IMS User Registration Device Authentication via HSS Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IMS user registration methods cannot control the devices used by users, compromising the security of enterprise networks as users can log in from various terminals and multiple users can access the same terminal, leading to unauthorized access.

Innovation Solution

The Home Subscriber Server (HSS) manages user equipment registration by determining attribute identifiers such as IMSI, IMEI, and IMS identifiers, generating a verification code, and comparing it with the user equipment's response to ensure only authorized devices access the IMS system, thereby enhancing access management and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the IMS system allows users to register from any terminal without device control, then user accessibility and ease of operation are improved, but network security and access control deteriorate

Engineering Contradiction:
Improveuser accessibilityVSAvoidnetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces device identification parameters (IMEI, IMSI) and generates verification codes based on these parameters. The HSS changes the authentication approach from solely user-based to combined user-device-based authentication by modifying the authentication parameters to include device-specific identifiers, thereby enabling security control without compromising user accessibility

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces an intermediary verification mechanism where the HSS acts as a mediator between the user equipment and the IMS network. The HSS generates verification codes based on device attributes and user credentials, and the S-CSCF forwards these verification requests, creating an intermediary layer that enables security verification while maintaining the existing registration flow

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple users can access the same terminal without restriction, then system versatility and adaptability are improved, but network security and access control deteriorate

Engineering Contradiction:
Improvesystem flexibilityVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent modifies the authentication parameters to include both user identifiers (IMSI) and device identifiers (IMEI). By changing the authentication parameters to include device-specific information, the system can distinguish between different users accessing the same terminal, enabling proper access control while maintaining the ability to support multiple users on different authorized devices

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary verification of device attributes and user credentials before allowing registration. The HSS generates verification codes in advance based on the user's IMSI and the device's IMEI, and this verification is performed before the user is granted access to the IMS network, ensuring that only authorized user-device combinations can register

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3726795B1IMS user registration method and device
Publication Date: 2023.05.31 DATANG MOBILE COMM EQUIP CO LTD
  • EP3726795B1 patent drawingFigure 1
  • EP3726795B1 patent drawingFigure 2
  • EP3726795B1 patent drawingFigure 3

AI summary

Disclosed are an IMS user registration method and device. The method comprises: after an HSS receives a registration request of a user terminal having no authentication data, acquiring configuration information of the user terminal; obtaining an authentication verification code ResponseHSS by using a random number and an attribute identifier of the user terminal, wherein the attribute identifier comprises an IMSI, an IMEI and an IMS identifier; sending the random number to the user terminal, and receiving a response verification code Response fed back by the user terminal; and determining whether the Response is the same as the ResponseHSS, and if so, sending the registration request to an application server to carry out registration of the user terminal. The technical problem in the prior art of greatly affecting the security of an enterprise network due to the fact that a device used by an IMS user cannot be controlled is solved.