Emergency Service Chain-of-Trust Validation for Unauthenticated Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IP-based emergency services face challenges in establishing a strong trust relationship between unassociated services and network elements, particularly in scenarios where users subscribe to independent services without network association or when roaming, leading to difficulties in providing unrestricted, seamless, and reliable end-to-end emergency connections.
Innovation Solution
The establishment of an Emergency Service Chain-of-Trust (ES CoT) method that creates a trust relationship between network components, using Public Key Infrastructure (PKI) and a web-of-trust model to validate and authenticate emergency service operations, ensuring the integrity and confidentiality of emergency communications, even in scenarios with altered or hidden control/data plane signaling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If rule based hotlining is used to restrict network access for emergency services, then network security is improved, but emergency service accessibility deteriorates for unauthenticated users
Solution Approach 1:
The patent segments network access control into multiple trust zones: authenticated users, unauthenticated emergency users, and network elements. Rule-based hotlining is applied selectively to unauthenticated emergency users to provide limited access only to emergency service destinations, while maintaining full security for other network access. This segmentation allows simultaneous achievement of security and emergency accessibility.
Solution Approach 2:
The patent introduces an intermediary trust validation mechanism that mediates between security requirements and emergency access needs. The intermediary validates emergency service requests through chain-of-trust relationships and certificates, allowing unauthenticated users to access emergency services without compromising overall network security. This intermediary layer resolves the contradiction by providing controlled access pathways.
2Reliability
If high QoS service flow establishment is implemented for emergency traffic, then emergency communication quality is improved, but network resource consumption increases
Solution Approach 1:
The patent applies high QoS service flow establishment locally only to authenticated emergency traffic and trusted emergency service communications. Non-emergency traffic and unauthenticated traffic receive standard QoS treatment. This localized application of high QoS ensures emergency communication quality while minimizing overall network resource consumption by not applying resource-intensive QoS guarantees to all traffic.
Solution Approach 2:
The patent dynamically changes QoS parameters based on traffic classification and trust validation results. For authenticated emergency traffic, QoS parameters are adjusted to provide high priority handling and guaranteed bandwidth. For other traffic, standard parameters apply. This dynamic parameter adjustment achieves high emergency communication quality while optimizing network resource utilization across all traffic types.
3Reliability
If chain-of-trust validation is performed for all emergency service requests, then trust reliability is improved, but processing time increases
Solution Approach 1:
The patent performs preliminary chain-of-trust validation by pre-establishing trust relationships and certificates between network elements before emergency services are needed. Trusted relationships are cached and validated quickly during emergency operations. This preliminary action reduces processing time during actual emergency service requests while maintaining high trust reliability through pre-validated relationships.
Solution Approach 2:
The patent applies partial chain-of-trust validation based on the specific emergency service type and user authentication status. For authenticated users, full chain-of-trust validation is performed. For unauthenticated emergency users accessing restricted services, the validation is partial or bypassed based on pre-configured emergency access policies. This selective validation approach maintains trust reliability for critical services while reducing processing time through optimized validation depth.
Data Source
AI summary
A method and apparatus for providing in a packet data telecommunication network serving one or more end terminals and/or Mobile Stations (MSs), a method for establishing, managing, modifying, and terminating an End-to-End (E2E) Emergency Service (ES) Chain-of-Trust (CoT) from an Access Serving Network (ASN) and Connectivity Service Network (CSN) to a PSAP, PSAP proxy, or PSAP (i.e. PSTN) gateway that results in the creation of a trust relationship amongst the components in the established ES CoT necessary to allow or validate the granting of any unauthenticated or unprovisioned ES network access and ES operation establishment, modification, and termination requests from amongst the components in an ES CoT to assist a particular terminal/MS or ES network component attempting to establish an ES session between the ES user agent of the terminal/MS and a serving PSAP.


