UICC-less IMS Emergency Call Authentication via EAP-TLS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack a reliable mechanism for handling IMS emergency calls from UICC-less users in I-WLAN systems, as there is no defined authentication method and user ID for such users, which hinders the ability to access and continue emergency calls.

Innovation Solution

Implementing EAP-TLS authentication that skips client authentication but performs server authentication, using identities like IMEI, MAC address, or local IP address to establish a secure connection for UICC-less users, ensuring emergency calls can be reliably initiated and maintained without modifying existing WLAN infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If EAP SIM/AKA authentication is used for UICC-less users, then authentication can be performed, but no reliable mechanism exists for UICC-less users to access I-WLAN for IMS emergency calls

Engineering Contradiction:
Improveemergency call access reliabilityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the authentication parameters by switching from EAP SIM/AKA (which requires UICC) to EAP-TLS authentication. This parameter change enables UICC-less users to authenticate using device identity certificates stored in the device's secure storage, thereby resolving the contradiction between enabling emergency call access and avoiding complex authentication mechanisms.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses device identity certificates as a copy or alternative to the traditional SIM card identity. Instead of requiring the physical UICC card, the device's built-in identity credentials are used for authentication, allowing UICC-less users to access emergency services reliably.

Inventive Principle:
Principle #26Copying

2Ease of operation

If common user name and password are used for all UICC-less users, then authentication is simplified, but user identification and session continuation become unreliable

Engineering Contradiction:
Improveauthentication simplicityVSAvoiduser identification reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the user identification from the common password approach and replaces it with unique device identity certificates. Each device has its own cryptographic identity, which is extracted and used for authentication. This maintains simplicity for the user while ensuring reliable user identification through device-specific credentials.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If pseudo IMSI is used for WLAN access, then emergency call support is enabled, but session continuation is not possible

Engineering Contradiction:
Improveemergency call supportVSAvoidsession duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent introduces device identity certificates as an intermediary authentication mechanism. Instead of using temporary pseudo IMSI that cannot sustain sessions, the device certificate serves as a persistent intermediary credential that enables both initial authentication and session continuation, resolving the contradiction between emergency call support and session duration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2122983B1Support of UICC-less calls
Publication Date: 2013.12.11 NOKIA CORP
  • EP2122983B1 patent drawingFigure 1
  • EP2122983B1 patent drawingFigure 2A~2D

AI summary

The invention relates to a method comprising initiating a session from a subscriber terminal, wherein the subscriber terminal does not comprise a specific user identification module, and authenticating the session based on a temporary identification of the subscriber terminal, by using a procedure performing a server authentication and avoiding a client authentication.