IMS Authentication Skip via P-CSCF Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the context of IP multimedia subsystem (IMS) centralized services, the lack of effective identity protection mechanisms allows malicious users to abuse special IMS private user identities, leading to unchecked access and administrative challenges in authentication and authorization processes, particularly in roaming scenarios.

Innovation Solution

A method and apparatus that transmit and process registration messages with integrity indication information, where affirmative integrity is indicated by an 'integrity-protected' flag set to 'yes', allowing authentication to be skipped for legitimate users and rejecting unauthorized requests, ensuring only IMSC can send integrity-protected requests, thereby preventing misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the PANI header with network-provided parameter is used to indicate authentication status from IMSC to S-CSCF, then authentication can be skipped for legitimate users, but the mechanism can be abused by malicious users setting the parameter without proper verification

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an intermediary verification mechanism where the P-CSCF acts as a mediator between IMSC and S-CSCF. The P-CSCF validates the integrity of the network-provided parameter before forwarding the registration request to S-CSCF, preventing malicious users from abusing the authentication skip mechanism while maintaining efficiency for legitimate users

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a feedback mechanism where the P-CSCF receives integrity information from the IMSC, verifies it against stored integrity data, and provides feedback to the S-CSCF about whether the network-provided parameter should be trusted. This feedback loop ensures security while maintaining authentication efficiency

Inventive Principle:
Principle #23Feedback

2Reliability

If a database of all IMSC servers is maintained for verification, then authentication can be securely skipped only for registered IMSCs, but this causes unacceptable administrative effort and database synchronization problems

Engineering Contradiction:
Improveauthentication securityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the integrity verification functionality from the S-CSCF and places it in the P-CSCF, which maintains a local integrity information database. This extraction eliminates the need for the S-CSCF to maintain a comprehensive IMSC database, reducing administrative complexity while maintaining security through localized verification

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the authentication verification process into two parts: the P-CSCF handles integrity verification using a local database of integrity information, while the S-CSCF focuses on authentication decision-making. This segmentation reduces the administrative burden on any single entity and eliminates synchronization problems across multiple domains

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If all IMSC servers in foreign CS roaming domains are stored in the database, then roaming authentication can be properly verified, but this causes unacceptable administrative efforts and database synchronization issues whenever IMSC servers are added or removed

Engineering Contradiction:
Improveroaming supportVSAvoiddatabase maintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent enables each P-CSCF to maintain its own local integrity information database for IMSC servers in its domain. When an IMSC server is added or removed, only the local P-CSCF needs to update its database, not all P-CSCFs in roaming domains. This self-service approach maintains roaming support while eliminating the need for complex inter-domain database synchronization

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10581822B2Methods, apparatuses, system and computer program product for supporting legacy P-CSCF to indicate the S-CSCF to skip authentication
Publication Date: 2020.03.03 NOKIA SOLUTIONS & NETWORKS OY
  • US10581822B2 patent drawing
  • US10581822B2 patent drawing
  • US10581822B2 patent drawing

AI summary

It is disclosed a method including transmitting, after successful registration of a terminal at a network entity, a registration message including terminal identity information and integrity indication information indicating affirmative integrity of the terminal identity information; and a method including processing, after reception of the registration message, the received registration message based on the terminal identity information and the integrity indication information such that, i) if the integrity is indicated affirmative, an authentication procedure of the terminal is skipped, or, ii) if the integrity is indicated negative, the received registration message is rejected without provisioning of key information related to registration of the terminal.