Early IMS Security Identity Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Early IMS Security mechanisms limit users to a single Implicit Registration Set (IRS) derived from a single IMSI, restricting the ability to register multiple distinct identities and services, such as work and personal identities, which are not independently manageable.

Innovation Solution

Enhancing terminal capabilities to derive multiple private user identities (IMPIs) from a single IMSI, each with its own IRS and associated public identities (IMPUs), allowing independent registration and management of these identities across different access networks and interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single IMSI is used to derive identities in Early IMS Security, then security is simplified and device complexity is reduced, but the ability to register multiple distinct identities and services is limited

Engineering Contradiction:
Improveability to register multiple distinct identitiesVSAvoidterminal capability complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the single IMSI into multiple distinct IMPIs (Private User Identities) by deriving different identities through multiple hash iterations. Each IMPI can be independently registered and managed, allowing users to have multiple distinct identities (e.g., work and personal) while still using a single IMSI stored on the SIM card. This segmentation resolves the contradiction by enabling multiple identities without requiring multiple IMSIs or complex terminal capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes parameters of the identity derivation process by varying the number of hash iterations (e.g., first hash iteration for first IMPI, second hash iteration for second IMPI) and using different salt values for each derivation. This allows a single IMSI to generate multiple distinct IMPIs with different security properties, enabling versatile identity registration while maintaining simple device storage requirements.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple IMPIs are derived from a single IMSI using different hash iterations, then multiple distinct identities can be registered independently, but the complexity of the identity management process increases

Engineering Contradiction:
Improveindependent registration and management of identitiesVSAvoididentity derivation and management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The identity management process is segmented into distinct derivation steps, where each IMPI is derived through a specific number of hash iterations from the same IMSI. The terminal stores only the single IMSI and derives different IMPIs on-demand by controlling the hash iteration count. This segmentation enables independent registration and management of multiple identities while keeping device storage simple.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a controlled intermediary process (the terminal's identity derivation function) that mediates between the single stored IMSI and multiple required IMPIs. By using a deterministic derivation function with controllable parameters (hash iteration count, salt values), the terminal can generate multiple distinct identities without storing multiple IMSIs, simplifying both storage and management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If traditional IMS authentication is used with multiple IMSIs, then multiple identities can be registered, but device complexity and security management become more difficult

Engineering Contradiction:
Improvenumber of registrable identitiesVSAvoidnumber of IMSIs to store and manage
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the single IMSI multi-functional by enabling it to serve as the source for multiple distinct IMPIs through controlled hash derivation. Instead of requiring one IMSI per identity (traditional approach), the universal IMSI can derive any number of IMPIs by varying derivation parameters. This universality enables multiple identity registrations while reducing device complexity from storing multiple IMSIs to storing just one.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the approach from storing multiple static IMSIs to deriving multiple dynamic IMPIs from a single IMSI by altering derivation parameters (hash iteration count, salt values). This parameter-based differentiation allows the same input (IMSI) to produce multiple distinct outputs (IMPIs), enabling versatile identity management with simplified device storage and security.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2177074B1Method and apparatus for early IMS security
Publication Date: 2017.10.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2177074B1 patent drawingFigure 1
  • EP2177074B1 patent drawingFigure 2
  • EP2177074B1 patent drawingFigure 3

AI summary

A method for providing Early IMS Security in a network is provided. In registering a 5 terminal on a telecommunications network, a plurality of IMPIs are derived from the IMSI of the terminal's user. Some or all of these IMPIs are registered with the network. Each IMPI has its own IRS containing its own IMPUs, enabling different identities of the user to be registered with the network (10).