UICC-less IMS Emergency Call Authentication via EAP-TLS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack a reliable mechanism for handling IMS emergency calls from UICC-less users in I-WLAN systems, as there is no defined authentication method and user ID for such users, which hinders the ability to access and continue emergency calls.
Innovation Solution
Implementing EAP-TLS authentication that skips client authentication but performs server authentication, using identities like IMEI, MAC address, or local IP address to establish a secure connection for UICC-less users, ensuring emergency calls can be reliably initiated and maintained without modifying existing WLAN infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EAP SIM/AKA authentication is used for UICC-less users, then authentication can be performed, but no reliable mechanism exists for UICC-less users to access I-WLAN for IMS emergency calls
Solution Approach 1:
The patent changes the authentication parameters by switching from EAP SIM/AKA (which requires UICC) to EAP-TLS authentication. This parameter change enables UICC-less users to authenticate using device identity certificates stored in the device's secure storage, thereby resolving the contradiction between enabling emergency call access and avoiding complex authentication mechanisms.
Solution Approach 2:
The patent uses device identity certificates as a copy or alternative to the traditional SIM card identity. Instead of requiring the physical UICC card, the device's built-in identity credentials are used for authentication, allowing UICC-less users to access emergency services reliably.
2Ease of operation
If common user name and password are used for all UICC-less users, then authentication is simplified, but user identification and session continuation become unreliable
Solution Approach 1:
The patent extracts the user identification from the common password approach and replaces it with unique device identity certificates. Each device has its own cryptographic identity, which is extracted and used for authentication. This maintains simplicity for the user while ensuring reliable user identification through device-specific credentials.
3Reliability
If pseudo IMSI is used for WLAN access, then emergency call support is enabled, but session continuation is not possible
Solution Approach 1:
The patent introduces device identity certificates as an intermediary authentication mechanism. Instead of using temporary pseudo IMSI that cannot sustain sessions, the device certificate serves as a persistent intermediary credential that enables both initial authentication and session continuation, resolving the contradiction between emergency call support and session duration.
Data Source
Figure 1
Figure 2A~2D
AI summary
The invention relates to a method comprising initiating a session from a subscriber terminal, wherein the subscriber terminal does not comprise a specific user identification module, and authenticating the session based on a temporary identification of the subscriber terminal, by using a procedure performing a server authentication and avoiding a client authentication.