Authentication Gateway for IMS Service Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the IMS system, non-IMS ASs have to authenticate each IMS user equipment accessing a non-IMS service, which degrades the service processing efficiency and requires negotiation of authentication mechanisms, leading to potential security and reliability issues due to data leakage.
Innovation Solution
An authentication system with an authentication gateway that forwards connection requests from IMS user equipment, generates and verifies random numbers to ensure authentication, thereby allowing the AS to provide non-IMS services without direct negotiation with the IMS user equipment, storing authentication data securely in the gateway rather than in each AS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If non-IMS AS directly authenticates each IMS user equipment, then authentication can be performed, but service processing efficiency degrades and security risks increase due to data leakage
Solution Approach 1:
The patent introduces an authentication gateway as an intermediary component between non-IMS AS and IMS user equipment. The authentication gateway centralizes authentication processing, generating and verifying random numbers uniformly for all authentication requests. This eliminates the need for each non-IMS AS to directly handle authentication, thereby improving service processing efficiency while maintaining security through centralized control and preventing data leakage across multiple distributed AS instances.
2Adaptability or versatility
If each non-IMS AS performs direct authentication with IMS user equipment, then authentication functionality is provided, but device complexity increases due to negotiation requirements
Solution Approach 1:
The authentication gateway serves as a universal authentication component that handles all authentication requests from different non-IMS AS to IMS user equipment using a standardized process. It generates random numbers, verifies responses, and provides uniform authentication functionality across multiple service types and AS instances. This multi-functional approach eliminates the need for each AS to implement and negotiate complex authentication mechanisms individually, thereby reducing device complexity while maintaining adaptability.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
An authentication system, method and device are provided in the present application. The authentication system includes an Application Server (AS) for providing non Internet protocol Multimedia Subsystem (IMS) service, an authentication gateway and an IMS terminal. The AS forwards a connection request message sent by the IMS terminal to said authentication gateway, the authentication gateway sends a obtained first random number to said IMS terminal through the AS, the IMS terminal generates a first Response (RES) value according to the first random number and sends the generated first RES value to the authentication gateway through the AS, and if the received first response value and an obtained Expected Response (XRES) value is found coincident after being compared by the authentication gateway, the authentication gateway determines that the authentication to the IMS terminal is passed, and indicates the AS to provide non IMS service for the IMS terminal. By using the technical solutions of the present application, solved is the problem existed in prior art that non IMS AS needs to authenticate each of IMS terminals respectively for obtaining non IMS service and thus reducing the service processing efficiency of the AS.