Sharing IP-SEC Resources Between Terminal and SIM Card

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current IMS systems restrict SIM card applications from utilizing IMS channels due to encryption and authentication mechanisms, preventing functionalities like mobile payments during voice conversations, and require significant network infrastructure adjustments to support additional IP-SEC channels.

Innovation Solution

Implementing a method to share IP-SEC connection resources between the terminal and SIM card using a proxy server or IP packet serialization, allowing SIM card applications to access IMS services without increasing network IP-SEC channels by using a proxy server as an interface or a discovery service for security parameters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SIM card applications are authorized to establish a new independent security association with the IMS network, then application security access is improved, but network infrastructure resources and capacity requirements increase

Engineering Contradiction:
Improveapplication security accessVSAvoidnetwork infrastructure resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the security association resources by allowing the terminal to share the existing IP-SEC channel established for voice communications with SIM card applications. Instead of creating separate independent security associations, the SIM card applications utilize the same security context and encrypted channel that the terminal already maintains with the IMS network, thereby combining security resources efficiently.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The terminal's existing IP-SEC security association is made multi-functional by enabling it to serve both traditional voice communications and SIM card applications simultaneously. The security context established for terminal-IMS communication is extended to cover application-IMS interactions, allowing a single security association to fulfill multiple functions without requiring additional dedicated security channels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Quantity of substance

If SIM card applications use the terminal's encrypted IP-SEC channel, then network resource usage is optimized, but application authentication capability deteriorates

Engineering Contradiction:
Improvenetwork resource usageVSAvoidapplication authentication capability
Core Design Contradiction:
Quantity of substanceVSEase of operation

Solution Approach 1:

The patent segments the authentication process into two distinct phases: first, the terminal performs mutual authentication with the IMS network and establishes the IP-SEC channel; second, the SIM card application authenticates with the IMS server through the already-established secure channel using application-specific credentials. This segmentation allows the terminal's resource-efficient channel sharing while preserving the application's independent authentication capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The terminal performs preliminary authentication with the IMS network before SIM card applications need to access IMS services. The security association and encrypted channel are established in advance by the terminal, creating a pre-configured secure pathway that subsequent SIM card applications can utilize without repeating the authentication process, thus maintaining both resource efficiency and authentication capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8788670B2Method for establishing a link between the applications of an authentication card of a subscriber and an IMS network
Publication Date: 2014.07.22 THALES DIS FRANCE SA
  • US8788670B2 patent drawing
  • US8788670B2 patent drawing

AI summary

The invention relates to a method for establishing a secured link between an authentication card of a subscriber and a telecommunication network, the card being connected to a mobile terminal, wherein the method includes the steps of establishing a secure link between the terminal and an IMS network; and sharing the resources of the secure link between the terminal and the card.