GBA Security Association Setup via Network Attachment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Generic Bootstrapping Architecture (GBA) in mobile networks requires separate and consecutive authentication of mobile terminals, leading to increased signaling and complexity, particularly due to the need for a specific HTTP connection for security association establishment.
Innovation Solution
Coupling the terminal's authentication for GBA-type security association with the network attachment process, where the network access server and subscriber server dialogue to establish the security association using the Diameter protocol, eliminating the need for a separate HTTP connection and simplifying the security association setup.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication procedures are used for network attachment and GBA security association, then authentication security is maintained, but signaling overhead increases and process complexity increases
Solution Approach 1:
The patent merges the network attachment authentication and GBA security association authentication into a single integrated procedure. The network access server performs both authentications concurrently by interacting with the subscriber server to obtain authentication vectors and deriving both the network authentication key and GBA security key from the same initial authentication process, thereby eliminating the need for separate consecutive authentication procedures while maintaining security requirements.
2Reliability
If separate authentication procedures are used for network attachment and GBA security association, then authentication completeness is ensured, but signaling overhead increases
Solution Approach 1:
The patent combines both authentication objectives into a single signaling exchange sequence. The network access server sends one authentication request to the subscriber server and receives authentication vectors that enable derivation of both network authentication credentials and GBA security association keys, thereby achieving complete authentication while minimizing signaling messages compared to separate procedures.
Solution Approach 2:
The patent performs preliminary authentication with the subscriber server during network attachment before the terminal needs to establish GBA security associations with applications. The authentication vectors are obtained in advance, and the terminal is authenticated to the network first, then the GBA security context is established using keys derived from the same authentication process, eliminating the need for a second separate authentication signaling exchange.
3Adaptability or versatility
If HTTP connection is required for GBA authentication, then security association establishment is possible, but connection complexity increases
Solution Approach 1:
The patent makes the network access server perform multiple functions: it acts as both the network authentication entity and the GBA bootstrapping function server. By integrating these roles, the system eliminates the need for separate HTTP connections to a dedicated BSF server, as the network access server itself provides GBA security association services using the Diameter protocol, thereby reducing connection complexity while maintaining security association capabilities.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method of putting in place a security association of GBA type for a terminal, comprising the following steps, executed in a network access server, following the receipt of a request for attachment to the network from the terminal: dispatching (E1) of a request to a subscriber server, receipt (E1) of a response comprising an indication that the user profile associated with the terminal supports the security association of GBA type.