Sharing IP-SEC Resources Between Terminal and SIM Card
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IMS systems restrict SIM card applications from utilizing IMS channels due to encryption and authentication mechanisms, preventing functionalities like mobile payments during voice conversations, and require significant network infrastructure adjustments to support additional IP-SEC channels.
Innovation Solution
Implementing a method to share IP-SEC connection resources between the terminal and SIM card using a proxy server or IP packet serialization, allowing SIM card applications to access IMS services without increasing network IP-SEC channels by using a proxy server as an interface or a discovery service for security parameters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SIM card applications are authorized to establish a new independent security association with the IMS network, then application security access is improved, but network infrastructure resources and capacity requirements increase
Solution Approach 1:
The patent merges the security association resources by allowing the terminal to share the existing IP-SEC channel established for voice communications with SIM card applications. Instead of creating separate independent security associations, the SIM card applications utilize the same security context and encrypted channel that the terminal already maintains with the IMS network, thereby combining security resources efficiently.
Solution Approach 2:
The terminal's existing IP-SEC security association is made multi-functional by enabling it to serve both traditional voice communications and SIM card applications simultaneously. The security context established for terminal-IMS communication is extended to cover application-IMS interactions, allowing a single security association to fulfill multiple functions without requiring additional dedicated security channels.
2Quantity of substance
If SIM card applications use the terminal's encrypted IP-SEC channel, then network resource usage is optimized, but application authentication capability deteriorates
Solution Approach 1:
The patent segments the authentication process into two distinct phases: first, the terminal performs mutual authentication with the IMS network and establishes the IP-SEC channel; second, the SIM card application authenticates with the IMS server through the already-established secure channel using application-specific credentials. This segmentation allows the terminal's resource-efficient channel sharing while preserving the application's independent authentication capability.
Solution Approach 2:
The terminal performs preliminary authentication with the IMS network before SIM card applications need to access IMS services. The security association and encrypted channel are established in advance by the terminal, creating a pre-configured secure pathway that subsequent SIM card applications can utilize without repeating the authentication process, thus maintaining both resource efficiency and authentication capability.
Data Source
AI summary
The invention relates to a method for establishing a secured link between an authentication card of a subscriber and a telecommunication network, the card being connected to a mobile terminal, wherein the method includes the steps of establishing a secure link between the terminal and an IMS network; and sharing the resources of the secure link between the terminal and the card.

