IMS Call Processing via Enterprise Authentication for Trusted Caller Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IP multimedia subsystem (IMS) communications, the trustworthiness of information related to a calling user is low when calling from an enterprise to an external user, leading to potential identity spoofing and privacy concerns.
Innovation Solution
A call processing method involving a network authentication server and an enterprise authentication server establishes a trustworthy security association to authenticate the calling user and enterprise, ensuring the information sent to the called user is reliable by using a TLS secure connection and pre-configured data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the calling user sends information related to the calling user to the called user directly in IMS communications, then the calling process is simple and fast, but the trustworthiness of the information is low and identity spoofing can occur
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the calling user and the called user. The authentication server receives calling user information, verifies it against authenticated information stored in the database, and only allows transmission of verified information to the called user. This mediator resolves the contradiction by ensuring trustworthiness through verification while maintaining relatively simple call flow procedures.
Solution Approach 2:
The patent implements preliminary authentication by pre-storing authenticated information about calling users in a database before actual call occurrences. When a call is made, the system retrieves and verifies this pre-prepared authentication data rather than performing complex real-time verification. This preliminary action ensures reliability while keeping the actual call processing simple and fast.
2Reliability
If authentication verification is performed in real-time during calls, then the trustworthiness of information is improved, but the call processing latency increases
Solution Approach 1:
The system performs authentication verification in advance and stores the authenticated information in a database before actual calls occur. During call processing, the system simply retrieves this pre-verified information and compares it with the calling user's provided information, rather than performing full authentication in real-time. This eliminates time-consuming real-time verification while maintaining high reliability through pre-performed checks.
Solution Approach 2:
The patent creates copies of authenticated calling user information and stores them in the database for quick retrieval during calls. Instead of performing complex authentication operations during each call, the system uses these pre-created copies for rapid verification. This copying approach maintains trustworthiness through verification while dramatically reducing call processing latency by avoiding repeated complex authentication operations.
3Reliability
If the calling user opens an account in the operator network, then the authentication capability is improved, but the time to market is slow and privacy information is exposed
Solution Approach 1:
The patent introduces an authentication server as an intermediary that handles authentication verification between the calling user and the operator network. The calling user only needs to provide basic information to their own enterprise's authentication server, which then verifies this information and communicates with the operator network. This intermediary approach provides strong authentication capability without requiring the calling user to open accounts in multiple operator networks, thus reducing time to market and limiting privacy exposure to only the necessary minimum information.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention provide a call processing method, a related device, and a communications system. It can be ensured that when a calling device calls a called device, identity information of a calling user displayed when the called device rings and/or information of an enterprise to which the calling user belongs is trustworthy. The method includes: A network authentication server receives a call request message from a calling device, where the call request message includes a first user identity of a calling user and a call authentication identifier; the network authentication server sends a call authentication request to an enterprise authentication server corresponding to the first user identity, where the call authentication request includes the call authentication identifier; the network authentication server receives a call authentication success indication from the enterprise authentication server, where the call authentication success indication indicates that authentication succeeds; and the network authentication server sends target data to a called device, where the target data includes identity information of the calling user and/or information of an enterprise to which the calling user belongs.