IMS Authentication Locking via S-CSCF and HSS Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IP Multimedia Subsystems, malicious users can send multiple authentication requests to determine another user's password, which existing systems fail to effectively address.

Innovation Solution

A method and apparatus where a Serving Call Session Control Function (S-CSCF) locks a user after a predetermined number of failed authentication attempts, sending a locking signal to the Home Subscriber Server (HSS) to reject further authentication challenges, and unlocks the user upon receipt of an unlock signal, either from the HSS or a locking timer expiration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the system allows multiple authentication requests from users, then user accessibility and service availability are improved, but security vulnerability increases due to potential password enumeration attacks

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing a locking mechanism that prevents malicious users from sending multiple authentication requests. When a user exceeds the predetermined number of failed authentication attempts, the S-CSCF sends a locking signal to the HSS, which then rejects further authentication challenges from that user. This proactive prevention stops password enumeration attacks before they can overwhelm the system.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback through the locking and unlocking mechanism. The HSS receives feedback about authentication failures from the S-CSCF and responds by locking the user's authentication challenges. The system provides feedback to operators through the HSS, which can unlock users when appropriate, creating a closed-loop security management system.

Inventive Principle:
Principle #23Feedback

2Object-affected harmful factors

If the system implements strict authentication locking, then security against malicious users is improved, but legitimate user access may be restricted

Engineering Contradiction:
Improvesecurity against malicious usersVSAvoidlegitimate user access
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent applies dynamics by making the locking state changeable. The locking mechanism is not permanent; operators can dynamically unlock users through the HSS when legitimate access is needed. This dynamic state allows the system to adapt between security mode (locked) and accessibility mode (unlocked) based on operational requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The HSS serves as an intermediary between the S-CSCF and the user authentication process. It receives locking signals from the S-CSCF, manages the locking state, and can issue unlocking signals to restore user access. This intermediary role allows for centralized control of the locking mechanism, enabling operators to distinguish between malicious users and legitimate users who need access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system processes multiple authentication requests sequentially, then authentication thoroughness is improved, but system processing time and load increase

Engineering Contradiction:
Improveauthentication thoroughnessVSAvoidsystem processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The locking mechanism prevents the system from processing excessive authentication requests by malicious users. By blocking further authentication challenges after a predetermined number of failures, the system avoids the time cost of processing numerous invalid authentication attempts while maintaining thorough authentication for legitimate users.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent extracts the authentication request processing from the main system flow by introducing a separate locking mechanism at the HSS. This extracted mechanism handles the decision-making about whether to process authentication requests, separating the security control function from the authentication processing function and reducing system load.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2449743B1Method and apparatus for use in an IP multimedia subsystem
Publication Date: 2016.09.07 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2449743B1 patent drawingFigure 1
  • EP2449743B1 patent drawingFigure 2
  • EP2449743B1 patent drawingFigure 3

AI summary

A method is provided for use in an IP Multimedia Subsystem, IMS, in which a Serving 5 Call Session Control Function, S-CSCF, of the IMS cooperates with a Home Subscriber Server, HSS, of the IMS, to lock a user following a predetermined number of failed authentications of the user at the S-CSCF and/or to unlock that user thereafter, with any request received from the user at a node of the IMS where the lock is in effect and requiring an authentication challenge being caused by the node to be rejected. In one example, a locking signal is sent from the S-CSCF to the HSS, following the predetermined number of failed authentications, to indicate to the HSS that the user should be locked at the HSS. The locking signal could be carried by a Server Assignment Request, SAR, message. In another example, the user is unlocked at the S-CSCF in response to receipt of an unlock signal sent from the HSS to the S-CSCF. The unlock signal could be carried by a Registration Termination Request, RTR, message.