Dual IMS Authentication for Shared Device Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IMS networks lack effective methods to monitor and control which users are authorized to use communication devices, particularly in public safety organizations where devices are shared among multiple individuals.

Innovation Solution

Implementing a dual authentication process within the IMS network that authenticates both the communication device and the user through device authentication information and user-specific credentials, such as passwords, during registration, session initiation, and session termination.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If only device authentication is implemented in IMS network, then device registration is simplified, but user access control is insufficient

Engineering Contradiction:
Improvedevice registrationVSAvoiduser access control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into two independent components: device authentication (verifying the communication device itself) and user authentication (verifying the individual user). This segmentation allows each authentication type to be handled separately through distinct credential verification, enabling simplified device registration while simultaneously providing robust user access control for shared devices in public safety organizations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If dual authentication (device and user) is implemented, then user access control is improved, but authentication complexity increases

Engineering Contradiction:
Improveuser access controlVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By segmenting authentication into separate device and user components, the system manages complexity through modular design. Each authentication type uses its own credential verification process, allowing the network to enforce both device validity and user authorization without creating a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Device authentication is performed as a preliminary action before user authentication. The device must first be validated and registered with the IMS network, establishing a baseline trust level. Only after successful device authentication can user credentials be verified, which streamlines the overall process by eliminating redundant verification steps.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If device sharing is allowed in public safety organizations, then resource utilization is improved, but monitoring and control of authorized users becomes difficult

Engineering Contradiction:
Improvedevice sharingVSAvoiduser authorization monitoring
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The dual authentication system provides continuous feedback to the IMS network about which users are authorized to use which devices. By requiring user credentials to be verified alongside device authentication, the network maintains an active record of authorized user-device pairings, enabling real-time monitoring and control of device sharing across public safety organizations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9032483B2Authenticating a communication device and a user of the communication device in an IMS network
Publication Date: 2015.05.12 ALCATEL LUCENT SA
  • US9032483B2 patent drawing
  • US9032483B2 patent drawing
  • US9032483B2 patent drawing

AI summary

IMS networks and methods are disclosed for authenticating a communication device and a user of the communication device. When a communication device attempts to register with an IMS network, the IMS network receives a register message from the device that includes device authentication information, such as a public or private identifier for the device. The IMS network processes the device authentication information to authenticate the communication device. The IMS network also receives user authentication information from the device, such as a password. The IMS network processes the user authentication information to authenticate the user of the device. The device and the user are both authenticated by the IMS network. Authentication of the user may also occur when originating a session or terminating a session over the IMS network with the device.