IMS Peering for Secure Cross-Domain User Identity Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems face challenges in securely transferring user identities and information across domains while providing seamless services to both internal and external parties, due to insecure connections, lack of association between user domains, limited communication modes, and information loss during message transport.

Innovation Solution

IMS peering enables secure authentication and information sharing between adjacent networks by using peering servers to map user identities and transmit authentication information, allowing sequenced applications to be invoked across domains and ensuring that user information is transmitted intact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user identity information is transmitted across domains using traditional message transport, then communication between domains is enabled, but security is compromised and information is lost during transport

Engineering Contradiction:
Improvecommunication between domainsVSAvoidsecurity and information integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a peering server as an intermediary component that mediates communication between adjacent networks. The peering server receives messages from one network, extracts and preserves user identity information, and forwards it to another network. This intermediary approach solves the contradiction by enabling cross-domain communication while maintaining security and information integrity through controlled message handling and selective information preservation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If Abrazo's twinning solution is implemented to associate mobile phone identity with enterprise identity, then user association between domains is achieved, but system complexity and cost increase due to requiring twice as many licenses

Engineering Contradiction:
Improveuser association between domainsVSAvoidsystem complexity and licensing requirements
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal peering server that can handle multiple user associations and identity mappings within a single system. Instead of requiring separate licensing for each user association as in the Abrazo solution, the peering server provides multi-functional capability to associate multiple mobile phone identities with enterprise identities, thereby reducing system complexity and licensing requirements while maintaining the ability to associate users across domains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If Session Border Controllers and transport providers strip information from messages for security or lack of knowledge, then security is improved, but useful information is lost

Engineering Contradiction:
ImprovesecurityVSAvoiduseful information in messages
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by having the peering server extract and preserve user identity information from messages before they are processed by Session Border Controllers or transport providers. By performing this extraction and preservation action in advance, the system ensures that useful information is captured and protected before any potential stripping occurs during subsequent security processing or transport, thus preventing information loss while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2299647B1Next generation integration between different domains, such as, enterprise and service provider using sequencing applications and IMS peering
Publication Date: 2017.06.14 AVAYA INC
  • EP2299647B1 patent drawingFigure 1
  • EP2299647B1 patent drawingFigure 2
  • EP2299647B1 patent drawingFigure 3

AI summary

The present invention provides mechanisms for sharing user information, including user authentication information, across communication networks and more specifically across networks separated by one or more Session Border Controllers (SBCs). The authentication of a user at one network can be leveraged by the second network to invoke one or more applications at the second network in connection with administering a communication session for the user.