IP Library Granted Patent US 9,032,483
Granted Patent B2
US 9,032,483 · App. 11/694,873 · Granted May 12, 2015

Authenticating a communication device and a user of the communication device in an IMS network

Inventors: Yigang Cai (Naperville, IL); Shiyan Hua (Lisle, IL)
Assignee: Alcatel Lucent
H04L9/3271H04L29/06217H04L63/083H04L65/1016H04L65/1073H04L9/0844H04L9/3226H04L2209/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,032,483
App. No.
11/694,873
Granted
May 12, 2015
Kind
B2
Abstract

IMS networks and methods are disclosed for authenticating a communication device and a user of the communication device. When a communication device attempts to register with an IMS network, the IMS network receives a register message from the device that includes device authentication information, such as a public or private identifier for the device. The IMS network processes the device authentication information to authenticate the communication device. The IMS network also receives user authentication information from the device, such as a password. The IMS network processes the user authentication information to authenticate the user of the device. The device and the user are both authenticated by the IMS network. Authentication of the user may also occur when originating a session or terminating a session over the IMS network with the device.

Claims (59)

1. A system comprising:

a Serving-Call Session Control Function (S-CSCF) of an IP Multimedia Subsystem (IMS) network;

the S-CSCF is configured to receive a first message from a device to register the device with the IMS network, wherein the first message includes a Public Identifier (PUID) for the device;

the S-CSCF is configured to transmit a second message to a Home Subscriber Server (HSS) of the IMS network with the PUID for the device, to receive a third message from the HSS with passwords that are mapped to the PUID, and to transmit a fourth message to the device to challenge the device for an authentication check;

the S-CSCF is configured to receive a fifth message from the device with an authentication response to authenticate the device;

the S-CSCF is configured to transmit a sixth message to the device to challenge a user of the device for a password, to receive a seventh message from the device that includes the password input by the user, to compare the password input by the user with the passwords mapped to the PUID, to authenticate the user as an authorized user of the device only when the password input by the user matches the passwords mapped to the PUID, and to register both the user and the device when the user is authenticated.

2. The system of claim 1 wherein:

the password is stored in a memory of the device as previously input by the user.

3. The system of claim 1 wherein:

the first message comprises a SIP REGISTER to register the device with the IMS network;

the fourth message comprises a SIP 401 response to challenge the device for the authentication check; and

the sixth message comprises a SIP MESSAGE to challenge the user for the password.

4. The system of claim 1 wherein:

the S-CSCF is configured to receive an eighth message from the device to originate a session over the IMS network, to transmit a ninth message to the device to challenge the user of the device for the password, to receive a tenth message from the device that includes the password input by the user, to compare the password input by the user with the passwords mapped to the PUID, to authenticate the user as an authorized user of the device only when the password input by the user matches the passwords mapped to the PUID, and to originate the session from the device when the user is authenticated.

5. The system of claim 4 wherein:

the eighth message comprises a SIP INVITE to originate the session over the IMS network; and

the ninth message comprises a SIP MESSAGE to challenge the user for the password.

6. The system of claim 1 wherein:

the S-CSCF is configured to receive an eighth message from another device to invite the device to terminate a session over the IMS network, to transmit a ninth message to the device to challenge the user of the device for the password, to receive a tenth message from the device that includes the password input by the user, to compare the password input by the user with the passwords mapped to the PUID, to authenticate the user as an authorized user of the device only when the password input by the user matches the passwords mapped to the PUID, and to terminate the session to the device when the user is authenticated.

7. The system of claim 6 wherein:

the eighth message comprises a SIP INVITE to invite the device to terminate the session over the IMS network; and

the ninth message comprises a SIP MESSAGE to challenge the user for the password.

8. A method operable in a Serving-Call Session Control Function (S-CSCF) of an IP Multimedia Subsystem (IMS) network, the method comprising:

receiving, in the S-CSCF, a first message from a device to register the device with the IMS network, wherein the first message includes a Public Identifier (PUID) for the device;

transmitting a second message from the S-CSCF to a Home Subscriber Server (HSS) of the IMS network with the PUID for the device;

receiving a third message in the S-CSCF from the HSS with passwords that are mapped to the PUID;

transmitting a fourth message from the S-CSCF to the device to challenge the device for an authentication check;

receiving a fifth message in the S-CSCF from the device with an authentication response to authenticate the device;

transmitting a sixth message from the S-CSCF to the device to challenge a user of the device for a password;

receiving a seventh message in the S-CSCF from the device that includes the password input by the user;

comparing, in the S-CSCF, the password input by the user with the passwords mapped to the PUID;

authenticating the user as an authorized user of the device only when the password input by the user matches the passwords mapped to the PUID; and

registering both the user and the device when the user is authenticated.

9. The method of claim 8 wherein:

the password is stored in a memory of the device as previously input by the user.

10. The method of claim 8 wherein:

the first message comprises a SIP REGISTER to register the device with the IMS network;

the fourth message comprises a SIP 401 response to challenge the device for the authentication check; and

the sixth message comprises a SIP MESSAGE to challenge the user for the password.

11. The method of claim 8 further comprising:

receiving an eighth message in the S-CSCF from the device to originate a session over the IMS network;

transmitting a ninth message from the S-CSCF to the device to challenge the user of the device for the password;

receiving a tenth message in the S-CSCF from the device that includes the password input by the user;

comparing the password input by the user with the passwords mapped to the PUID;

authenticating the user as an authorized user of the device only when the password input by the user matches the passwords mapped to the PUID; and

originating the session from the device when the user is authenticated.

12. The method of claim 11 wherein:

the eighth message comprises a SIP INVITE to originate the session over the IMS network; and

the ninth message comprises a SIP MESSAGE to challenge the user for the password.

13. The method of claim 8 further comprising:

receiving an eighth message in the S-CSCF from another device to invite the device to terminate a session over the IMS network;

transmitting a ninth message from the S-CSCF to the device to challenge the user of the device for the password;

receiving a tenth message in the S-CSCF from the device that includes the password input by the user;

comparing the password input by the user with the passwords mapped to the PUID;

authenticating the user as an authorized user of the device only when the password input by the user matches the passwords mapped to the PUID; and

terminating the session to the device when the user is authenticated.

14. The method of claim 13 wherein:

the eighth message comprises a SIP INVITE to invite the device to terminate the session over the IMS network; and

the ninth message comprises a SIP MESSAGE to challenge the user for the password.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2015
From: ALCATEL-LUCENT USA INC.
To: ALCATEL LUCENT
Reel/Frame 035426/0170 →
MERGER AND CHANGE OF NAME Recorded Apr 15, 2015
From: LUCENT TECHNOLOGIES INC.; ALCATEL USA MARKETING, INC.; ALCATEL USA SOURCING, INC.; LUCENT TECHNOLOGIES INC.
To: ALCATEL-LUCENT USA INC.
Reel/Frame 035410/0065 →
RELEASE OF SECURITY INTEREST Recorded Oct 9, 2014
From: CREDIT SUISSE AG
To: ALCATEL-LUCENT USA INC.
Reel/Frame 033949/0016 →
SECURITY INTEREST Recorded Mar 7, 2013
From: ALCATEL-LUCENT USA INC.
To: CREDIT SUISSE AG
Reel/Frame 030510/0627 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2007
From: CAI, YIGANG; HUA, SHIYAN
To: LUCENT TECHNOLOGIES INC.
Reel/Frame 019130/0919 →
Continuity (1)
Related Publication 20080244266A1 · Oct 2, 2008