Authentication Server Merging Network Attachment and Security Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Generic Bootstrapping Architecture (GBA) for mobile networks requires dual authentication steps, leading to increased complexity, delays, and excessive network signaling when a mobile terminal connects to a non-3GPP access network.
Innovation Solution
A method that combines the network attachment and security association processes into a single phase, where an authentication server receives a message from a bootstrapping function server containing security association parameters and uses these parameters for terminal authentication, thereby simplifying the authentication and security association procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dual authentication is performed (first with AAA/EAP server for network attachment, then with BSF for security association), then security is ensured, but complexity and signaling overhead increase
Solution Approach 1:
The patent combines the network attachment authentication and security association authentication into a single integrated process. The terminal performs both authentication objectives simultaneously by sending one authentication request to the AAA server, which then coordinates with the BSF to obtain security association parameters, eliminating the need for separate authentication phases while maintaining security requirements.
Solution Approach 2:
The AAA server is enhanced to perform multiple functions: it acts as both the network access authentication server and the security association establishment server. By integrating these functions into a single server entity, the system reduces the number of separate authentication procedures while ensuring both network attachment security and application-level security associations are established.
2Reliability
If dual authentication steps are performed, then security association is established, but access time increases
Solution Approach 1:
The AAA server performs preliminary actions by obtaining security association parameters from the BSF in advance, before the terminal completes its authentication. This allows the security association to be established concurrently with the authentication process rather than sequentially, reducing the total time required for the terminal to gain access to applications.
Solution Approach 2:
By merging the network attachment and security association processes into a single authentication transaction, the patent eliminates the time delay associated with performing two separate authentication sequences. The terminal sends one authentication request and receives both network access authorization and security association parameters in a single interaction flow.
3Reliability
If separate authentication and security association phases are used, then security is maintained, but signaling overhead increases
Solution Approach 1:
The patent merges the signaling exchanges of network attachment authentication and security association establishment into a single set of messages. The terminal sends one authentication request to the AAA server, which then communicates with the BSF to obtain security parameters, and finally returns both authentication result and security association parameters to the terminal in one response, significantly reducing the number of signaling messages required.
Solution Approach 2:
The AAA server acts as an intermediary that coordinates between the terminal and the BSF. It receives the terminal's authentication request, obtains security association parameters from the BSF, and delivers them to the terminal. This intermediary role consolidates multiple signaling interactions into a single coordinated process, reducing overall network signaling overhead.
Data Source
AI summary
A method is provided for implementing a security association for a terminal being attached to an access network. The method includes the following steps, carried out by an authentication server of the access network, after receiving a request coming from the terminal for attachment to the network: receiving a first message containing at least one security association parameter from a bootstrapping server function; authenticating the terminal by using at least one first authentication parameter provided by a home subscriber server of the terminal; and sending a security association message containing the at least one security association parameter to the authenticated terminal.


