IMS Data Channel Certificate Management for Network Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The IMS data channel's security mechanism, using SCTP over DTLS over UDP, requires a security certificate, which if autonomously generated or installed by a terminal, leads to loss of network control and monitoring capabilities, affecting communication reliability.
Innovation Solution
A method and device for reliable IMS data channel communication, involving a certificate management server that receives an encrypted ticket and identification information from a terminal, verifies the application with a key management server, and issues a data channel application certificate, ensuring secure and reliable communication without manual certificate installation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a security certificate is autonomously generated or installed by a terminal, then the terminal can perform IMS data channel communication, but the network loses capabilities of controlling and monitoring communication content
Solution Approach 1:
The patent introduces a certificate management server as an intermediary between the terminal and the key management server. This server receives encrypted tickets from terminals, forwards them to the key management server for verification, and issues certificates only after successful verification. This intermediary mechanism allows terminals to obtain certificates without autonomous generation, while the network maintains full control and monitoring capabilities through the certificate issuance process.
2Ease of operation
If a security certificate is autonomously generated or installed by a terminal, then the terminal can perform IMS data channel communication, but communication reliability is affected
Solution Approach 1:
The patent implements a feedback mechanism where the certificate management server receives encrypted tickets from terminals, sends them to the key management server for verification, and only issues certificates after successful verification. This feedback loop ensures that only verified terminals receive certificates, maintaining communication reliability while simplifying terminal operations.
3Reliability
If network control capability is maintained for IMS data channel communication, then communication reliability is improved, but the complexity of certificate management increases
Solution Approach 1:
The patent segments the certificate management function into separate components: a certificate management server that handles ticket reception and certificate issuance, and a key management server that performs verification. This segmentation allows the network to maintain control and reliability while distributing complexity across specialized servers, making the overall system more manageable.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
This application provides an IMS data channel based communication method and a device. The method may include: A certificate management server receives an encrypted ticket and identification information of a first application from an AS. The certificate management server sends the encrypted ticket and the identification information of the first application to a KMS. The certificate management server receives a first key. The certificate management server sends a data channel application certificate corresponding to the first key to the AS, where the data channel application certificate is used by the first application to perform an IMS data channel service with a second application of a second terminal. In this application, the certificate management server issues the reliable data channel application certificate to the first terminal, and an IMS network can learn of the data channel application certificate, to avoid manual installation/replacement of a third-party (provided by a non-communication network) certificate and use of an unreliable self-signed certificate by the first terminal, thereby providing reliable IMS data channel communication.