Unified GBA Authentication for Dual IMS VoLTE and RCS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current industry specifications do not provide a clear solution for XCAP authentication when dual IMS registration is used, particularly for VoLTE and RCS clients sharing the same IMS identity, leading to unclear infrastructure and authentication methods for XCAP traffic.
Innovation Solution
Implementing a method where VoLTE and RCS functions on a device share a single set of GBA-based shared secrets, such as Bootstrapping Transaction Identifiers (B-TIDs), for authentication using Generic Bootstrapping Architecture (GBA) and Generic Authentication Architecture (GAA), regardless of whether they are in the same or different stacks, ensuring unified authentication across dual IMS registrations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If dual IMS registration is used for VoLTE and RCS clients, then service functionality and versatility are improved, but authentication infrastructure complexity and clarity deteriorate
Solution Approach 1:
The patent merges the authentication infrastructure for VoLTE and RCS by implementing a shared GBA infrastructure where both service clients use the same Bootstrapping Server Function (BSF) and Authentication Proxy (AP). This consolidation reduces infrastructure complexity while maintaining dual registration functionality, as both clients authenticate through the unified GBA framework using shared security contexts.
Solution Approach 2:
The GBA infrastructure is designed with universal applicability where the BSF and AP serve multiple service clients (VoLTE and RCS) simultaneously. The shared security context and authentication mechanism provide multi-functional support, allowing the same authentication infrastructure to handle different service types without requiring separate authentication paths.
2Reliability
If separate authentication infrastructures are used for VoLTE and RCS, then authentication security is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent combines separate authentication infrastructures into a unified GBA framework where VoLTE and RCS clients share the same BSF, AP, and security context management. This merging maintains security through the robust GBA protocol while reducing system complexity by eliminating redundant authentication components and shared secret management overhead.
3Device complexity
If shared GBA infrastructure is used for dual IMS registration, then device complexity is reduced, but authentication clarity and specification completeness worsen
Solution Approach 1:
The patent segments the authentication process into distinct phases and roles: the BSF handles bootstrapping and security context establishment, the AP handles authentication of service clients, and the service clients (VoLTE/RCS) handle service-specific operations. This segmentation provides clear operational boundaries and roles, improving specification completeness despite using a shared infrastructure.
Solution Approach 2:
The Authentication Proxy (AP) serves as an intermediary between the shared GBA infrastructure and multiple service clients. It mediates authentication requests, manages shared security contexts, and provides clear interface definitions, thereby improving authentication clarity while enabling infrastructure sharing.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
This specification presents methods and apparatus in a device and a network node implementing a Bootstrapping Server Function, BSF, for enabling multiple service functions/clients in the device sharing a common public identity and each performing its own registration to one or more (IMS) core network, to use a common bootstrapping of application security based on the Generic Bootstrapping Architecture, GBA / Generic Authentication Architecture, GAA, infrastructure. Therefore, when using Extensible Markup Language, XML, Configuration Access Protocol, XCAP, or the likes, the multiple service functions in the device use the same authentication method for all XCAP traffic or the likes, such as GBA/GAA but enabling it to use the same key sets (e.g., same B-TID).