IMS Authentication Skip via P-CSCF Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the context of IP multimedia subsystem (IMS) centralized services, the lack of effective identity protection mechanisms allows malicious users to abuse special IMS private user identities, leading to unchecked access and administrative challenges in authentication and authorization processes, particularly in roaming scenarios.
Innovation Solution
A method and apparatus that transmit and process registration messages with integrity indication information, where affirmative integrity is indicated by an 'integrity-protected' flag set to 'yes', allowing authentication to be skipped for legitimate users and rejecting unauthorized requests, ensuring only IMSC can send integrity-protected requests, thereby preventing misuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the PANI header with network-provided parameter is used to indicate authentication status from IMSC to S-CSCF, then authentication can be skipped for legitimate users, but the mechanism can be abused by malicious users setting the parameter without proper verification
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the P-CSCF acts as a mediator between IMSC and S-CSCF. The P-CSCF validates the integrity of the network-provided parameter before forwarding the registration request to S-CSCF, preventing malicious users from abusing the authentication skip mechanism while maintaining efficiency for legitimate users
Solution Approach 2:
The patent implements a feedback mechanism where the P-CSCF receives integrity information from the IMSC, verifies it against stored integrity data, and provides feedback to the S-CSCF about whether the network-provided parameter should be trusted. This feedback loop ensures security while maintaining authentication efficiency
2Reliability
If a database of all IMSC servers is maintained for verification, then authentication can be securely skipped only for registered IMSCs, but this causes unacceptable administrative effort and database synchronization problems
Solution Approach 1:
The patent extracts the integrity verification functionality from the S-CSCF and places it in the P-CSCF, which maintains a local integrity information database. This extraction eliminates the need for the S-CSCF to maintain a comprehensive IMSC database, reducing administrative complexity while maintaining security through localized verification
Solution Approach 2:
The patent segments the authentication verification process into two parts: the P-CSCF handles integrity verification using a local database of integrity information, while the S-CSCF focuses on authentication decision-making. This segmentation reduces the administrative burden on any single entity and eliminates synchronization problems across multiple domains
3Adaptability or versatility
If all IMSC servers in foreign CS roaming domains are stored in the database, then roaming authentication can be properly verified, but this causes unacceptable administrative efforts and database synchronization issues whenever IMSC servers are added or removed
Solution Approach 1:
The patent enables each P-CSCF to maintain its own local integrity information database for IMSC servers in its domain. When an IMSC server is added or removed, only the local P-CSCF needs to update its database, not all P-CSCFs in roaming domains. This self-service approach maintains roaming support while eliminating the need for complex inter-domain database synchronization
Data Source
AI summary
It is disclosed a method including transmitting, after successful registration of a terminal at a network entity, a registration message including terminal identity information and integrity indication information indicating affirmative integrity of the terminal identity information; and a method including processing, after reception of the registration message, the received registration message based on the terminal identity information and the integrity indication information such that, i) if the integrity is indicated affirmative, an authentication procedure of the terminal is skipped, or, ii) if the integrity is indicated negative, the received registration message is rejected without provisioning of key information related to registration of the terminal.


