GBA Security Association Setup via Network Attachment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Generic Bootstrapping Architecture (GBA) in mobile networks requires separate and consecutive authentication of mobile terminals, leading to increased signaling and complexity, particularly due to the need for a specific HTTP connection for security association establishment.

Innovation Solution

Coupling the terminal's authentication for GBA-type security association with the network attachment process, where the network access server and subscriber server dialogue to establish the security association using the Diameter protocol, eliminating the need for a separate HTTP connection and simplifying the security association setup.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication procedures are used for network attachment and GBA security association, then authentication security is maintained, but signaling overhead increases and process complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidprocess complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the network attachment authentication and GBA security association authentication into a single integrated procedure. The network access server performs both authentications concurrently by interacting with the subscriber server to obtain authentication vectors and deriving both the network authentication key and GBA security key from the same initial authentication process, thereby eliminating the need for separate consecutive authentication procedures while maintaining security requirements.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate authentication procedures are used for network attachment and GBA security association, then authentication completeness is ensured, but signaling overhead increases

Engineering Contradiction:
Improveauthentication completenessVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines both authentication objectives into a single signaling exchange sequence. The network access server sends one authentication request to the subscriber server and receives authentication vectors that enable derivation of both network authentication credentials and GBA security association keys, thereby achieving complete authentication while minimizing signaling messages compared to separate procedures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary authentication with the subscriber server during network attachment before the terminal needs to establish GBA security associations with applications. The authentication vectors are obtained in advance, and the terminal is authenticated to the network first, then the GBA security context is established using keys derived from the same authentication process, eliminating the need for a second separate authentication signaling exchange.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If HTTP connection is required for GBA authentication, then security association establishment is possible, but connection complexity increases

Engineering Contradiction:
Improvesecurity association capabilityVSAvoidconnection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes the network access server perform multiple functions: it acts as both the network authentication entity and the GBA bootstrapping function server. By integrating these roles, the system eliminates the need for separate HTTP connections to a dedicated BSF server, as the network access server itself provides GBA security association services using the Diameter protocol, thereby reducing connection complexity while maintaining security association capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2692165B1Putting in place of a security association of GBA type for a terminal in a mobile telecommunications network
Publication Date: 2017.08.23 ORANGE SA
  • EP2692165B1 patent drawingFigure 1
  • EP2692165B1 patent drawingFigure 2
  • EP2692165B1 patent drawing

AI summary

The invention relates to a method of putting in place a security association of GBA type for a terminal, comprising the following steps, executed in a network access server, following the receipt of a request for attachment to the network from the terminal: dispatching (E1) of a request to a subscriber server, receipt (E1) of a response comprising an indication that the user profile associated with the terminal supports the security association of GBA type.