Policy Control Node Identity Verification for IMS Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security architectures for IMS, such as those described in 3GPP TR 33.878, are inadequate for early IMS implementations, particularly in handling IPv4-based systems, leading to potential attacks and increased load on the HSS due to the introduction of an idle timer, which can result in resource conflicts and unnecessary information transmission over the Gi interface.
Innovation Solution
A system where packet data support nodes send mobile user station identity information over a first interface to a charging and/or policy handling node, which verifies whether the request for bearer services and service sessions originate from the same user station, using identity information like MSISDN, IMSI, and IP addresses, thereby reducing the need for additional nodes and minimizing the impact of idle timers on IP address allocation and release.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an idle timer is introduced to protect against attacks in early IMS implementations, then security is improved, but the load on the HSS increases and resource conflicts occur
Solution Approach 1:
The patent introduces a verification node that acts as an intermediary between the HSS and other network elements. This node verifies user identities and IP addresses locally, preventing direct attacks on the HSS while eliminating the need for idle timers. The intermediary validates requests by checking against stored subscriber information, thereby protecting the HSS from excessive load and resource conflicts.
2Reliability
If identity verification is performed at multiple nodes, then security against attacks is improved, but the device complexity increases
Solution Approach 1:
The patent implements multi-functionality by enabling existing network nodes to perform multiple roles. The verification node can function as both a policy control element and an authentication verifier, while GGSNs and SGSNs maintain their core functions while also participating in identity verification. This approach enhances security without requiring a complete overhaul of the network architecture or adding excessive new nodes.
3Measurement precision
If all user identity information is transmitted over the Gi interface, then verification accuracy is improved, but information loss occurs due to idle timer constraints
Solution Approach 1:
The patent applies preliminary action by pre-fetching and storing user identity information (MSISDN, IP addresses, subscriber profiles) at the verification node before actual verification is needed. This allows the system to perform comprehensive identity verification without relying on idle timers to hold information in transit. The verification node has immediate access to all necessary subscriber data, ensuring both verification accuracy and information completeness.
Data Source
AI summary
The present invention relates to an arrangement in a communications system participating in user station (UE; 1) service request and/or access procedures and comprising a number of packet data support nodes (10), a number of charging and/or policy handling nodes (30) and a number of application functions (20) handling mobility management and call control of mobile user stations requesting and/or accessing services. The packet data support node(s) (10) comprise(s) means adapted to send first mobile user station identity related information over a first interface (Gx,Gy; Gx/Gy) to a charging and/or policy handling node (30), at reception of a request for bearer services from a mobile user station (1). The application function(s) (20) comprise(s) means for, at reception of a request for a service session (SIP) from a mobile user station (1), sending second mobile user station identity related information to the charging and/or policy handling node (30), over a second interface (Rx,Rx/Gq). The policy and/or charging handling node (30) comprises verification means (32) adapted to establish whether the request for a bearer service to the packet data support node (10) and the request for a service session to the application function (20) (AF; P/S/I-CSCF) originate from one and the same mobile user station (1).


