IMS Data Channel Certificate Management for Network Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The IMS data channel's security mechanism, using SCTP over DTLS over UDP, requires a security certificate, which if autonomously generated or installed by a terminal, leads to loss of network control and monitoring capabilities, affecting communication reliability.

Innovation Solution

A method and device for reliable IMS data channel communication, involving a certificate management server that receives an encrypted ticket and identification information from a terminal, verifies the application with a key management server, and issues a data channel application certificate, ensuring secure and reliable communication without manual certificate installation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a security certificate is autonomously generated or installed by a terminal, then the terminal can perform IMS data channel communication, but the network loses capabilities of controlling and monitoring communication content

Engineering Contradiction:
Improveterminal certificate installationVSAvoidnetwork control capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a certificate management server as an intermediary between the terminal and the key management server. This server receives encrypted tickets from terminals, forwards them to the key management server for verification, and issues certificates only after successful verification. This intermediary mechanism allows terminals to obtain certificates without autonomous generation, while the network maintains full control and monitoring capabilities through the certificate issuance process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a security certificate is autonomously generated or installed by a terminal, then the terminal can perform IMS data channel communication, but communication reliability is affected

Engineering Contradiction:
Improveterminal certificate installationVSAvoidcommunication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the certificate management server receives encrypted tickets from terminals, sends them to the key management server for verification, and only issues certificates after successful verification. This feedback loop ensures that only verified terminals receive certificates, maintaining communication reliability while simplifying terminal operations.

Inventive Principle:
Principle #23Feedback

3Reliability

If network control capability is maintained for IMS data channel communication, then communication reliability is improved, but the complexity of certificate management increases

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidcertificate management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the certificate management function into separate components: a certificate management server that handles ticket reception and certificate issuance, and a key management server that performs verification. This segmentation allows the network to maintain control and reliability while distributing complexity across specialized servers, making the overall system more manageable.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP4184821B1IMS data channel-based communication method and device
Publication Date: 2025.04.16 HUAWEI TECH CO LTD
  • EP4184821B1 patent drawingFigure 1~2
  • EP4184821B1 patent drawingFigure 3~4
  • EP4184821B1 patent drawingFigure 5

AI summary

This application provides an IMS data channel based communication method and a device. The method may include: A certificate management server receives an encrypted ticket and identification information of a first application from an AS. The certificate management server sends the encrypted ticket and the identification information of the first application to a KMS. The certificate management server receives a first key. The certificate management server sends a data channel application certificate corresponding to the first key to the AS, where the data channel application certificate is used by the first application to perform an IMS data channel service with a second application of a second terminal. In this application, the certificate management server issues the reliable data channel application certificate to the first terminal, and an IMS network can learn of the data channel application certificate, to avoid manual installation/replacement of a third-party (provided by a non-communication network) certificate and use of an unreliable self-signed certificate by the first terminal, thereby providing reliable IMS data channel communication.