Unified GBA Authentication for Dual IMS VoLTE and RCS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current industry specifications do not provide a clear solution for XCAP authentication when dual IMS registration is used, particularly for VoLTE and RCS clients sharing the same IMS identity, leading to unclear infrastructure and authentication methods for XCAP traffic.

Innovation Solution

Implementing a method where VoLTE and RCS functions on a device share a single set of GBA-based shared secrets, such as Bootstrapping Transaction Identifiers (B-TIDs), for authentication using Generic Bootstrapping Architecture (GBA) and Generic Authentication Architecture (GAA), regardless of whether they are in the same or different stacks, ensuring unified authentication across dual IMS registrations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dual IMS registration is used for VoLTE and RCS clients, then service functionality and versatility are improved, but authentication infrastructure complexity and clarity deteriorate

Engineering Contradiction:
Improveservice functionalityVSAvoidauthentication infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication infrastructure for VoLTE and RCS by implementing a shared GBA infrastructure where both service clients use the same Bootstrapping Server Function (BSF) and Authentication Proxy (AP). This consolidation reduces infrastructure complexity while maintaining dual registration functionality, as both clients authenticate through the unified GBA framework using shared security contexts.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The GBA infrastructure is designed with universal applicability where the BSF and AP serve multiple service clients (VoLTE and RCS) simultaneously. The shared security context and authentication mechanism provide multi-functional support, allowing the same authentication infrastructure to handle different service types without requiring separate authentication paths.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication infrastructures are used for VoLTE and RCS, then authentication security is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines separate authentication infrastructures into a unified GBA framework where VoLTE and RCS clients share the same BSF, AP, and security context management. This merging maintains security through the robust GBA protocol while reducing system complexity by eliminating redundant authentication components and shared secret management overhead.

Inventive Principle:
Principle #5Merging (Combining)

3Device complexity

If shared GBA infrastructure is used for dual IMS registration, then device complexity is reduced, but authentication clarity and specification completeness worsen

Engineering Contradiction:
Improvedevice complexityVSAvoidauthentication clarity
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent segments the authentication process into distinct phases and roles: the BSF handles bootstrapping and security context establishment, the AP handles authentication of service clients, and the service clients (VoLTE/RCS) handle service-specific operations. This segmentation provides clear operational boundaries and roles, improving specification completeness despite using a shared infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Authentication Proxy (AP) serves as an intermediary between the shared GBA infrastructure and multiple service clients. It mediates authentication requests, manages shared security contexts, and provides clear interface definitions, thereby improving authentication clarity while enabling infrastructure sharing.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3427503B1Systems and methods for using GBA for services used by multiple functions on the same device
Publication Date: 2021.12.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3427503B1 patent drawingFigure 1
  • EP3427503B1 patent drawingFigure 2
  • EP3427503B1 patent drawingFigure 3

AI summary

This specification presents methods and apparatus in a device and a network node implementing a Bootstrapping Server Function, BSF, for enabling multiple service functions/clients in the device sharing a common public identity and each performing its own registration to one or more (IMS) core network, to use a common bootstrapping of application security based on the Generic Bootstrapping Architecture, GBA / Generic Authentication Architecture, GAA, infrastructure. Therefore, when using Extensible Markup Language, XML, Configuration Access Protocol, XCAP, or the likes, the multiple service functions in the device use the same authentication method for all XCAP traffic or the likes, such as GBA/GAA but enabling it to use the same key sets (e.g., same B-TID).