GBA OpenID Interworking for Unified Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inefficiencies in accessing protected resources across multiple services and websites, requiring multiple usernames and passwords, and existing authentication mechanisms do not seamlessly integrate security and authorization processes.

Innovation Solution

The interworking of Generic Bootstrapping Architecture (GBA) and OpenID architecture facilitates secure session establishment by providing a user session security key, enabling single sign-on and efficient access to services while managing user information securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple usernames and passwords are used for different services, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple authentication mechanisms (GBA bootstrapping and shared identity service) into a unified authentication flow. The mobile terminal first performs GBA authentication to obtain a shared secret, then uses this shared secret to authenticate with the shared identity service, which in turn authenticates with service providers. This merging allows a single authentication process to secure multiple services without requiring separate credentials for each.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The shared identity service acts as a universal authentication intermediary that can work with multiple service providers across different networks. Once the mobile terminal authenticates through the shared identity service, the obtained authentication credentials can be used to access multiple different services, making the authentication mechanism universally applicable rather than service-specific.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authentication mechanisms are used for each service, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The shared identity service functions as an intermediary between the mobile terminal and multiple service providers. Instead of the mobile terminal directly implementing separate authentication mechanisms for each service, it interacts with the shared identity service which handles the complexity of multiple authentication protocols. The terminal only needs to implement GBA and communicate with the shared identity service, while the intermediary manages the complexity of interfacing with various service providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If extensive personal information is collected for each service, then authorization is improved, but loss of information increases

Engineering Contradiction:
ImproveauthorizationVSAvoidloss of information
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The patent extracts personal information management from individual service registrations and centralizes it in the shared identity service. Instead of collecting and storing extensive personal information at each service provider, the system extracts only the necessary authentication credentials through the shared identity service. The mobile terminal maintains control over its identity information, sharing only what is necessary for authentication, thereby reducing information loss while maintaining authorization capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8943321B2User identity management for permitting interworking of a bootstrapping architecture and a shared identity service
Publication Date: 2015.01.27 NOKIA TECHNOLOGIES OY
  • US8943321B2 patent drawing
  • US8943321B2 patent drawing
  • US8943321B2 patent drawing

AI summary

A method, apparatus and computer program product are provided to facilitate authentication of a request, such as by a mobile terminal, while also supplying information about the user to a service, website, application or the like A method, apparatus and computer program product may provide for interworking a bootstrapping architecture, such as Generic Bootstrapping Architecture, and a shared identity service, such as OpenID architecture In this regard, a method, apparatus and computer program product may provide for a secure session with a service provider through Generic Bootstrapping Architecture while being able to supply the service provider with the user information and/or accessing a user account using OpenID architecture.