Early IMS Security Identity Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Early IMS Security mechanisms limit users to a single Implicit Registration Set (IRS) derived from a single IMSI, restricting the ability to register multiple distinct identities and services, such as work and personal identities, which are not independently manageable.
Innovation Solution
Enhancing terminal capabilities to derive multiple private user identities (IMPIs) from a single IMSI, each with its own IRS and associated public identities (IMPUs), allowing independent registration and management of these identities across different access networks and interfaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single IMSI is used to derive identities in Early IMS Security, then security is simplified and device complexity is reduced, but the ability to register multiple distinct identities and services is limited
Solution Approach 1:
The patent segments the single IMSI into multiple distinct IMPIs (Private User Identities) by deriving different identities through multiple hash iterations. Each IMPI can be independently registered and managed, allowing users to have multiple distinct identities (e.g., work and personal) while still using a single IMSI stored on the SIM card. This segmentation resolves the contradiction by enabling multiple identities without requiring multiple IMSIs or complex terminal capabilities.
Solution Approach 2:
The patent changes parameters of the identity derivation process by varying the number of hash iterations (e.g., first hash iteration for first IMPI, second hash iteration for second IMPI) and using different salt values for each derivation. This allows a single IMSI to generate multiple distinct IMPIs with different security properties, enabling versatile identity registration while maintaining simple device storage requirements.
2Adaptability or versatility
If multiple IMPIs are derived from a single IMSI using different hash iterations, then multiple distinct identities can be registered independently, but the complexity of the identity management process increases
Solution Approach 1:
The identity management process is segmented into distinct derivation steps, where each IMPI is derived through a specific number of hash iterations from the same IMSI. The terminal stores only the single IMSI and derives different IMPIs on-demand by controlling the hash iteration count. This segmentation enables independent registration and management of multiple identities while keeping device storage simple.
Solution Approach 2:
The patent introduces a controlled intermediary process (the terminal's identity derivation function) that mediates between the single stored IMSI and multiple required IMPIs. By using a deterministic derivation function with controllable parameters (hash iteration count, salt values), the terminal can generate multiple distinct identities without storing multiple IMSIs, simplifying both storage and management complexity.
3Adaptability or versatility
If traditional IMS authentication is used with multiple IMSIs, then multiple identities can be registered, but device complexity and security management become more difficult
Solution Approach 1:
The patent makes the single IMSI multi-functional by enabling it to serve as the source for multiple distinct IMPIs through controlled hash derivation. Instead of requiring one IMSI per identity (traditional approach), the universal IMSI can derive any number of IMPIs by varying derivation parameters. This universality enables multiple identity registrations while reducing device complexity from storing multiple IMSIs to storing just one.
Solution Approach 2:
The patent changes the approach from storing multiple static IMSIs to deriving multiple dynamic IMPIs from a single IMSI by altering derivation parameters (hash iteration count, salt values). This parameter-based differentiation allows the same input (IMSI) to produce multiple distinct outputs (IMPIs), enabling versatile identity management with simplified device storage and security.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for providing Early IMS Security in a network is provided. In registering a 5 terminal on a telecommunications network, a plurality of IMPIs are derived from the IMSI of the terminal's user. Some or all of these IMPIs are registered with the network. Each IMPI has its own IRS containing its own IMPUs, enabling different identities of the user to be registered with the network (10).