IMS Authentication via Signing Server Identity Headers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems face challenges in authenticating and authorizing calling parties using third-party specific identities, particularly in IP Multimedia Subsystems (IMS) networks, leading to issues such as fraudulent robocalls and managing individual subscriptions for employees in organizations.
Innovation Solution
A system and method that involves registering calling parties with an IMS originating network, determining whether to invoke a signing server for secondary authentication and authorization (A&A) based on authorization, adding an identity header to the call invite request, and validating it through a verification server to ensure the call is established with the intended party.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods are used in IMS networks, then the system is simple to operate, but it cannot effectively prevent fraudulent robocalls and lacks support for third-party specific identities
Solution Approach 1:
The patent introduces a signing server as an intermediary component between the calling party and the IMS network. This signing server performs secondary authentication and authorization by verifying calling party identities and adding identity headers to call invite requests. The intermediary signing server enhances authentication reliability without requiring fundamental changes to the existing IMS network architecture, thus resolving the contradiction between improved security and system complexity.
2Ease of operation
If individual subscriptions are managed for each employee, then authentication is straightforward, but it increases operational complexity and cost for organizations
Solution Approach 1:
The patent enables a single organizational subscription to serve multiple employees by introducing the concept of third-party specific identities. The signing server allows any registered employee to authenticate using organizational credentials without requiring individual subscription accounts. This universal authentication mechanism eliminates the need to manage numerous individual subscriptions while maintaining ease of operation for end users.
3Adaptability or versatility
If third-party specific identities are supported, then organizational subscription management is improved, but additional authentication mechanisms increase system complexity
Solution Approach 1:
The patent implements preliminary authentication and authorization actions through the signing server before calls are routed through the IMS network. The signing server pre-verify calling party identities and attach identity headers to requests, performing authentication work in advance. This preliminary action enables support for diverse third-party identities while containing complexity within a dedicated preprocessing component rather than throughout the entire system.
Data Source
AI summary
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Specifically, the disclosure related to a system and method for authenticating and authorizing a calling party by an IP Multimedia Subsystem (IMS) network. In particular, the present disclosure provides a unique mechanism implemented at the HSS for providing parameter provisioning service by exposing related application programming interface (API) to the third party for creating the group data information with all the necessary details like list of IMPUs for which authentication and authorization is needed to use a first node identities assigned by the first node. The group data information is further utilized by IMS originating network for invoking a signing server for performing secondary A&A for the calling party. The method further includes invoking a verification sever for validation of the call invite request by IMS terminating network based on the presence of identity header added by signing server. Further, based on a receipt of a validation status response from the verification server, the call invite is forwarded to the called party for the establishment of the call between the calling party and the called party. Thus, the disclosed mechanism ensures that the called party receives a call from the intended user.


