IMS Contact Information Access Control via S-CSCF Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IP Multimedia Subsystem (IMS) lacks a mechanism to control user access and modification of contact information associated with different private user identities, posing a security risk, especially when less secure authentication methods are used or in open access networks.

Innovation Solution

Implementing a contact information access policy within the Serving Call/Session Control Function to define and enforce the conditions under which users can view, modify, or delete contact information associated with private user identities, using authentication mechanisms, location, and service profiles to restrict access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IMS allows users to register multiple private user identities with different authentication methods, then user accessibility and versatility are improved, but security control and information protection deteriorate

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments contact information access control by private user identity, creating distinct access policies for each identity. The system divides the user base into separate groups based on their authentication methods and applies individualized access control policies, allowing fine-grained security management while maintaining overall system versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different access control characteristics to different private user identities. Each identity receives customized access policies based on its authentication method and security requirements, rather than applying a uniform access control model across all users.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If IMS provides unrestricted access to contact information for all registered users, then ease of operation is improved, but information security and data protection worsen

Engineering Contradiction:
Improvecontact information accessVSAvoidunauthorized data access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the Serving Call/Session Control Function as an intermediary between users and contact information. This intermediary component evaluates access requests against defined policies before granting access, thereby maintaining ease of operation for authorized users while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the Serving Call/Session Control Function continuously monitors access requests and provides feedback by allowing or denying access based on policy evaluation. This enables the system to maintain security while preserving user convenience for authorized operations.

Inventive Principle:
Principle #23Feedback

3Reliability

If IMS uses strong authentication mechanisms for all user registrations, then security control is improved, but device complexity and implementation requirements worsen

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by varying authentication requirements based on the specific private user identity and its associated security needs. The system adjusts authentication parameters dynamically, applying stronger mechanisms where necessary and simpler methods where appropriate, thereby balancing security with implementation complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2250791B1Securing contact information
Publication Date: 2016.08.10 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2250791B1 patent drawingFigure 1
  • EP2250791B1 patent drawingFigure 2~3
  • EP2250791B1 patent drawingFigure 4a~4b

AI summary

A method of controlling user access to contact information associated with public user identities (IMPUs) registered in respect of the user's subscription within an IP Multimedia Subsystem. The method comprises installing into a Serving Call/Session Control Function assigned to the user, one or more contact information access policies, the contact information access policy or policies defining if and under what circumstances the user can view or delete contact information. Upon a request by the user to view and/or modify said contact information, the Serving Call/Session Control Function evaluates and enforces these contact information policies.