Generic Authentication Architecture for Mobile Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Generic Authentication Architectures (GAAs) in 3G and 3GPP2 networks are limited by supporting only one authentication mechanism between the subscriber and the Bootstrapping Server Function (BSF), lacking authentication between the BSF and Network Application Function (NAF), which can lead to security breaches and restricted compatibility with various networks and service entities.
Innovation Solution
A generic authentication architecture that allows negotiation and selection of multiple authentication mechanisms between service entities and an Entity Authentication Centre (EAC), enabling mutual authentication between service entities and the EAC, and generating shared derived keys for secure communication, thus enhancing flexibility and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single authentication mechanism (AKA) is used between subscriber and BSF, then the authentication process is simple, but the system lacks flexibility and cannot support multiple authentication mechanisms
Solution Approach 1:
The patent implements a universal authentication framework where the BSF can perform multiple authentication mechanisms (AKA, CAVE, AAA) through a unified architecture. The system defines authentication modes that can be negotiated between service entities and BSF, allowing the same authentication infrastructure to support diverse authentication methods without requiring separate dedicated systems for each mechanism.
Solution Approach 2:
The patent introduces dynamic authentication mode negotiation between service entities and the BSF. The authentication mechanism is not fixed but can be selected and negotiated based on the capabilities and requirements of the communicating parties. This dynamic selection allows the system to adapt to different scenarios while maintaining a consistent underlying architecture.
2Reliability
If authentication between BSF and NAF is not implemented, then the system is simpler, but security is compromised as attackers can counterfeit NAF and steal subscriber secret information
Solution Approach 1:
The patent positions the BSF as a trusted intermediary that mediates authentication between service entities and the network. The BSF not only authenticates the subscriber but also authenticates the service entity (NAF) before allowing service access. This intermediary role ensures that both parties are verified, preventing counterfeiting attacks while maintaining a centralized security architecture.
Solution Approach 2:
The patent implements preliminary authentication of the service entity by the BSF before the service entity can interact with authenticated subscribers. This preliminary action ensures that only verified service entities can access subscriber services, preventing security breaches from counterfeit NAFs. The authentication sequence is structured so that service entity verification occurs before service provisioning.
3Adaptability or versatility
If multiple authentication mechanisms are supported, then the system is more versatile, but the negotiation and selection process becomes more complex
Solution Approach 1:
The patent implements partial action by implementing authentication mechanism negotiation only where needed - specifically between service entities and BSF when multiple mechanisms are available. The system doesn't require full negotiation in all cases but only when the service entity and BSF both support multiple authentication mechanisms. This selective approach reduces operational complexity while maintaining versatility where required.
4Reliability
If the authentication architecture is extended to support end-to-end communication authentication, then security is improved, but the system complexity increases
Solution Approach 1:
The patent merges the authentication functions for end-to-end communication into the existing BSF architecture. Rather than creating separate authentication systems for different communication scenarios, the solution combines service entity authentication, subscriber authentication, and key management functions within the unified BSF framework. This merging approach extends security to end-to-end communications while avoiding the complexity of multiple separate authentication systems.
Data Source
AI summary
The invention discloses a method for authenticating in end-to-end communications based on a mobile network, applied to a system including a first service entity requesting a service, a second service entity providing the service and an entity authentication center, EAC; respectively performing a mutual authentication between the first service entity and the EAC and that between the second service entity and the EAC according to the negotiated authentication mode; if the first service entity requests the second service entity to provide the service, the EAC providing authentication inquiring for the first service entity and the second service entity according to the negotiated authentication mode, and generating a shared derived key according to the negotiated authentication mode; and the first service entity and the second service entity authenticating each other according to the shared derived key and the negotiated authentication mode, and generating a session key for protecting the service.


