IMS Gateway Extending Trust to Third-Party Ecosystems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IMS-based service delivery faces inefficiencies due to the need for custom development of clients to interoperate with the IMS core network, limiting the number of users who can access these services to only trusted subscribers of the service provider.
Innovation Solution
Extending the trust relationship to allow generic clients, such as WebRTC clients, to authenticate with third-party ecosystems like GMAIL, FACEBOOK, or YAHOO!, enabling IMS services to be exposed to a broader user base by using a gateway that authenticates credentials with these domains, thereby bypassing traditional IMS authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If custom IMS clients are developed to interoperate with the IMS core network, then service reliability and security are improved, but device complexity and development time increase
Solution Approach 1:
The patent introduces a gateway as an intermediary component that sits between the IMS core network and external clients. This gateway handles authentication and protocol translation, allowing generic clients to access IMS services without requiring custom IMS-specific client development. The gateway mediates between the trusted IMS network and untrusted external clients, maintaining security while reducing client complexity.
2Reliability
If custom IMS clients are developed for each service provider, then service security is improved, but time to market and development effort increase
Solution Approach 1:
The patent creates a universal gateway that can serve multiple service providers and multiple types of clients simultaneously. This single gateway implementation provides authentication and protocol translation services for various IMS services (VoIP, video conferencing, messaging) and multiple service providers, eliminating the need to develop separate custom clients for each service. The gateway's multi-functional design reduces development time while maintaining security through centralized authentication mechanisms.
3Reliability
If traditional IMS authentication processes are used, then service security is maintained, but user accessibility is limited to trusted subscribers only
Solution Approach 1:
The gateway acts as a mediator that extends the trusted IMS authentication domain to untrusted external clients. It performs authentication for users from third-party ecosystems (GMAIL, FACEBOOK, YAHOO!) and translates their credentials into forms acceptable by the IMS core network. This allows the IMS network to maintain its security model while expanding access to a broader user base beyond traditional trusted subscribers.
4Ease of operation
If generic clients like WebRTC are used to access IMS services, then ease of operation and user base expansion are improved, but authentication complexity with third-party ecosystems increases
Solution Approach 1:
The gateway implements self-service authentication mechanisms by automatically handling credential verification with third-party ecosystems. When a user provides credentials from services like GMAIL or FACEBOOK, the gateway autonomously verifies these credentials against the respective third-party domains and obtains authentication tokens. This self-service approach simplifies the user experience while managing authentication complexity within the gateway itself.
Data Source
AI summary
Systems and methods for extending and re-using an IP multimedia subsystem (IMS) to extend the trust relationship from a closed group of customers of wireless service providers to users of other ecosystems (e.g., GMAIL, FACEBOOK, or YAHOO!) for IMS services are disclosed. Some embodiments include receiving a request from an initiating device to establish a service connection between the initiating device and an endpoint through an Internet Protocol Multimedia Subsystem (IMS) session. The request may include third-party domain credentials (e.g., maintained by a third-party domain) associated with an end-user. The third-party domain credentials can be extracted from the request. Communications with the third-party domain can be used to verify the third-party domain credentials. The IMS session can be established between the initiating device and the endpoint upon verification of the third-party domain credentials.


