IMS Trust Level Indicator for Interoperability Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IP Multimedia Subsystem (IMS) networks face challenges in handling trust levels across different access technologies and networks, leading to reduced security and increased risk of unsolicited communications, particularly when interoperating with non-3GPP networks like TISPAN and PacketCable, which have lower security mechanisms.

Innovation Solution

The introduction of a trust level indicator in SIP messages allows nodes in the IMS network to apply flexible security policies based on the trust level of the communication, enabling differentiated handling of signalling messages from various sources, including numerical or descriptive indicators that consider factors like user terminal type, encryption, and network security mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If IMS networks interoperate with non-3GPP networks (TISPAN, PacketCable) using their security mechanisms (HTTP Digest, TLS, NASS-IMS), then network interoperability and access options are improved, but security level deteriorates because these mechanisms offer lower security than IMS AKA

Engineering Contradiction:
Improvenetwork interoperabilityVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies different security policies to different network sources by introducing trust level indicators. Each network (3GPP IMS, TISPAN, PacketCable) is assigned a specific trust level based on its security mechanism capabilities. This allows the system to maintain high security for 3GPP IMS AKA traffic while still accepting interoperability traffic from non-3GPP networks with their lower-security mechanisms, thus resolving the contradiction between interoperability and security level.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent introduces dynamic security policy selection based on trust level indicators in SIP messages. Instead of applying a static security policy to all traffic, the system dynamically adjusts security handling according to the trust level of each message source. This enables the network to adapt security measures to the specific interoperability scenario, maintaining high security where possible while enabling interoperability where required.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If a single trust domain is applied to all signalling in current IMS networks, then implementation simplicity is maintained, but the ability to handle differentiated trust levels from different networks deteriorates, leading to reduced security when interconnecting with non-IMS networks

Engineering Contradiction:
Improvetrust domain structureVSAvoidsecurity handling capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single trust domain into multiple trust levels (e.g., high trust for 3GPP IMS AKA, medium trust for TISPAN NASS-IMS, low trust for HTTP Digest/TLS). This segmentation allows the system to differentiate between various network sources and apply appropriate security policies to each, resolving the contradiction between implementation simplicity and security handling capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the trust domain parameter from a single uniform trust level to a multi-level trust indicator system. Trust level indicators are embedded in SIP messages to convey the security capability of the message source. This parameter change enables the system to handle differentiated trust levels from different networks while maintaining a relatively simple implementation through standardized indicator handling.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9900347B2Handling trust in an IP multimedia subsystem communication network
Publication Date: 2018.02.20 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9900347B2 patent drawing
  • US9900347B2 patent drawing
  • US9900347B2 patent drawing

AI summary

A method and apparatus for handling trust in an IP Multimedia Subsystem network. A node in the IP Multimedia Subsystem network receives a Session Initiation Protocol message from a remote node. The message includes an indicator indicating the level of trust of a communication sent from the remote node to the IP Multimedia Subsystem node. The node can then apply a security policy to the message, the security policy being determined by the indicator.