IMS Authentication Mode Selection for Subscriber Compatibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The core network in IMS systems cannot determine the appropriate authentication mode for subscribers after receiving a registration request, leading to incorrect rejection of legal 2G-based subscribers, as the authentication modes for 2G and 3G-based subscribers differ, resulting in poor error tolerance.

Innovation Solution

A method where the Serving-Call Session Control Function (S-CSCF) requests an authentication vector from the Home Subscriber Server (HSS) with a specific identifier, allowing the network to choose between Early-IMS-based and Full-IMS-based authentication modes based on the subscriber's capabilities and access network type, ensuring accurate authentication and access authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network applies Full-IMS-based authentication mode to all subscribers, then security function is improved, but 2G-based legal subscribers are incorrectly rejected

Engineering Contradiction:
Improvesecurity functionVSAvoidauthentication accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements dynamic authentication mode selection where the network adapts the authentication method based on the subscriber's access network type. The S-CSCF entity determines whether to apply Early-IMS-based or Full-IMS-based authentication by examining the access network type information in the registration request, enabling the system to dynamically adjust its behavior to match the subscriber's capabilities rather than using a fixed authentication mode for all users.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different authentication modes to different subscriber groups based on their access network characteristics. Instead of using a uniform authentication approach, the system tailors the authentication method to the local conditions: Early-IMS-based authentication for 2G network access and Full-IMS-based authentication for 3G network access, thereby optimizing both security and compatibility for each specific case.

Inventive Principle:
Principle #3Local quality

2Device complexity

If the network uses a unified authentication mode for all subscribers, then device complexity is reduced, but error tolerance capability deteriorates

Engineering Contradiction:
Improveauthentication processing complexityVSAvoiderror tolerance capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system dynamically selects the appropriate authentication mode based on the access network type detected during registration. The S-CSCF entity examines the registration request to determine the access network type and automatically chooses the corresponding authentication method, enabling the network to adapt its complexity level to match the subscriber's capabilities while maintaining high error tolerance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary determination of the authentication mode during the registration phase, before actual authentication takes place. By examining the access network type information in the registration request and pre-selecting the appropriate authentication mode, the system avoids authentication failures and eliminates the need for complex error handling during the authentication process itself.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the network applies Early-IMS-based authentication mode, then compatibility with 2G network is improved, but security function deteriorates

Engineering Contradiction:
Improvecompatibility with 2G networkVSAvoidsecurity function
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system dynamically adjusts the authentication mode based on the access network type. When a 2G network is detected, Early-IMS-based authentication is applied to ensure compatibility. When a 3G network is detected, Full-IMS-based authentication is applied to provide enhanced security. This dynamic adaptation allows the system to optimize both compatibility and security based on the actual network conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different authentication modes to different network environments: Early-IMS-based authentication for 2G networks where it provides adequate security and compatibility, and Full-IMS-based authentication for 3G networks where higher security is available and required. This localized approach ensures that each network type receives the most appropriate authentication method for its capabilities.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7822407B2Method for selecting the authentication manner at the network side
Publication Date: 2010.10.26 SNAPTRACK INC
  • US7822407B2 patent drawing
  • US7822407B2 patent drawing
  • US7822407B2 patent drawing

AI summary

The present invention discloses a method for a network to choose an authentication mode, wherein the key lies in that, according to the received authentication information in the authentication vector request message from S-CSCF as well as according to type of the requesting subscriber, HSS returns authentication information of the Early-IMS-based authentication vector to S-CSCF, or returns authentication information of the Full-IMS-based authentication mode to S-CSCF, or directly returns failure information to S-CSCF. If it is under the former two situations, the subscriber will be authenticated by adopting the corresponding authentication mode, and then S-CSCF will return access-allowed or access-rejected information to the subscriber according to authentication result. If it is in the latter situation, S-CSCF will directly send access-rejected information to the subscriber. By applying the present invention, the network can choose a proper authentication mode to authenticate the subscriber according to the subscriber's requirements, so that processing ability of the network is enhanced and the network is compatible with original security protocols to the fullest extent.