Authentication Information Sharing Between CSCF and BSF

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks face inefficiencies due to redundant authentication operations between IMS-AKA and GBA-AKA authentication procedures, leading to duplicate authentication information generation and increased operational costs.

Innovation Solution

Sharing user authentication information between Call Session Control Function (CSCF) and Bootstrapping Server Function (BSF) allows the reuse of authentication information generated for IMS-AKA authentication for GBA-AKA authentication, and vice versa, eliminating redundant operations by transferring or retaining AKA vectors and General User Security Settings.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate independent authentication procedures are used for IMS-AKA and GBA-AKA, then both authentication types can be supported, but duplicate authentication information is generated and maintained

Engineering Contradiction:
Improveauthentication type supportVSAvoidauthentication information
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges the authentication information management of IMS-AKA and GBA-AKA by enabling the BSF to obtain AKA vectors from the HSS for both authentication types. The BSF stores these vectors and uses them for both IMS-AKA authentication via CSCF and GBA-AKA authentication via NAF, eliminating duplicate information generation while maintaining support for both authentication types

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The BSF is designed with multi-functionality to serve both IMS-AKA and GBA-AKA authentication procedures. It obtains AKA vectors from HSS, stores them, and distributes them to both CSCF (for IMS-AKA) and NAF (for GBA-AKA), making a single component responsible for multiple authentication functions and reducing overall system redundancy

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If duplicate authentication information is generated for IMS-AKA and GBA-AKA, then both authentication domains can operate independently, but operational costs increase

Engineering Contradiction:
Improveauthentication independenceVSAvoidoperational cost
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines the authentication information generation process by having the HSS generate AKA vectors that are obtained by the BSF for use in both IMS-AKA and GBA-AKA domains. This merging of the information generation process reduces operational costs while maintaining the independence and reliability of both authentication domains through proper key derivation and distribution

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If AKA vectors are obtained separately for IMS-AKA and GBA-AKA, then each authentication can proceed independently, but authentication efficiency decreases

Engineering Contradiction:
Improveauthentication independenceVSAvoidauthentication efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The BSF performs preliminary action by obtaining AKA vectors from the HSS in advance and storing them before they are needed for authentication. When authentication requests arrive from either CSCF or NAF, the BSF can quickly retrieve and distribute the pre-obtained vectors, significantly improving authentication efficiency while maintaining the independence of each authentication process

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2245873B1System and method of user authentication in wireless communication networks
Publication Date: 2020.01.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2245873B1 patent drawingFigure 1
  • EP2245873B1 patent drawingFigure 2~3
  • EP2245873B1 patent drawingFigure 4

AI summary

Methods and systems taught herein provide for authentication information for authenticating a user terminal to be shared between a network entity that supports IMS-AKA authentication of the user terminal and a network entity that supports GBA-AKA authentication of the user terminal. Sharing authentication information between these entities allows all or part of the authentication information generated for IMS-AKA authentication of the user terminal to be used subsequently for GBA-AKA authentication of the user terminal, or vice versa.