Authentication Server Key Derivation for 5G Application Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The introduction of the Generic Bootstrapping Architecture (GBA) in mobile networks incurs substantial costs due to the need for a specialized bootstrapping server and lacks a similar security mechanism in fifth-generation (5G) mobile networks, which complicates secure communication between user equipment and application servers.
Innovation Solution
A method that uses an authentication server integrated within the mobile communication network to generate a master key during authentication, which is then used to derive a secure communication key independently of the authentication process, eliminating the need for a specialized bootstrapping server and allowing secure communication between user equipment and application servers without additional authentication procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a specialized bootstrapping server (BSF) is introduced to enable secure communication between user equipment and application servers, then security is improved, but device complexity and deployment costs increase
Solution Approach 1:
The patent merges the bootstrapping server functionality into the existing authentication server (AUSF), eliminating the need for a separate BSF. The authentication server is enhanced to perform both authentication and key derivation for application servers, reducing architectural complexity while maintaining security through integrated functionality.
Solution Approach 2:
The authentication server is designed to serve multiple purposes: traditional network authentication and bootstrapping for application server communications. By making the authentication server universal, the patent eliminates dedicated bootstrapping infrastructure while maintaining secure communication capabilities across different services.
2Reliability
If a bootstrapping server is deployed to derive application-specific keys, then secure communication is enabled, but deployment costs increase due to additional infrastructure
Solution Approach 1:
The patent combines the key derivation functionality into the existing authentication server, eliminating the need for separate bootstrapping infrastructure. This merger reduces deployment costs by utilizing already-deployed authentication servers rather than requiring additional specialized hardware or software components.
Solution Approach 2:
The authentication server autonomously performs key derivation for application servers using its existing authentication context and master keys. The system serves itself by leveraging existing security infrastructure and credentials, eliminating the need for separate bootstrapping operations and reducing overall system complexity.
3Ease of operation
If the same random variable is used for both authentication and key derivation, then the process is simplified, but security is compromised
Solution Approach 1:
The patent segments the random variable usage into distinct components: one random variable for authentication and another for key derivation. This segmentation ensures that compromising one does not affect the other, maintaining security while keeping the process manageable through clear separation of concerns.
Solution Approach 2:
Different quality requirements are applied to different parts of the key derivation process. The patent uses distinct random variables with appropriate entropy requirements specific to each function (authentication vs. application key derivation), ensuring each receives the appropriate security level without over-engineering the entire system.
4Device complexity
If multiple keys are derived from a single master key, then key management is simplified, but security is reduced if the master key is compromised
Solution Approach 1:
The patent implements a hierarchical key structure where the master key is segmented into multiple derived keys for different purposes (authentication, application servers, services). This segmentation allows efficient key management while ensuring that compromise of one derived key does not expose the master key or other derived keys, maintaining security through structural separation.
Data Source
AI summary
A method for determining a key for securing communication between a user apparatus and an application server. An authentication server of a mobile communication network and the user apparatus generate a secret master key during an authentication procedure. The user apparatus sends the authentication server a request for a key to communicate with the application server and receives a random variable. The authentication server and the user apparatus calculate the requested key by using a key derivation function applied to at least the random variable, a user identifier and an application server identifier using the master key.

