R-UIM Authentication via IP Address Binding for IMS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Second generation R-UIM cards are not compatible with third generation wireless communication networks, leading to security vulnerabilities such as impersonation and IP spoofing attacks, as they do not support the AKA security protocol required for IMS services, preventing customers from accessing multimedia services and potentially resulting in fraudulent billing.

Innovation Solution

A method is implemented to authenticate mobile units using a first and second address, where the second address is associated with the identifier provided by the mobile unit, and the binding between the subscriber identity and allocated address is stored and verified to prevent unauthorized access, ensuring secure communication and service access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If second generation R-UIM cards are used in third generation networks, then service compatibility is improved, but security is worsened due to lack of AKA protocol support

Engineering Contradiction:
Improveservice compatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between the legacy R-UIM card (which lacks AKA protocol) and the 3G network security requirements. The system acts as a bridge by implementing address binding verification between the allocated IP address and the subscriber identity, enabling security enforcement without requiring the R-UIM to support modern authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If address binding verification is implemented, then security against impersonation and IP spoofing is improved, but system complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary address binding verification during the initial service setup phase, allocating and binding the IP address to the subscriber identity before actual service usage. This preliminary action ensures that security checks are performed once during configuration, rather than continuously during operation, thereby minimizing ongoing system complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If legacy R-UIM cards are supported in 3G networks, then customer retention is improved, but network security is worsened due to susceptibility to attacks

Engineering Contradiction:
Improvecustomer retentionVSAvoidnetwork security threats
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by proactively preventing impersonation and IP spoofing attacks through address binding verification. By checking whether the IP address used by a device matches the pre-bound subscriber identity before allowing service access, the system neutralizes security threats in advance, protecting the network from harmful factors while maintaining support for legacy cards.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS7912452B2Authenticating a removable user identity module to an internet protocol multimedia subsystem (IMS)
Publication Date: 2011.03.22 WSOU INVESTMENTS LLC
  • US7912452B2 patent drawing
  • US7912452B2 patent drawing
  • US7912452B2 patent drawing

AI summary

The present invention provides a method that may include accessing a first address and an identifier provided by a mobile unit, providing the identifier, receiving a second address associated with the identifier in response to providing the identifier, and authenticating the mobile unit based on the first and second addresses.