IMS Contact Information Access Control via S-CSCF Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IP Multimedia Subsystem (IMS) lacks a mechanism to control user access and modification of contact information associated with different private user identities, posing a security risk, especially when less secure authentication methods are used or in open access networks.
Innovation Solution
Implementing a contact information access policy within the Serving Call/Session Control Function to define and enforce the conditions under which users can view, modify, or delete contact information associated with private user identities, using authentication mechanisms, location, and service profiles to restrict access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If IMS allows users to register multiple private user identities with different authentication methods, then user accessibility and versatility are improved, but security control and information protection deteriorate
Solution Approach 1:
The patent segments contact information access control by private user identity, creating distinct access policies for each identity. The system divides the user base into separate groups based on their authentication methods and applies individualized access control policies, allowing fine-grained security management while maintaining overall system versatility.
Solution Approach 2:
The patent implements local quality by assigning different access control characteristics to different private user identities. Each identity receives customized access policies based on its authentication method and security requirements, rather than applying a uniform access control model across all users.
2Ease of operation
If IMS provides unrestricted access to contact information for all registered users, then ease of operation is improved, but information security and data protection worsen
Solution Approach 1:
The patent introduces the Serving Call/Session Control Function as an intermediary between users and contact information. This intermediary component evaluates access requests against defined policies before granting access, thereby maintaining ease of operation for authorized users while blocking unauthorized access attempts.
Solution Approach 2:
The system implements feedback mechanisms where the Serving Call/Session Control Function continuously monitors access requests and provides feedback by allowing or denying access based on policy evaluation. This enables the system to maintain security while preserving user convenience for authorized operations.
3Reliability
If IMS uses strong authentication mechanisms for all user registrations, then security control is improved, but device complexity and implementation requirements worsen
Solution Approach 1:
The patent applies parameter changes by varying authentication requirements based on the specific private user identity and its associated security needs. The system adjusts authentication parameters dynamically, applying stronger mechanisms where necessary and simpler methods where appropriate, thereby balancing security with implementation complexity.
Data Source
Figure 1
Figure 2~3
Figure 4a~4b
AI summary
A method of controlling user access to contact information associated with public user identities (IMPUs) registered in respect of the user's subscription within an IP Multimedia Subsystem. The method comprises installing into a Serving Call/Session Control Function assigned to the user, one or more contact information access policies, the contact information access policy or policies defining if and under what circumstances the user can view or delete contact information. Upon a request by the user to view and/or modify said contact information, the Serving Call/Session Control Function evaluates and enforces these contact information policies.