IMS Server Simulates Registration for Non-Registering Endpoints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IP PBXs in IMS networks cannot register with the network, preventing them from accessing IMS services and making calls, as they lack the ability to establish a security association with the P-CSCF, leading to denied service.
Innovation Solution
A method where a server in the IMS network receives a non-registration request from a non-registering endpoint, requests credentials from the HSS, transmits an authentication challenge, and authenticates the endpoint, allowing it to access IMS services without registration by simulating registration to obtain credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a non-registering endpoint (IP PBX) attempts to access IMS services, then service accessibility is improved, but security is worsened because the endpoint cannot establish a security association with the P-CSCF
Solution Approach 1:
The patent introduces a registration simulation mechanism where the server acts as an intermediary. The server simulates a registration process for the non-registering endpoint, obtaining credentials from the HSS that would normally only be available during actual registration. This simulated registration credential allows the endpoint to access services securely without requiring actual registration capability, thus resolving the contradiction between service accessibility and security.
2Reliability
If the P-CSCF blocks non-registration requests, then security is improved, but service accessibility is worsened for legitimate non-registering endpoints
Solution Approach 1:
The patent inverts the traditional approach by having the server simulate registration on behalf of the non-registering endpoint rather than requiring the endpoint to register itself. Instead of the endpoint attempting registration (which it cannot do), the server performs the registration simulation and uses the obtained credentials to authenticate the endpoint's service requests. This inversion allows legitimate non-registering endpoints to access services while maintaining security, as the authentication is performed by the trusted server.
3Reliability
If the S-CSCF challenges non-registration requests, then security is improved, but service accessibility is worsened and authentication complexity increases
Solution Approach 1:
The patent applies preliminary action by having the server perform registration simulation and obtain credentials from the HSS before the endpoint needs to access services. The credentials are obtained in advance during a simulated registration process, so when the endpoint subsequently sends service requests, the authentication is already prepared and can proceed smoothly without challenging the endpoint. This preliminary credential acquisition eliminates the need for challenging non-registration requests while maintaining security.
Data Source
AI summary
Embodiments of the present invention provide methods for providing a non-registering endpoint with non-registration services (such as the ability to make a call) in an IMS network without requiring the non-registering endpoint to register. A request for a non-registration service is received and processed by an entity in the IMS network that is configured to handle such requests. The entity requires information about the non-registering endpoint itself before it can process the request. Since the non-registering endpoint is part of the network, a Home Subscriber Server (HSS) knows some information about the non-registering endpoint, but can only provide this information to the entity if the non-registering endpoint is registered or being registered by the entity. Consequently, in embodiments, the entity makes it look like the non-registering endpoint is registering, in order for the entity to obtain the information from the HSS.


