IMS Authorization Verification for Registration State Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Rel-5 networks lack an authorization solution for the registration state event package, allowing unauthorized users to access and subscribe to others' registration state information, which is not adequately addressed by the Serving Call State Control Function (S-CSCF).
Innovation Solution
A method and system where a first network entity sends a request to a second network entity, which verifies the authorization of the requester by comparing it against all non-barred public user identities and previously identified network entities, ensuring only authorized entities receive user registration state information, including those listed in the Path header field of the REGISTER request and application servers not belonging to third-party providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the Serving Call State Control Function (S-CSCF) allows any user to subscribe to registration state information without authorization verification, then the system is simple to operate and has low device complexity, but unauthorized users can access and receive status information of other users, compromising security and privacy
Solution Approach 1:
The patent applies preliminary action by performing authorization verification before allowing subscription to registration state information. The S-CSCF checks whether the subscriber is authorized to receive registration state information of the user before establishing the subscription, preventing unauthorized access in advance rather than detecting and blocking it later
Solution Approach 2:
The patent introduces an intermediary authorization verification mechanism between the subscriber and the registration state information. The S-CSCF acts as a mediator that intercepts SUBSCRIBE requests, verifies authorization status against authorized subscribers list, and only forwards authorized requests to the user agent, thus protecting user information without requiring changes to user devices
2Reliability
If the S-CSCF implements comprehensive authorization verification by comparing against all non-barred public user identities, previously identified network entities in Path header field, and application servers, then unauthorized access is prevented, but the verification process becomes more complex and time-consuming
Solution Approach 1:
The system performs preliminary authorization verification by maintaining a pre-established list of authorized subscribers. During the subscription process, the S-CSCF simply checks whether the requesting entity appears in this pre-computed authorized list, rather than performing complex real-time verification against all possible user identities and network entities
Solution Approach 2:
The authorized subscribers list is automatically maintained and updated by the system itself during registration and network entity identification processes. The S-CSCF autonomously manages the authorization data without requiring external intervention, reducing operational complexity while maintaining comprehensive authorization coverage
Data Source
AI summary
The present invention is directed to a method and system for authorizing access to information of a user. The system includes a first network entity and a second network entity. The first network entity sends a request for information of a user to the second network entity. The second network entity receives the request for information of the user, verifies that the first network entity is authorized to receive the requested information, and generates a response authorizing the request if the first network entity is authorized to receive the information. The verifying may include comparing the first network entity against all non-barred public user identities of the user, comparing the first network entity against all network entities identified in a previous request, and comparing the first network entity against all application servers not belonging to third-party providers outside a network to which the user is connected.


