IMS Session Authentication with Dual Identity Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IP multimedia subsystem (IMS) authentication methods do not allow for separate authentication of different individual IMS public user identities with the same or different IMS private user identities, which is problematic for applications like mission critical push to talk (MCPTT) that require independent device authentication and user identity obscuration.
Innovation Solution
The solution involves enhancing IMS registration messages to include indications for double authentication, using in-band and out-of-band signaling mechanisms to authenticate both private and public user identities, and employing keying based on public user identities to ensure secure and independent authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional IMS authentication is used, then authentication process is simple, but different individual IMS public user identities cannot be separately authenticated with the same or different IMS private user identities
Solution Approach 1:
The authentication process is segmented into two distinct phases: traditional IMS authentication for the private user identity, and a second authentication phase for the public user identity. This segmentation allows each authentication type to be handled independently, enabling multiple public identities to be authenticated with the same private identity while maintaining clear separation of concerns.
Solution Approach 2:
The system performs preliminary authentication of the private user identity through traditional IMS authentication before enabling public user identity authentication. This preliminary action establishes a trusted base that allows subsequent public identity authentications to occur securely without requiring complete re-authentication.
2Ease of operation
If device authentication is required for security, then security is maintained, but device availability to multiple authorized users is limited
Solution Approach 1:
The identity system is segmented into private user identity (for device authentication and security) and public user identity (for user-specific services and multiple user support). This allows the device to be securely authenticated once with the private identity, while multiple authorized users can then be authenticated with their respective public identities, enabling both security and multi-user access.
Solution Approach 2:
The private user identity acts as an intermediary that bridges device authentication and user-specific authentication. By first authenticating the device with the private identity, the system establishes a secure context that then enables multiple public identities to be authenticated, serving as a mediator between security requirements and user accessibility.
Data Source
AI summary
The present disclosure describes methods and systems for establishing a Session Initiation Protocol Session. One method includes transmitting a first message requesting authentication configuration information; in response to the first message, receiving a second message that includes the authentication configuration information; transmitting a third message that includes authentication information based upon the received authentication configuration information; receiving an authentication challenge request that is formatted according to the second protocol; and in response to receiving the authentication challenge request, transmitting an authentication response to the second network node.


