Credential Security Level Verification in Generic Bootstrapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In generic bootstrapping architectures, applications in terminal equipment cannot determine the security level of credentials received from credential establishment entities, leading to potential execution of applications with insufficient security, unnecessary network load, and fraud scenarios due to lack of credential deletion awareness.

Innovation Solution

A method and system for security level establishment in terminal equipment that involves sending a request for credentials, receiving credential quality information, determining the security level, comparing it with a desired level, and notifying or deleting credentials based on conditions such as revocation or removal of smartcards, thereby ensuring only secure applications are executed and credentials are properly managed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications execute without verifying credential security levels, then application execution flexibility is improved, but security reliability deteriorates

Engineering Contradiction:
Improveapplication execution flexibilityVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification of credential security levels before application execution. The application entity receives credential quality information from the credential establishment entity and determines whether the credential meets the required security level before allowing the application to execute, thus preventing security issues before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the credential establishment entity provides credential quality information back to the application entity. This feedback loop enables the application entity to make informed decisions about whether to execute applications based on the security level of available credentials

Inventive Principle:
Principle #23Feedback

2Productivity

If applications are executed with insufficient security credentials, then application execution speed is improved, but security reliability deteriorates

Engineering Contradiction:
Improveapplication execution speedVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

Security verification is performed in advance before application execution. The application entity determines the security level of credentials and compares it with required security levels before initiating application execution, ensuring that only adequately secured applications are executed while maintaining efficient processing

Inventive Principle:
Principle #10Preliminary action

3Device complexity

If credential deletion awareness is not implemented, then system complexity is reduced, but fraud vulnerability increases

Engineering Contradiction:
Improvesystem complexityVSAvoidfraud vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The credential establishment entity provides feedback to the application entity regarding credential validity status and deletion conditions. This feedback mechanism enables the system to automatically respond to credential revocation events and delete credentials when necessary, preventing fraud without requiring complex manual monitoring systems

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system implements self-service credential management where the application entity automatically receives and processes credential quality information, determines security levels, and executes or aborts application execution based on credential validity. The system also automatically handles credential deletion when revocation conditions are met, reducing the need for external intervention

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8037522B2Security level establishment under generic bootstrapping architecture
Publication Date: 2011.10.11 NOKIA TECHNOLOGIES OY
  • US8037522B2 patent drawing
  • US8037522B2 patent drawing
  • US8037522B2 patent drawing

AI summary

Security level establishment for an application in a terminal equipment under a generic bootstrapping architecture offering a plurality of different bootstrapping mechanisms, the terminal equipment comprising a credential establishment entity and an application entity, comprising a request for a credential for the application from the application entity to the credential establishment entity and a response from the credential establishment entity to the application entity, wherein the response comprises the requested credential and credential quality information.