Application Key Authentication via Encrypted Session
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mechanisms for establishing secure sessions between communication devices in cellular networks are vulnerable to abuse, particularly due to the lack of protection for user device identities and the risk of unauthorized access to application keys, which can lead to spamming and unauthorized information access.
Innovation Solution
A method involving the establishment of an encrypted session using a certificate to securely transmit requests for application keys, where the response depends on the authentication and authorization of the application function, ensuring only authorized entities receive the application key and user device identifier.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the network provides application keys to application functions without strict authentication, then the ease of operation is improved, but the security is worsened due to risk of abuse and unauthorized access
Solution Approach 1:
The patent applies preliminary action by requiring application functions to be pre-authenticated and pre-authorized by the network before they can request application keys. The network maintains an authorized list of application functions and checks this list before providing keys, preventing unauthorized access in advance.
Solution Approach 2:
The patent introduces the network as an intermediary between application functions and user devices. The network acts as a trusted mediator that authenticates application functions, manages the authorized list, and controls key distribution, preventing direct unauthorized access between application functions and user devices.
2Productivity
If the network returns user device identifiers with application keys, then the productivity is improved by enabling direct communication, but the loss of information increases due to exposure of device identities to unauthorized parties
Solution Approach 1:
The patent applies local quality by providing different information to different authorized application functions based on their specific authorization level. The network can selectively include or exclude user device identifiers in responses to different application functions, allowing some to receive full information while others receive limited information.
Solution Approach 2:
The patent changes the parameter of information completeness in responses based on authorization. The network can modify response content by including or excluding user device identifiers depending on the specific authorization level of each application function, rather than providing uniform information to all.
3Reliability
If the network implements strict authentication and authorization checks, then the security is improved, but the device complexity increases due to additional authentication mechanisms
Solution Approach 1:
The patent applies universality by implementing a multi-functional authentication and authorization mechanism that handles multiple security requirements through a single unified system. The network's authentication mechanism simultaneously verifies application function identity, checks authorization status, and manages key distribution, reducing overall system complexity.
Data Source
AI summary
A method is disclosed comprising: establishing an encrypted session with an application function based on a certificate; receiving a request for an application key from the application function using the encrypted session, wherein the request comprises a key identifier relating to a user device and an application function identifier; determining at least one response to the request for the application key from a set of possible responses, the set comprising at least a rejection and a message comprising the application key and a user device identifier; and transmitting the at least one response to the request for the application key to the application function. Furthermore, related methods, apparatuses, computer programs and systems are disclosed.


