanced circuits, or comparable device or a combination thereof.
[0113] In some other examples, the processing circuitry 310 can be a central processing unit (CPU) configured to execute program instructions to perform various functions and processes described herein. Accordingly, the memory 320 can be configured to store program instructions. The processing circuitry 310, when executing the program instructions, can perform the functions and processes. The memory 320 can further store other programs or data, such as operating systems, application programs, and the like. The memory 320 can include a read only memory (ROM) , a random access memory (RAM) , a flash memory, a solid state memory, a hard disk drive, an optical disk drive, and the like.
[0114] The RF module 330 receives a processed data signal from the processing circuitry 310 and converts the data signal to a wireless signal that is then transmitted via the antenna array 340, or vice versa. The RF module 330 can include a digital to analog converter (DAC) , an analog to digital converter (ADC) , a frequency upconverter, a frequency downconverter, filters and amplifiers for reception and transmission operations. The RF module 330 can include multi-antenna circuitry for beamforming operations. For example, the multi-antenna circuitry can include an uplink spatial filter circuit, and a downlink spatial filter circuit for shifting analog signal phases or scaling analog signal amplitudes.
[0115] The network interface 350 enables communication between the apparatus 300 and other network entities in a communication system. In some implementations, the network interface 350 may include one or more Ethernet drivers and / or controllers, fiber channel drivers, and / or controllers, or other similar network interface drivers and / or controllers to enable communications for the apparatus 300 within the communication system.
[0116] The apparatus 300 can optionally include other components, such as input and output devices, additional or signal processing circuitry, and the like. Accordingly, the apparatus 300 may be capable of performing other additional functions, such as executing application programs, and processing alternative communication protocols.
[0117] The processes and functions described herein can be implemented as a computer program which, when executed by one or more processors, can cause the one or more processors to perform the respective processes and functions. The computer program may be stored or distributed on a suitable medium, such as an optical storage medium or a solid-state medium supplied together with, or as part of, other hardware. The computer program may also be distributed in other forms, such as via the Internet or other wired or wireless telecommunication systems. For example, the computer program can be obtained and loaded into an apparatus, including obtaining the computer program through physical medium or distributed system or from a server connected to the Internet.
[0118] The computer program may be accessible from a computer-readable medium providing program instructions for use by or in connection with a computer or any instruction execution system. The computer-readable medium may include any apparatus that stores, communicates, propagates, or transports the computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable medium can be magnetic, optical, electronic, electromagnetic, infrared, or semiconductor system (or apparatus or device) or a propagation medium. The computer-readable medium may include a computer-readable non-transitory storage medium such as a semiconductor or solid state memory, magnetic tape, a removable computer diskette, a random access memory (RAM) , a read-only memory (ROM) , a magnetic disk and an optical disk, and the like. The computer-readable non-transitory storage medium can include all types of computer-readable medium, including magnetic storage medium, optical storage medium, flash medium, and solid state storage medium.
[0119] While aspects of the present disclosure have been described in conjunction with the specific embodiments thereof that are proposed as examples, alternatives, modifications, and variations to the examples may be made. Accordingly, embodiments as set forth herein are intended to be illustrative and not limiting. There are changes that may be made without departing from the scope of the claims set forth below.
Claims
1.A user equipment (UE) , comprising circuitry configured to:determine whether the UE is accessing a wireless network over a low bit rate access type, andin response to determining the UE is accessing the wireless network over a low bit rate access type, transmit a first session initiation protocol (SIP) register request message to a network entity in an IP multimedia subsystem (IMS) in the wireless network, the SIP register request message including a security-client header field that contains a predetermined minimal subset of security algorithms for integrity and confidentiality protection.2.The UE of claim 1, wherein the network entity comprises a proxy call session control function (P-CSCF) entity.3.The UE of claim 1, wherein the circuitry is further configured to:in response to determining the UE is accessing the wireless network via an access type other than the low bitrate access type, transmit a second SIP register request message including all security algorithms for integrity and confidentiality protection supported by the UE.4.The UE of claim 1, wherein the low bitrate access type is a satellite access.5.The UE of claim 4, wherein the satellite access comprises access via a geostationary (GEO) satellite.6.The UE of claim 1, wherein the low bitrate access type is a narrowband internet of things (NB-IoT) access.7.The UE of claim 1, wherein the security-client header field comprises two sets of IPsec security parameters associated with the predetermined minimal subset of security algorithms for integrity and confidentiality protection.8.The UE of claim 7, wherein in response to determining the UE is accessing the wireless network via an access type other than the low bitrate access type, the security-client header field comprises more than two sets of IPsec security parameters.9.The UE of claim 8, wherein each set of IPsec security parameters comprises an encryption algorithm parameter and an integrity algorithm parameter.10.The UE of claim 1, wherein the UE is configured to operate with thenetwork entity that supports the predetermined minimal subset of security algorithms in response to the network entity determining the UE is accessing the wireless network over the low bit rate access type.11.A method for initiating an IP Multimedia Subsystem (IMS) registration performed by a user equipment (UE) , comprising:determining whether the UE is accessing a wireless network over a low bit rate access type, andin response to determining the UE is accessing the wireless network over a low bit rate access type, transmitting a first session initiation protocol (SIP) register request message to a network entity in an IP multimedia subsystem (IMS) in the wireless network, the SIP register request message including a security-client header field that contains a predetermined minimal subset of security algorithms for integrity and confidentiality protection.12.The method of claim 11, wherein the network entity comprises a proxy call session control function (P-CSCF) entity.13.The method of claim 11, further comprising:in response to determining the UE is accessing the wireless network via an access type other than the low bitrate access type, transmitting a second SIP register request message including all security algorithms for integrity and confidentiality protection supported by the UE.14.The method of claim 11, wherein the low bitrate access type is a satellite access.15.The method of claim 14, wherein the satellite access comprises access via a geostationary (GEO) satellite.16.The method of claim 11, wherein the low bitrate access type is a narrowband internet of things (NB-IoT) access.17.The method of claim 11, wherein the security-client header field comprises two sets of IPsec security parameters associated with the predetermined minimal subset of security algorithms for integrity and confidentiality protection.18.The method of claim 17, wherein in response to determining the UE is accessing the wireless network via an access type other than the low bitrate access type, the security-client header field comprises more than two sets of IPsec security parameters.19.The method of claim 18, wherein each set of IPsec security parameters comprises an encryption algorithm parameter and an integrity algorithm parameter.20.A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method, the method comprising:determining whether a user equipment (UE) is accessing a wireless network over a low bit rate access type, andin response to determining the UE is accessing the wireless network over a low bit rate access type, transmitting a first session initiation protocol (SIP) register request message to a network entity in an IP multimedia subsystem (IMS) in the wireless network, the SIP register request message including a security-client header field that contains a predetermined minimal subset of security algorithms for integrity and confidentiality protection.