Bootstrapping Server Authentication Key Reuse

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems face challenges in providing authentication services without modifying existing standard protocols or developing new ones, particularly in radio communication systems where authentication is crucial for secure user communication.

Innovation Solution

A method and apparatus for authenticating in a communication network using a key agreement protocol to establish a shared key, generating a master key, and tying it to an authentication procedure, allowing for secure key reuse without altering existing protocols, employing techniques like Diffie-Hellman key exchange and HTTP Digest authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication services are implemented in existing communication systems, then security is improved, but protocol modification requirements increase complexity and cost

Engineering Contradiction:
Improveauthentication securityVSAvoidprotocol modification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication functionality into a separate bootstrapping server component that operates independently from existing communication protocols. This allows authentication services to be added without modifying existing protocol stacks, resolving the contradiction between improving security and avoiding protocol modification complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a bootstrapping server as an intermediary component that mediates between terminal devices and the communication network. This intermediary handles authentication operations using standard protocols (HTTP, TCP/IP), eliminating the need to modify existing communication protocols while still providing secure authentication services

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If new authentication protocols are developed, then authentication capability is improved, but implementation cost increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal bootstrapping server that can provide authentication services to multiple types of terminal devices and communication networks using standardized protocols. This multi-functional approach eliminates the need to develop and implement separate authentication solutions for different systems, reducing overall implementation cost while maintaining authentication capability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses existing standard protocols (HTTP, TCP/IP) that are already widely implemented and standardized, rather than developing entirely new proprietary protocols. This approach leverages existing protocol implementations and infrastructure, significantly reducing development and implementation costs while providing robust authentication capability

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9300641B2Method and apparatus for providing bootstrapping procedures in a communication network
Publication Date: 2016.03.29 NOKIA TECHNOLOGIES OY
  • US9300641B2 patent drawing
  • US9300641B2 patent drawing
  • US9300641B2 patent drawing

AI summary

An approach is provided for performing authentication in a communication system. In one embodiment, a key is established with a terminal in a communication network according to a key agreement protocol. The agreed key is tied to an authentication procedure to provide a security association that supports reuse of the key. A master key is generated based on the agreed key. In another embodiment, digest authentication is combined with key exchange parameters (e.g., Diffie-Hellman parameters) in the payload of the digest message, in which a key (e.g., SMEKEY or MN-AAA) is utilized as a password. In yet another embodiment, an authentication algorithm (e.g., Cellular Authentication and Voice Encryption (CAVE)) is employed with a key agreement protocol with conversion functions to support bootstrapping.