IMS Call Processing via Enterprise Authentication for Trusted Caller Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In IP multimedia subsystem (IMS) communications, the trustworthiness of information related to a calling user is low when calling from an enterprise to an external user, leading to potential identity spoofing and privacy concerns.

Innovation Solution

A call processing method involving a network authentication server and an enterprise authentication server establishes a trustworthy security association to authenticate the calling user and enterprise, ensuring the information sent to the called user is reliable by using a TLS secure connection and pre-configured data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the calling user sends information related to the calling user to the called user directly in IMS communications, then the calling process is simple and fast, but the trustworthiness of the information is low and identity spoofing can occur

Engineering Contradiction:
Improvetrustworthiness of calling user informationVSAvoidcomplexity of authentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the calling user and the called user. The authentication server receives calling user information, verifies it against authenticated information stored in the database, and only allows transmission of verified information to the called user. This mediator resolves the contradiction by ensuring trustworthiness through verification while maintaining relatively simple call flow procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication by pre-storing authenticated information about calling users in a database before actual call occurrences. When a call is made, the system retrieves and verifies this pre-prepared authentication data rather than performing complex real-time verification. This preliminary action ensures reliability while keeping the actual call processing simple and fast.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication verification is performed in real-time during calls, then the trustworthiness of information is improved, but the call processing latency increases

Engineering Contradiction:
Improvetrustworthiness of calling user informationVSAvoidcall processing latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication verification in advance and stores the authenticated information in a database before actual calls occur. During call processing, the system simply retrieves this pre-verified information and compares it with the calling user's provided information, rather than performing full authentication in real-time. This eliminates time-consuming real-time verification while maintaining high reliability through pre-performed checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates copies of authenticated calling user information and stores them in the database for quick retrieval during calls. Instead of performing complex authentication operations during each call, the system uses these pre-created copies for rapid verification. This copying approach maintains trustworthiness through verification while dramatically reducing call processing latency by avoiding repeated complex authentication operations.

Inventive Principle:
Principle #26Copying

3Reliability

If the calling user opens an account in the operator network, then the authentication capability is improved, but the time to market is slow and privacy information is exposed

Engineering Contradiction:
Improveauthentication capabilityVSAvoidtime to market
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces an authentication server as an intermediary that handles authentication verification between the calling user and the operator network. The calling user only needs to provide basic information to their own enterprise's authentication server, which then verifies this information and communicates with the operator network. This intermediary approach provides strong authentication capability without requiring the calling user to open accounts in multiple operator networks, thus reducing time to market and limiting privacy exposure to only the necessary minimum information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4247032B1Call processing method, related device and communication system
Publication Date: 2025.10.01 HUAWEI TECH CO LTD
  • EP4247032B1 patent drawingFigure 1
  • EP4247032B1 patent drawingFigure 2
  • EP4247032B1 patent drawingFigure 3

AI summary

Embodiments of the present invention provide a call processing method, a related device, and a communications system. It can be ensured that when a calling device calls a called device, identity information of a calling user displayed when the called device rings and/or information of an enterprise to which the calling user belongs is trustworthy. The method includes: A network authentication server receives a call request message from a calling device, where the call request message includes a first user identity of a calling user and a call authentication identifier; the network authentication server sends a call authentication request to an enterprise authentication server corresponding to the first user identity, where the call authentication request includes the call authentication identifier; the network authentication server receives a call authentication success indication from the enterprise authentication server, where the call authentication success indication indicates that authentication succeeds; and the network authentication server sends target data to a called device, where the target data includes identity information of the calling user and/or information of an enterprise to which the calling user belongs.