Authentication Message for Application Security Key

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems face challenges in leveraging authentication with the home network for purposes that do not impact the serving network's key hierarchy, particularly in establishing shared security keys between a communications device and an application server without affecting the serving network's security keys.

Innovation Solution

A method where a communications device receives a message indicating authentication with the home network is for establishing a shared security key between the device and an application server, performed via the control plane of the serving network, ensuring the serving network's authentication policy and key hierarchy are not impacted, and generating a master key shared between the device and the home network for application-layer security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed via the serving network to establish security keys with application servers, then application-layer security is improved, but the serving network's key hierarchy and authentication policy may be impacted

Engineering Contradiction:
Improveapplication-layer securityVSAvoidserving network key hierarchy
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The authentication system is segmented into two independent parts: (1) authentication with the home network for generating application-layer security keys, and (2) authentication with the serving network for maintaining its own key hierarchy. This segmentation allows application-layer security to be established without impacting the serving network's key hierarchy, as each authentication process operates independently with its own key generation scope.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The application-layer security key generation is extracted from the serving network's authentication process and relocated to the home network's authentication process. By taking out the application key establishment function from the serving network, the patent enables application-layer security to be provided while preserving the serving network's authentication policy and key hierarchy integrity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If a new authentication type is introduced for application servers, then authentication versatility is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication purposeVSAvoidauthentication procedure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The home network's authentication system is enhanced with multi-functionality to serve dual purposes: (1) traditional network access authentication, and (2) application-layer security key generation. By making the home network authentication universally applicable to both functions, the patent avoids adding separate authentication procedures, thereby increasing versatility without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses the existing home network authentication procedure as a template or copy for application-layer authentication, rather than creating an entirely new authentication mechanism. This copying approach allows the system to leverage proven authentication protocols and procedures, reducing the complexity burden that would otherwise come with designing and implementing a completely new authentication system from scratch.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20210400475A1Authentication of a Communications Device
Publication Date: 2021.12.23 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20210400475A1 patent drawing
  • US20210400475A1 patent drawing
  • US20210400475A1 patent drawing

AI summary

A method is performed by a communications device. The method may comprise receiving, via a control plane of a serving network of the communications device, a message in anauthentication procedure for authentication of the communications device with a home network of the communications device. The message in some embodiments indicates that the authentication is for the purpose of establishing a shared security key between the communications device and an application server.