Application Key Authentication via Encrypted Session

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mechanisms for establishing secure sessions between communication devices in cellular networks are vulnerable to abuse, particularly due to the lack of protection for user device identities and the risk of unauthorized access to application keys, which can lead to spamming and unauthorized information access.

Innovation Solution

A method involving the establishment of an encrypted session using a certificate to securely transmit requests for application keys, where the response depends on the authentication and authorization of the application function, ensuring only authorized entities receive the application key and user device identifier.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the network provides application keys to application functions without strict authentication, then the ease of operation is improved, but the security is worsened due to risk of abuse and unauthorized access

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by requiring application functions to be pre-authenticated and pre-authorized by the network before they can request application keys. The network maintains an authorized list of application functions and checks this list before providing keys, preventing unauthorized access in advance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces the network as an intermediary between application functions and user devices. The network acts as a trusted mediator that authenticates application functions, manages the authorized list, and controls key distribution, preventing direct unauthorized access between application functions and user devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the network returns user device identifiers with application keys, then the productivity is improved by enabling direct communication, but the loss of information increases due to exposure of device identities to unauthorized parties

Engineering Contradiction:
ImproveproductivityVSAvoidloss of information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent applies local quality by providing different information to different authorized application functions based on their specific authorization level. The network can selectively include or exclude user device identifiers in responses to different application functions, allowing some to receive full information while others receive limited information.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of information completeness in responses based on authorization. The network can modify response content by including or excluding user device identifiers depending on the specific authorization level of each application function, rather than providing uniform information to all.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If the network implements strict authentication and authorization checks, then the security is improved, but the device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by implementing a multi-functional authentication and authorization mechanism that handles multiple security requirements through a single unified system. The network's authentication mechanism simultaneously verifies application function identity, checks authorization status, and manages key distribution, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240056805A1Method, apparatus and system relating to a response to an request for an application key
Publication Date: 2024.02.15 NOKIA TECHNOLOGIES OY
  • US20240056805A1 patent drawing
  • US20240056805A1 patent drawing
  • US20240056805A1 patent drawing

AI summary

A method is disclosed comprising: establishing an encrypted session with an application function based on a certificate; receiving a request for an application key from the application function using the encrypted session, wherein the request comprises a key identifier relating to a user device and an application function identifier; determining at least one response to the request for the application key from a set of possible responses, the set comprising at least a rejection and a message comprising the application key and a user device identifier; and transmitting the at least one response to the request for the application key to the application function. Furthermore, related methods, apparatuses, computer programs and systems are disclosed.