Bootstrapping Server Authentication Key Reuse
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems face challenges in providing authentication services without modifying existing standard protocols or developing new ones, particularly in radio communication systems where authentication is crucial for secure user communication.
Innovation Solution
A method and apparatus for authenticating in a communication network using a key agreement protocol to establish a shared key, generating a master key, and tying it to an authentication procedure, allowing for secure key reuse without altering existing protocols, employing techniques like Diffie-Hellman key exchange and HTTP Digest authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication services are implemented in existing communication systems, then security is improved, but protocol modification requirements increase complexity and cost
Solution Approach 1:
The patent segments the authentication functionality into a separate bootstrapping server component that operates independently from existing communication protocols. This allows authentication services to be added without modifying existing protocol stacks, resolving the contradiction between improving security and avoiding protocol modification complexity
Solution Approach 2:
The patent introduces a bootstrapping server as an intermediary component that mediates between terminal devices and the communication network. This intermediary handles authentication operations using standard protocols (HTTP, TCP/IP), eliminating the need to modify existing communication protocols while still providing secure authentication services
2Reliability
If new authentication protocols are developed, then authentication capability is improved, but implementation cost increases
Solution Approach 1:
The patent implements a universal bootstrapping server that can provide authentication services to multiple types of terminal devices and communication networks using standardized protocols. This multi-functional approach eliminates the need to develop and implement separate authentication solutions for different systems, reducing overall implementation cost while maintaining authentication capability
Solution Approach 2:
The patent uses existing standard protocols (HTTP, TCP/IP) that are already widely implemented and standardized, rather than developing entirely new proprietary protocols. This approach leverages existing protocol implementations and infrastructure, significantly reducing development and implementation costs while providing robust authentication capability
Data Source
AI summary
An approach is provided for performing authentication in a communication system. In one embodiment, a key is established with a terminal in a communication network according to a key agreement protocol. The agreed key is tied to an authentication procedure to provide a security association that supports reuse of the key. A master key is generated based on the agreed key. In another embodiment, digest authentication is combined with key exchange parameters (e.g., Diffie-Hellman parameters) in the payload of the digest message, in which a key (e.g., SMEKEY or MN-AAA) is utilized as a password. In yet another embodiment, an authentication algorithm (e.g., Cellular Authentication and Voice Encryption (CAVE)) is employed with a key agreement protocol with conversion functions to support bootstrapping.


