PKI Certificate Authentication for IMS Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current telecommunication systems face challenges in authenticating communication devices effectively to prevent counterfeit devices from accessing services, particularly in integrating packet-switched and circuit-switched networks while ensuring secure encrypted communications.

Innovation Solution

The implementation of a method using Public Key Infrastructure (PKI) certificates for authentication, where communication devices register with a system, receive and transmit public keys, and engage in encrypted communications, leveraging an Internet Protocol Multimedia Subsystem (IMS) network architecture that integrates packet-switched and circuit-switched networks, with a Certificate Authority authenticating devices and notifying the system of valid certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in telecommunication systems, then device registration is straightforward, but counterfeit devices can easily access services without proper verification

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication actions by verifying PKI certificates during the device registration process before allowing service access. The Home Subscriber Server (HSS) authenticates the communication device using the PKI certificate presented during registration, ensuring that only legitimate devices are registered in the system before they can access any services.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using PKI certificates as a trusted third-party verification system. The certificate authority acts as an intermediary that issues cryptographic proofs of device legitimacy, allowing the HSS to verify device authenticity without direct physical inspection or complex manual verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If PKI certificate authentication is implemented, then counterfeit devices are prevented from accessing services, but the authentication and registration process becomes more complex

Engineering Contradiction:
Improvedevice authentication reliabilityVSAvoidregistration process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The communication device performs self-service authentication by automatically presenting its PKI certificate to the HSS during the registration process. The device itself handles the cryptographic verification without requiring manual intervention from operators or additional verification steps, making the process automated and relatively simple despite the cryptographic complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces mechanical or manual authentication methods with cryptographic substitution. Instead of physical device inspection, manual verification, or hardware-based authentication mechanisms, the system uses mathematical cryptography through PKI certificates to automatically verify device legitimacy, substituting complex mathematical operations for simpler physical verification processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If encrypted communications are required for all device interactions, then security is enhanced, but communication overhead and processing requirements increase

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication device energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies encryption selectively rather than universally. Encrypted communications using PKI certificates are implemented specifically for authentication-critical interactions between the device and HSS, while other non-sensitive communications may use less resource-intensive protocols. This local application of encryption maintains security where needed without unnecessarily increasing energy consumption for all communications.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9385863B2System and method for authenticating a communication device
Publication Date: 2016.07.05 AT&T INTELLECTUAL PROPERTY I L P
  • US9385863B2 patent drawing
  • US9385863B2 patent drawing
  • US9385863B2 patent drawing

AI summary

A system that incorporates teachings of the present disclosure may include, for example, a communication device having a controller to transmit to a communication system a PKI certificate, and engage in encrypted communications responsive to receiving a public key from the communication system. The communication system can have a plurality of network elements that integrate operations of a circuit-switched communication network and a packet-switched communication network. Other embodiments are disclosed.