Policy Control Node Identity Verification for IMS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security architectures for IMS, such as those described in 3GPP TR 33.878, are inadequate for early IMS implementations, particularly in handling IPv4-based systems, leading to potential attacks and increased load on the HSS due to the introduction of an idle timer, which can result in resource conflicts and unnecessary information transmission over the Gi interface.

Innovation Solution

A system where packet data support nodes send mobile user station identity information over a first interface to a charging and/or policy handling node, which verifies whether the request for bearer services and service sessions originate from the same user station, using identity information like MSISDN, IMSI, and IP addresses, thereby reducing the need for additional nodes and minimizing the impact of idle timers on IP address allocation and release.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an idle timer is introduced to protect against attacks in early IMS implementations, then security is improved, but the load on the HSS increases and resource conflicts occur

Engineering Contradiction:
ImprovesecurityVSAvoidload on HSS
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a verification node that acts as an intermediary between the HSS and other network elements. This node verifies user identities and IP addresses locally, preventing direct attacks on the HSS while eliminating the need for idle timers. The intermediary validates requests by checking against stored subscriber information, thereby protecting the HSS from excessive load and resource conflicts.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity verification is performed at multiple nodes, then security against attacks is improved, but the device complexity increases

Engineering Contradiction:
Improvesecurity against attacksVSAvoidnumber of nodes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality by enabling existing network nodes to perform multiple roles. The verification node can function as both a policy control element and an authentication verifier, while GGSNs and SGSNs maintain their core functions while also participating in identity verification. This approach enhances security without requiring a complete overhaul of the network architecture or adding excessive new nodes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If all user identity information is transmitted over the Gi interface, then verification accuracy is improved, but information loss occurs due to idle timer constraints

Engineering Contradiction:
Improveverification accuracyVSAvoidinformation transmission completeness
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies preliminary action by pre-fetching and storing user identity information (MSISDN, IP addresses, subscriber profiles) at the verification node before actual verification is needed. This allows the system to perform comprehensive identity verification without relying on idle timers to hold information in transit. The verification node has immediate access to all necessary subscriber data, ensuring both verification accuracy and information completeness.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7843860B2Arrangement, nodes and a method relating to services access over a communication system
Publication Date: 2010.11.30 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7843860B2 patent drawing
  • US7843860B2 patent drawing
  • US7843860B2 patent drawing

AI summary

The present invention relates to an arrangement in a communications system participating in user station (UE; 1) service request and/or access procedures and comprising a number of packet data support nodes (10), a number of charging and/or policy handling nodes (30) and a number of application functions (20) handling mobility management and call control of mobile user stations requesting and/or accessing services. The packet data support node(s) (10) comprise(s) means adapted to send first mobile user station identity related information over a first interface (Gx,Gy; Gx/Gy) to a charging and/or policy handling node (30), at reception of a request for bearer services from a mobile user station (1). The application function(s) (20) comprise(s) means for, at reception of a request for a service session (SIP) from a mobile user station (1), sending second mobile user station identity related information to the charging and/or policy handling node (30), over a second interface (Rx,Rx/Gq). The policy and/or charging handling node (30) comprises verification means (32) adapted to establish whether the request for a bearer service to the packet data support node (10) and the request for a service session to the application function (20) (AF; P/S/I-CSCF) originate from one and the same mobile user station (1).