Authentication Information Sharing Between CSCF and BSF
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication networks face inefficiencies due to redundant authentication operations between IMS-AKA and GBA-AKA authentication procedures, leading to duplicate authentication information generation and increased operational costs.
Innovation Solution
Sharing user authentication information between Call Session Control Function (CSCF) and Bootstrapping Server Function (BSF) allows the reuse of authentication information generated for IMS-AKA authentication for GBA-AKA authentication, and vice versa, eliminating redundant operations by transferring or retaining AKA vectors and General User Security Settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If separate independent authentication procedures are used for IMS-AKA and GBA-AKA, then both authentication types can be supported, but duplicate authentication information is generated and maintained
Solution Approach 1:
The patent merges the authentication information management of IMS-AKA and GBA-AKA by enabling the BSF to obtain AKA vectors from the HSS for both authentication types. The BSF stores these vectors and uses them for both IMS-AKA authentication via CSCF and GBA-AKA authentication via NAF, eliminating duplicate information generation while maintaining support for both authentication types
Solution Approach 2:
The BSF is designed with multi-functionality to serve both IMS-AKA and GBA-AKA authentication procedures. It obtains AKA vectors from HSS, stores them, and distributes them to both CSCF (for IMS-AKA) and NAF (for GBA-AKA), making a single component responsible for multiple authentication functions and reducing overall system redundancy
2Reliability
If duplicate authentication information is generated for IMS-AKA and GBA-AKA, then both authentication domains can operate independently, but operational costs increase
Solution Approach 1:
The patent combines the authentication information generation process by having the HSS generate AKA vectors that are obtained by the BSF for use in both IMS-AKA and GBA-AKA domains. This merging of the information generation process reduces operational costs while maintaining the independence and reliability of both authentication domains through proper key derivation and distribution
3Ease of operation
If AKA vectors are obtained separately for IMS-AKA and GBA-AKA, then each authentication can proceed independently, but authentication efficiency decreases
Solution Approach 1:
The BSF performs preliminary action by obtaining AKA vectors from the HSS in advance and storing them before they are needed for authentication. When authentication requests arrive from either CSCF or NAF, the BSF can quickly retrieve and distribute the pre-obtained vectors, significantly improving authentication efficiency while maintaining the independence of each authentication process
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
Methods and systems taught herein provide for authentication information for authenticating a user terminal to be shared between a network entity that supports IMS-AKA authentication of the user terminal and a network entity that supports GBA-AKA authentication of the user terminal. Sharing authentication information between these entities allows all or part of the authentication information generated for IMS-AKA authentication of the user terminal to be used subsequently for GBA-AKA authentication of the user terminal, or vice versa.