GBA Authentication Mechanism Negotiation Preventing Bid-Down Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 3GPP and 3GPP2 communication systems, there is a challenge in negotiating the appropriate authentication and bootstrapping mechanisms between mobile nodes and networks, especially when multiple mechanisms are supported, which can lead to 'bid-down' attacks where weaker mechanisms are inadvertently selected, compromising security.

Innovation Solution

A method where the mobile node sends a list of supported authentication mechanisms to the bootstrapping server function, which selects and authenticates using an integrity-protected mechanism, ensuring that the chosen mechanism is verified to prevent unauthorized changes during the bootstrapping process, thereby enhancing security and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the mobile node includes its identity in the first GET request to the bootstrapping server, then the authentication mechanism is implicitly pre-selected, but the bootstrapping server loses the ability to select the most appropriate authentication mechanism

Engineering Contradiction:
Improveimplicit mechanism selectionVSAvoidmechanism selection flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication mechanism selection process into two independent parts: (1) the mobile node sends its identity without implicit mechanism selection, and (2) the bootstrapping server independently selects the authentication mechanism based on the identity and network policies. This segmentation resolves the contradiction by allowing the server to choose the most appropriate mechanism while maintaining operational simplicity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The bootstrapping server acts as an intermediary that receives the mobile node's identity, consults network policies and capabilities, and then selects the most appropriate authentication mechanism. This intermediary role allows the system to maintain ease of operation while achieving adaptability in mechanism selection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the mobile node pre-selects an authentication mechanism by including identity in the request, then the process is simplified, but security is compromised due to potential 'bid-down' attacks

Engineering Contradiction:
Improveauthentication process complexityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by having the bootstrapping server pre-establish network policies and authentication mechanism rankings before the actual authentication process. When the mobile node sends its identity, the server already has the framework in place to securely select the strongest appropriate mechanism, preventing bid-down attacks while maintaining process simplicity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback through the server's policy database that contains information about supported authentication mechanisms and their security characteristics. The server uses this feedback information to make informed decisions about mechanism selection, ensuring security while keeping the process simple for the mobile node.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple authentication mechanisms are supported, then versatility is improved, but the risk of selecting weaker mechanisms increases

Engineering Contradiction:
Improveauthentication mechanism supportVSAvoidbid-down attack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter of mechanism selection from client-initiated to server-initiated. The server uses its knowledge of network capabilities, mobile node identity, and security policies to select the appropriate mechanism from the supported list. This parameter change ensures that stronger mechanisms are selected when available while maintaining versatility in supported mechanisms.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system applies local quality by allowing different authentication mechanisms to be selected for different mobile nodes or different network contexts. The server can choose the most appropriate mechanism locally for each authentication request based on specific conditions, rather than using a fixed or client-determined mechanism for all cases.

Inventive Principle:
Principle #3Local quality

4Reliability

If the bootstrapping server selects the authentication mechanism, then security is improved, but the mobile node must wait for server selection increasing time

Engineering Contradiction:
Improveauthentication securityVSAvoidbootstrapping time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the bootstrapping server pre-configure its policy database with information about supported authentication mechanisms and selection criteria before actual authentication occurs. This preliminary preparation allows the server to quickly select the appropriate mechanism when the mobile node sends its identity, minimizing additional delay while ensuring secure selection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1891789B1Apparatus, method and computer program product providing mobile node identities in conjunction with authentication preferences in generic bootstrapping architecture (GBA)
Publication Date: 2019.07.24 NOKIA TECHNOLOGIES OY
  • EP1891789B1 patent drawingFigure 1
  • EP1891789B1 patent drawingFigure 2
  • EP1891789B1 patent drawingFigure 3

AI summary

In one exemplary and non-limiting aspect thereof a method is provided that includes sending a wireless network (WN) a first message that includes a list of authentication mechanisms supported by a node and, in association with each authentication mechanism, a corresponding identity; determining in the WN an authentication mechanism to be used for bootstrapping, based at least on the list received from the node; and including information in a second message that is sent to the node, the information including the determined authentication mechanism in conjunction with a corresponding identity. The method further includes protecting at least the list of authentication mechanisms supported by the node and the corresponding identities and sending a second message to the network, the second message including at least the list of authentication mechanisms and the corresponding identities. The method further includes receiving a second response message from the network that is at least partially integrity protected, where the second response message includes an indication of the selected authentication mechanism and the corresponding identity.