Bootstrapping Server Function for Enterprise Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers face challenges in efficiently authenticating enterprise users across networks, as existing solutions often require complex key management and lack a standardized method for secure service delivery.

Innovation Solution

The proposed solution utilizes a Generic Bootstrapping Architecture (GBA) that generates security keys based on enterprise names, using a Key Derivation Function (KDF) to create unique keys for authentication and service control, leveraging a Bootstrapping Server Function (BSF) to manage and deliver secure services to enterprise subscribers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used, then authentication can be performed, but key management becomes complex and scalable

Engineering Contradiction:
Improveauthentication securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Bootstrapping Server Function (BSF) as an intermediary component that centralizes key management operations. The BSF receives enterprise identifiers, generates corresponding security keys through key derivation functions, and distributes them to appropriate network elements, thereby eliminating the complexity of decentralized key management while maintaining authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security key generation mechanism is designed to be universal, where a single BSF can serve multiple enterprises by deriving keys from enterprise identifiers. This multi-functional approach allows the system to handle authentication for various enterprises without requiring separate dedicated key management systems for each, thus reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If enterprise-specific authentication is implemented, then authentication accuracy improves, but service delivery efficiency decreases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidservice delivery efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system performs preliminary key generation and distribution before actual service delivery occurs. Enterprise identifiers are preprocessed to generate security keys in advance, and these keys are cached or pre-distributed to network elements. This preliminary action eliminates the need for real-time key generation during service delivery, thereby maintaining high authentication accuracy while significantly improving service delivery efficiency.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure key generation is implemented, then network security improves, but processing time increases

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security keys are generated in advance during network setup or provisioning phases rather than during actual authentication events. The BSF pre-generates keys based on enterprise identifiers and makes them available when needed, eliminating the time-consuming key generation process during authentication and thus reducing processing time while maintaining strong network security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of generating new cryptographic keys for each authentication event, the system uses deterministic key derivation functions that generate identical keys from the same enterprise identifiers. This copying approach ensures consistent, reproducible key generation that is computationally efficient, thereby reducing processing time while maintaining security through deterministic derivation rather than random generation.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8776197B2Secure enterprise service delivery
Publication Date: 2014.07.08 VERIZON PATENT & LICENSING INC
  • US8776197B2 patent drawing
  • US8776197B2 patent drawing
  • US8776197B2 patent drawing

AI summary

A device receives enterprise information associated with enterprises supported by a network, and determines enterprise identifiers for one or more enterprises identified in the enterprise information. The device also receives information associated with devices and subscribers of the network, and determines security key parameters based on the information associated with the devices and the subscribers of the network. The device further generates, based on the security key parameters, a security key for each of the enterprise identifiers.