IMS Authentication via Signing Server Identity Headers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in authenticating and authorizing calling parties using third-party specific identities, particularly in IP Multimedia Subsystems (IMS) networks, leading to issues such as fraudulent robocalls and managing individual subscriptions for employees in organizations.

Innovation Solution

A system and method that involves registering calling parties with an IMS originating network, determining whether to invoke a signing server for secondary authentication and authorization (A&A) based on authorization, adding an identity header to the call invite request, and validating it through a verification server to ensure the call is established with the intended party.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in IMS networks, then the system is simple to operate, but it cannot effectively prevent fraudulent robocalls and lacks support for third-party specific identities

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a signing server as an intermediary component between the calling party and the IMS network. This signing server performs secondary authentication and authorization by verifying calling party identities and adding identity headers to call invite requests. The intermediary signing server enhances authentication reliability without requiring fundamental changes to the existing IMS network architecture, thus resolving the contradiction between improved security and system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If individual subscriptions are managed for each employee, then authentication is straightforward, but it increases operational complexity and cost for organizations

Engineering Contradiction:
Improvesubscription management easeVSAvoidmanagement complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent enables a single organizational subscription to serve multiple employees by introducing the concept of third-party specific identities. The signing server allows any registered employee to authenticate using organizational credentials without requiring individual subscription accounts. This universal authentication mechanism eliminates the need to manage numerous individual subscriptions while maintaining ease of operation for end users.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If third-party specific identities are supported, then organizational subscription management is improved, but additional authentication mechanisms increase system complexity

Engineering Contradiction:
Improveidentity support versatilityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication and authorization actions through the signing server before calls are routed through the IMS network. The signing server pre-verify calling party identities and attach identity headers to requests, performing authentication work in advance. This preliminary action enables support for diverse third-party identities while containing complexity within a dedicated preprocessing component rather than throughout the entire system.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250211985A1System and method for authenticating and authorizing a calling party in a wireless communication system
Publication Date: 2025.06.26 SAMSUNG ELECTRONICS CO LTD
  • US20250211985A1 patent drawing
  • US20250211985A1 patent drawing
  • US20250211985A1 patent drawing

AI summary

The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Specifically, the disclosure related to a system and method for authenticating and authorizing a calling party by an IP Multimedia Subsystem (IMS) network. In particular, the present disclosure provides a unique mechanism implemented at the HSS for providing parameter provisioning service by exposing related application programming interface (API) to the third party for creating the group data information with all the necessary details like list of IMPUs for which authentication and authorization is needed to use a first node identities assigned by the first node. The group data information is further utilized by IMS originating network for invoking a signing server for performing secondary A&A for the calling party. The method further includes invoking a verification sever for validation of the call invite request by IMS terminating network based on the presence of identity header added by signing server. Further, based on a receipt of a validation status response from the verification server, the call invite is forwarded to the called party for the establishment of the call between the calling party and the called party. Thus, the disclosed mechanism ensures that the called party receives a call from the intended user.