Authentication Gateway for IMS Service Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the IMS system, non-IMS ASs have to authenticate each IMS user equipment accessing a non-IMS service, which degrades the service processing efficiency and requires negotiation of authentication mechanisms, leading to potential security and reliability issues due to data leakage.

Innovation Solution

An authentication system with an authentication gateway that forwards connection requests from IMS user equipment, generates and verifies random numbers to ensure authentication, thereby allowing the AS to provide non-IMS services without direct negotiation with the IMS user equipment, storing authentication data securely in the gateway rather than in each AS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If non-IMS AS directly authenticates each IMS user equipment, then authentication can be performed, but service processing efficiency degrades and security risks increase due to data leakage

Engineering Contradiction:
Improveauthentication securityVSAvoidservice processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an authentication gateway as an intermediary component between non-IMS AS and IMS user equipment. The authentication gateway centralizes authentication processing, generating and verifying random numbers uniformly for all authentication requests. This eliminates the need for each non-IMS AS to directly handle authentication, thereby improving service processing efficiency while maintaining security through centralized control and preventing data leakage across multiple distributed AS instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If each non-IMS AS performs direct authentication with IMS user equipment, then authentication functionality is provided, but device complexity increases due to negotiation requirements

Engineering Contradiction:
Improveauthentication functionalityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authentication gateway serves as a universal authentication component that handles all authentication requests from different non-IMS AS to IMS user equipment using a standardized process. It generates random numbers, verifies responses, and provides uniform authentication functionality across multiple service types and AS instances. This multi-functional approach eliminates the need for each AS to implement and negotiate complex authentication mechanisms individually, thereby reducing device complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2506615B1Authentication system, method and device
Publication Date: 2019.07.24 CHINA MOBILE COMM GRP CO LTD
  • EP2506615B1 patent drawingFigure 1
  • EP2506615B1 patent drawingFigure 2
  • EP2506615B1 patent drawingFigure 3~4

AI summary

An authentication system, method and device are provided in the present application. The authentication system includes an Application Server (AS) for providing non Internet protocol Multimedia Subsystem (IMS) service, an authentication gateway and an IMS terminal. The AS forwards a connection request message sent by the IMS terminal to said authentication gateway, the authentication gateway sends a obtained first random number to said IMS terminal through the AS, the IMS terminal generates a first Response (RES) value according to the first random number and sends the generated first RES value to the authentication gateway through the AS, and if the received first response value and an obtained Expected Response (XRES) value is found coincident after being compared by the authentication gateway, the authentication gateway determines that the authentication to the IMS terminal is passed, and indicates the AS to provide non IMS service for the IMS terminal. By using the technical solutions of the present application, solved is the problem existed in prior art that non IMS AS needs to authenticate each of IMS terminals respectively for obtaining non IMS service and thus reducing the service processing efficiency of the AS.