Authentication Server Key Derivation for 5G Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of the Generic Bootstrapping Architecture (GBA) in mobile networks incurs substantial costs due to the need for a specialized bootstrapping server and lacks a similar security mechanism in fifth-generation (5G) mobile networks, which complicates secure communication between user equipment and application servers.

Innovation Solution

A method that uses an authentication server integrated within the mobile communication network to generate a master key during authentication, which is then used to derive a secure communication key independently of the authentication process, eliminating the need for a specialized bootstrapping server and allowing secure communication between user equipment and application servers without additional authentication procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a specialized bootstrapping server (BSF) is introduced to enable secure communication between user equipment and application servers, then security is improved, but device complexity and deployment costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the bootstrapping server functionality into the existing authentication server (AUSF), eliminating the need for a separate BSF. The authentication server is enhanced to perform both authentication and key derivation for application servers, reducing architectural complexity while maintaining security through integrated functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server is designed to serve multiple purposes: traditional network authentication and bootstrapping for application server communications. By making the authentication server universal, the patent eliminates dedicated bootstrapping infrastructure while maintaining secure communication capabilities across different services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a bootstrapping server is deployed to derive application-specific keys, then secure communication is enabled, but deployment costs increase due to additional infrastructure

Engineering Contradiction:
Improvesecure communicationVSAvoiddeployment cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent combines the key derivation functionality into the existing authentication server, eliminating the need for separate bootstrapping infrastructure. This merger reduces deployment costs by utilizing already-deployed authentication servers rather than requiring additional specialized hardware or software components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication server autonomously performs key derivation for application servers using its existing authentication context and master keys. The system serves itself by leveraging existing security infrastructure and credentials, eliminating the need for separate bootstrapping operations and reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If the same random variable is used for both authentication and key derivation, then the process is simplified, but security is compromised

Engineering Contradiction:
Improveprocess simplicityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the random variable usage into distinct components: one random variable for authentication and another for key derivation. This segmentation ensures that compromising one does not affect the other, maintaining security while keeping the process manageable through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different quality requirements are applied to different parts of the key derivation process. The patent uses distinct random variables with appropriate entropy requirements specific to each function (authentication vs. application key derivation), ensuring each receives the appropriate security level without over-engineering the entire system.

Inventive Principle:
Principle #3Local quality

4Device complexity

If multiple keys are derived from a single master key, then key management is simplified, but security is reduced if the master key is compromised

Engineering Contradiction:
Improvekey management complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a hierarchical key structure where the master key is segmented into multiple derived keys for different purposes (authentication, application servers, services). This segmentation allows efficient key management while ensuring that compromise of one derived key does not expose the master key or other derived keys, maintaining security through structural separation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11895487B2Method for determining a key for securing communication between a user apparatus and an application server
Publication Date: 2024.02.06 ORANGE SA
  • US11895487B2 patent drawing
  • US11895487B2 patent drawing

AI summary

A method for determining a key for securing communication between a user apparatus and an application server. An authentication server of a mobile communication network and the user apparatus generate a secret master key during an authentication procedure. The user apparatus sends the authentication server a request for a key to communicate with the application server and receives a random variable. The authentication server and the user apparatus calculate the requested key by using a key derivation function applied to at least the random variable, a user identifier and an application server identifier using the master key.