Unified Data Management Binding Information for IMS Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In telecommunication networks, especially in Non-Public Networks (NPNs) and Fifth Generation Core (5GC) environments, User Equipment (UE) may not support International Mobile Subscriber Identity (IMSI) and Authentication and Key Agreement (AKA) mechanisms, making it challenging to authenticate UEs for IMS services without extensive configuration.

Innovation Solution

The proposed method involves a Service-Based Architecture (SBA) telecommunication network, specifically using the Unified Data Management (UDM) and Home Subscriber Server (HSS) to exchange binding information, such as IP addresses and timestamps, to support UE authentication in IMS networks, even for UEs that do not support traditional AKA-based identifiers and credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional AKA-based authentication mechanisms are used in IMS networks, then security is improved, but device complexity and configuration requirements increase for UEs that do not support these mechanisms

Engineering Contradiction:
Improveauthentication securityVSAvoidUE configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The HSS acts as an intermediary between the IMS network and UEs that do not support AKA. It stores binding information linking IP addresses to user identities and provides this information to the P-CSCF, enabling authentication without requiring the UE to implement complex AKA mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The HSS is enhanced to perform multiple functions: it continues to support traditional AKA authentication while also providing binding information for UEs that do not support AKA. This allows a single network element to serve both authentication paradigms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If GIBA is used for early IMS deployments without full IMS security infrastructure, then ease of deployment is improved, but security protection against advanced threats is reduced

Engineering Contradiction:
ImproveIMS deployment easeVSAvoidsecurity protection level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The binding information is pre-stored in the HSS before authentication occurs. This preliminary setup allows the network to provide security protection even when UEs lack full AKA capability, as the binding information is already in place to verify IP address authenticity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of requiring UEs to implement complex AKA protocols, the system creates a simplified authentication path where the HSS provides binding information that serves as a substitute for full AKA verification, enabling security without copying the entire AKA mechanism.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If IP address binding is implemented in HSS for GIBA authentication, then authentication capability is improved for non-AKA devices, but network complexity increases due to additional signalling and data management

Engineering Contradiction:
Improveauthentication capabilityVSAvoidnetwork signalling complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The binding information management is merged into the existing HSS infrastructure. Rather than creating a separate system for storing and managing IP address bindings, the HSS is extended to handle both traditional subscriber data and binding information within a unified architecture.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The HSS automatically manages binding information storage, retrieval, and updates without requiring external management systems. When a UE connects, the HSS self-services by providing the appropriate binding information to the P-CSCF based on the user identity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12267674B2Method for supporting authentication of a user equipment in an internet multimedia subsystem (IMS) communication network
Publication Date: 2025.04.01 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12267674B2 patent drawing
  • US12267674B2 patent drawing
  • US12267674B2 patent drawing

AI summary

A method for supporting authentication of a User Equipment, UE, in an Internet Protocol, IP, Multimedia Subsystem, IMS, telecommunication network, by interfacing a Service Based Architecture, SBA, telecommunication network, the method including receiving, by a Unified Data Management, UDM, in the SBA telecommunication network, from a Session Management Function, SMF, in the SBA telecommunication network, binding information, wherein the binding information is used to identify the UE in the IMS telecommunication network; receiving, by the UDM in the SBA telecommunication network, from a Home Subscriber Server, in the IMS telecommunication network, a request for providing the binding information, and providing, by the UDM in the SBA telecommunication network, to the HSS in the IMS telecommunication network the binding information, thereby supporting authentication of the UE. Complementary methods and corresponding nodes are also presented herein.