Authentication Server Merging Network Attachment and Security Association

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Generic Bootstrapping Architecture (GBA) for mobile networks requires dual authentication steps, leading to increased complexity, delays, and excessive network signaling when a mobile terminal connects to a non-3GPP access network.

Innovation Solution

A method that combines the network attachment and security association processes into a single phase, where an authentication server receives a message from a bootstrapping function server containing security association parameters and uses these parameters for terminal authentication, thereby simplifying the authentication and security association procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dual authentication is performed (first with AAA/EAP server for network attachment, then with BSF for security association), then security is ensured, but complexity and signaling overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the network attachment authentication and security association authentication into a single integrated process. The terminal performs both authentication objectives simultaneously by sending one authentication request to the AAA server, which then coordinates with the BSF to obtain security association parameters, eliminating the need for separate authentication phases while maintaining security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The AAA server is enhanced to perform multiple functions: it acts as both the network access authentication server and the security association establishment server. By integrating these functions into a single server entity, the system reduces the number of separate authentication procedures while ensuring both network attachment security and application-level security associations are established.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dual authentication steps are performed, then security association is established, but access time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidterminal access time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The AAA server performs preliminary actions by obtaining security association parameters from the BSF in advance, before the terminal completes its authentication. This allows the security association to be established concurrently with the authentication process rather than sequentially, reducing the total time required for the terminal to gain access to applications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

By merging the network attachment and security association processes into a single authentication transaction, the patent eliminates the time delay associated with performing two separate authentication sequences. The terminal sends one authentication request and receives both network access authorization and security association parameters in a single interaction flow.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If separate authentication and security association phases are used, then security is maintained, but signaling overhead increases

Engineering Contradiction:
Improvesecurity association establishmentVSAvoidnetwork signaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges the signaling exchanges of network attachment authentication and security association establishment into a single set of messages. The terminal sends one authentication request to the AAA server, which then communicates with the BSF to obtain security parameters, and finally returns both authentication result and security association parameters to the terminal in one response, significantly reducing the number of signaling messages required.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The AAA server acts as an intermediary that coordinates between the terminal and the BSF. It receives the terminal's authentication request, obtains security association parameters from the BSF, and delivers them to the terminal. This intermediary role consolidates multiple signaling interactions into a single coordinated process, reducing overall network signaling overhead.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9532218B2Implementing a security association during the attachment of a terminal to an access network
Publication Date: 2016.12.27 ORANGE SA
  • US9532218B2 patent drawing
  • US9532218B2 patent drawing
  • US9532218B2 patent drawing

AI summary

A method is provided for implementing a security association for a terminal being attached to an access network. The method includes the following steps, carried out by an authentication server of the access network, after receiving a request coming from the terminal for attachment to the network: receiving a first message containing at least one security association parameter from a bootstrapping server function; authenticating the terminal by using at least one first authentication parameter provided by a home subscriber server of the terminal; and sending a security association message containing the at least one security association parameter to the authenticated terminal.