VoIP Authentication via EAP-SIM and HLR Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current VoIP systems require prior registration and cannot seamlessly integrate voice services over WiFi hotspots for GSM subscribers, as they lack a method to link WiFi authentication with VoIP service authorization, leading to limitations in service access and billing.
Innovation Solution
A VoIP telephone communication system that allows GSM, 2G, 3G, or 4G mobile operators to provide VoIP services without prior registration by using an authentication server connected to the HLR, which authenticates terminals via EAP protocols, generating a temporary identity including IP address, MSISDN, and access point IP, enabling secure and transparent access to VoIP services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If prior registration on a dedicated VoIP server is required, then service security and billing control are improved, but service accessibility and ease of operation deteriorate
Solution Approach 1:
The system performs preliminary authentication through EAP-SIM protocol during WiFi connection establishment, before the user needs to access VoIP services. The authentication server pre- validates the user identity using SIM card credentials, and this authentication result is reused for VoIP service authorization, eliminating the need for separate pre-registration on VoIP servers.
Solution Approach 2:
The authentication server acts as an intermediary between the WiFi access system and the VoIP service system. It receives authentication requests from the access point, validates them against the HLR database, and provides authorization decisions for both network access and VoIP service usage, thereby linking the two services through a single authentication mechanism.
2Reliability
If separate authentication for VoIP service is implemented, then service security is improved, but system complexity and number of authentication steps increase
Solution Approach 1:
The system merges the authentication processes for WiFi network access and VoIP service authorization into a single EAP-SIM authentication operation. The authentication server combines both authentication functions, so that one successful authentication grants both network access and VoIP service rights, eliminating the need for separate authentication systems.
Solution Approach 2:
The EAP-SIM authentication mechanism is designed to be universal, serving multiple functions: it authenticates users for WiFi network access, authorizes VoIP service usage, and enables billing identification. This single authentication protocol handles multiple service authorization tasks that would otherwise require separate authentication systems.
3Ease of operation
If EAP-SIM protocol is used for WiFi authentication only, then network access control is improved, but VoIP service authorization capability deteriorates
Solution Approach 1:
The authentication server implements a feedback mechanism where the result of EAP-SIM authentication is fed back to determine VoIP service authorization. The server receives the authentication outcome from the access point and uses this feedback to automatically grant or deny VoIP service access, creating a linked authorization system without requiring separate authentication.
Solution Approach 2:
The system dynamically adapts the EAP-SIM authentication outcome for different service authorizations. The same authentication result is flexibly used to control both network access and VoIP service rights, allowing the system to adjust service permissions based on the authentication state without requiring separate static authentication mechanisms.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
VoIP telephone communication system whereby the operator's network applies a communication procedure, the Requester terminal (M) for access to the VoIP service automatically contacts the server (SR) to be authenticated and then obtains an address (IP) from DHCP, then it contacts the VoIP server which verifies the identity of the Requester (M) and registers it to provide the VoIP service.