Cellular Network Authentication Algorithm Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cellular network authentication methods face vulnerabilities due to increasing computational power and the need for enhanced security in long-term evolution and machine-type communication systems, where traditional encryption techniques are becoming less effective against advanced attacks.

Innovation Solution

A method and apparatus for a cellular terminal that employs a security entity with a secure element and subscriber identity application, using cryptographic algorithms like MILENAGE and TUAK, which can select and adapt cryptographic algorithms dynamically for authentication requests and responses, including extended authentication messages with 256-bit authentication tokens and parameters, to enhance security and compatibility with legacy systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption techniques are used for cellular network authentication, then compatibility with legacy systems is maintained, but security resilience against advanced attacks deteriorates

Engineering Contradiction:
Improvesecurity resilienceVSAvoidcompatibility with legacy systems
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication system dynamically adapts between different cryptographic algorithms (MILENAGE for legacy systems, TUAK for enhanced security) based on the capabilities of the terminal and network configuration. This allows the system to optimize security resilience while maintaining backward compatibility with legacy authentication infrastructure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the cryptographic parameters used in authentication by supporting multiple algorithm types (MILENAGE, TUAK-128, TUAK-256) with different key lengths and computational characteristics. This enables the system to adjust security parameters according to threat models and terminal capabilities, resolving the contradiction between enhanced security and legacy compatibility.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If cryptographic algorithms are dynamically selected for authentication, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidalgorithm selection mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication entity is designed with multi-functionality to support multiple cryptographic algorithms (MILENAGE, TUAK-128, TUAK-256) within a single unified framework. This universal design allows the system to enhance security through algorithm selection without proportionally increasing device complexity, as the same authentication infrastructure handles multiple algorithm types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If extended authentication messages with 256-bit tokens are used, then authentication security is improved, but message length and processing overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication message length
Core Design Contradiction:
ReliabilityVSLength of moving object

Solution Approach 1:

The authentication message structure dynamically adapts its length based on the selected cryptographic algorithm. When TUAK-256 is selected for enhanced security, extended messages with 256-bit tokens are used. When legacy algorithms are used, standard message lengths are maintained. This dynamic adjustment optimizes security while minimizing unnecessary processing overhead.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3146740B1Cellular network authentication
Publication Date: 2021.04.14 NOKIA TECHNOLOGIES OY
  • EP3146740B1 patent drawingFigure 1~2
  • EP3146740B1 patent drawingFigure 3~4
  • EP3146740B1 patent drawingFigure 5

AI summary

A method, apparatus and computer program in which a cellular terminal: transmits a request that requires authentication procedure triggering to a cellular network and responsively receiving from the cellular network an authentication request message with an indication of a selected cryptographic algorithm from a group of a plurality of cryptographic algorithms; decodes the authentication request message to a decoded authentication request according to the selected cryptographic algorithm and based on a shared secret known by the cellular terminal and a network operator of the cellular terminal; based on the decoded authentication request, the shared secret and the selected cryptographic algorithm, produces and encrypts an authentication response message; and transmits the authentication response message to the cellular network.