IMS-Based Remote Access for Local Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for remote access to local networks lack security and require physical presence within the network for device pairing, and there is no trust model for authenticating remote devices accessing the network from outside.

Innovation Solution

Implementing an IMS-based remote access solution that configures capabilities and credentials in the IMS core for remote access, authorizes users through an IMS identity-based Access Control List, and establishes secure connections using IMS messaging and authentication mechanisms, allowing remote devices to access local networks securely without physical presence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If UPnP Remote Access Architecture is used for remote device access, then device connectivity is enabled, but security and authentication are lacking

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity and authentication
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an IMS core network as an intermediary between the remote device and local network. The IMS network acts as a trusted mediator that performs authentication, authorization, and credential distribution, resolving the security deficiency of direct UPnP remote access while maintaining connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent separates the authentication and access functions into distinct components: IMS identity-based authentication, ACL-based authorization, and credential-based connection establishment. This segmentation allows each function to be optimized independently, with security handled by IMS mechanisms and access control by ACLs.

Inventive Principle:
Principle #1Segmentation

2Reliability

If physical presence is required for device pairing, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidremote access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical requirement of physical presence with electronic IMS-based authentication mechanisms. Users can be authenticated remotely using IMS identities and credentials distributed through the IMS core, eliminating the need for physical device presence while maintaining security through trusted IMS authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent performs authentication and credential distribution in advance through IMS network provisioning. Users are pre-authenticated and pre-authorized via IMS mechanisms before actual remote access is needed, allowing seamless connection establishment without requiring physical presence during the access event.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If IMS-based authentication is implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improvetrust model and authenticationVSAvoidauthentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal IMS authentication infrastructure that already serves multiple purposes (voice, messaging, data services). The same IMS identity and authentication mechanisms used for general service access are reused for remote network access authentication, avoiding the need for separate authentication systems and reducing overall complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables devices to self-authenticate using IMS identities and credentials automatically provided by the IMS core. The authentication process is handled transparently by the IMS network without requiring complex manual configuration or additional authentication infrastructure at the device level.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2255496B1Method and apparatus for remote access to a local network
Publication Date: 2016.02.10 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2255496B1 patent drawingFigure 1~2
  • EP2255496B1 patent drawingFigure 3~4
  • EP2255496B1 patent drawingFigure 5~6

AI summary

A method and apparatus for enabling remote access to a local gateway (302) of a local network from a remote device (300) located outside the local network. Capabilities and credentials of the remote device and of the local gateway are configured independently in an IMS core (304) for the remote access. One or more users are also authorised for remote access to the local network by adding an IMS identity of each authorised user to an IMS based ACL (Access Control List). An access request to the local gateway from the remote device will be accepted if the IMS identity of the remote device user is present in the IMS based ACL. A remote access connection can then be established by means of the configured capabilities and credentials of the remote device and the local gateway.