IMS Authentication Segmentation for Multiple Public Identities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IMS authentication methods do not allow for separate authentication of different individual IMS public user identities with the same or different IMS private user identities, which is a limitation in applications like MCPTT where different users need to access the same device without compromising security and identity confidentiality.
Innovation Solution
The solution involves enhancing IMS registration messages to include indications for double authentication, using both in-band and out-of-band signaling methods to verify public user identities, and incorporating keying based on public user identities to ensure secure and separate authentication of private and public identities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional IMS authentication is used, then authentication of private user identity is achieved, but separate authentication of multiple public user identities is not possible
Solution Approach 1:
The patent segments the authentication process into two distinct phases: first authenticating the private user identity, then separately authenticating each public user identity. This segmentation allows multiple public identities to be independently verified against the single authenticated private identity, resolving the contradiction between authentication flexibility and identity security.
Solution Approach 2:
The patent performs preliminary authentication of the private user identity before allowing any public user identities to be authenticated. This preliminary action establishes a trusted base that enables subsequent public identity authentications to be both flexible and secure, as each public identity is verified against the already-authenticated private identity.
2Adaptability or versatility
If multiple public identities are authenticated with the same device, then user access flexibility is improved, but identity confidentiality may be compromised
Solution Approach 1:
The patent introduces the private user identity as an intermediary that mediates between multiple public user identities and the network. The private identity acts as a confidential bridge that allows multiple public identities to be authenticated without exposing the relationships between them, thus maintaining identity confidentiality while enabling flexible device access.
Solution Approach 2:
The patent applies different authentication treatments to different identity types: the private user identity is authenticated once with full security measures, while each public user identity is authenticated separately with appropriate verification. This local quality approach ensures that the most sensitive identity (private) receives the highest level of protection while still enabling flexible public identity usage.
3Reliability
If separate authentication for each public identity is implemented, then identity security is improved, but authentication complexity increases
Solution Approach 1:
The patent performs preliminary authentication of the private user identity once, establishing a trusted foundation. This preliminary action reduces subsequent complexity because all public identity authentications can reference the already-verified private identity, rather than requiring completely independent authentication processes for each public identity.
Solution Approach 2:
The patent segments the authentication process into distinct, manageable phases: private identity authentication followed by separate public identity authentications. This segmentation organizes the complexity into clear steps, making the overall process more manageable and easier to implement despite the multiple authentication requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method and UE for registering with a third network node using IMS, the method creating a tunnel; authenticating a first public identity associated with the UE to the first network node; receiving configuration information with a second private identifier and a second public user identifier, and registering with a third network node using the second private identifier and the second public user identifier. Further, a method and first network node configured for authentication between a UE and a third network node using IMS, the method establishing a tunnel; authenticating a first public identity of the UE; receiving a configuration information message from the UE including a network identifier for a network the UE is registered on; obtaining, from a second network node, a second private identifier and second public user identifier; and providing the second private identifier and second public user identifier to the UE.