Generic Authentication Architecture for Mobile Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Generic Authentication Architectures (GAAs) in 3G and 3GPP2 networks are limited by supporting only one authentication mechanism between the subscriber and the Bootstrapping Server Function (BSF), lacking authentication between the BSF and Network Application Function (NAF), which can lead to security breaches and restricted compatibility with various networks and service entities.

Innovation Solution

A generic authentication architecture that allows negotiation and selection of multiple authentication mechanisms between service entities and an Entity Authentication Centre (EAC), enabling mutual authentication between service entities and the EAC, and generating shared derived keys for secure communication, thus enhancing flexibility and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single authentication mechanism (AKA) is used between subscriber and BSF, then the authentication process is simple, but the system lacks flexibility and cannot support multiple authentication mechanisms

Engineering Contradiction:
Improveauthentication mechanism flexibilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework where the BSF can perform multiple authentication mechanisms (AKA, CAVE, AAA) through a unified architecture. The system defines authentication modes that can be negotiated between service entities and BSF, allowing the same authentication infrastructure to support diverse authentication methods without requiring separate dedicated systems for each mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces dynamic authentication mode negotiation between service entities and the BSF. The authentication mechanism is not fixed but can be selected and negotiated based on the capabilities and requirements of the communicating parties. This dynamic selection allows the system to adapt to different scenarios while maintaining a consistent underlying architecture.

Inventive Principle:
Principle #15Dynamics

2Reliability

If authentication between BSF and NAF is not implemented, then the system is simpler, but security is compromised as attackers can counterfeit NAF and steal subscriber secret information

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent positions the BSF as a trusted intermediary that mediates authentication between service entities and the network. The BSF not only authenticates the subscriber but also authenticates the service entity (NAF) before allowing service access. This intermediary role ensures that both parties are verified, preventing counterfeiting attacks while maintaining a centralized security architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication of the service entity by the BSF before the service entity can interact with authenticated subscribers. This preliminary action ensures that only verified service entities can access subscriber services, preventing security breaches from counterfeit NAFs. The authentication sequence is structured so that service entity verification occurs before service provisioning.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple authentication mechanisms are supported, then the system is more versatile, but the negotiation and selection process becomes more complex

Engineering Contradiction:
Improveauthentication mechanism diversityVSAvoidauthentication negotiation ease
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements partial action by implementing authentication mechanism negotiation only where needed - specifically between service entities and BSF when multiple mechanisms are available. The system doesn't require full negotiation in all cases but only when the service entity and BSF both support multiple authentication mechanisms. This selective approach reduces operational complexity while maintaining versatility where required.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If the authentication architecture is extended to support end-to-end communication authentication, then security is improved, but the system complexity increases

Engineering Contradiction:
Improveend-to-end communication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication functions for end-to-end communication into the existing BSF architecture. Rather than creating separate authentication systems for different communication scenarios, the solution combines service entity authentication, subscriber authentication, and key management functions within the unified BSF framework. This merging approach extends security to end-to-end communications while avoiding the complexity of multiple separate authentication systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8468353B2Method, system and authentication centre for authenticating in end-to-end communications based on a mobile network
Publication Date: 2013.06.18 HUAWEI TECH CO LTD
  • US8468353B2 patent drawing
  • US8468353B2 patent drawing
  • US8468353B2 patent drawing

AI summary

The invention discloses a method for authenticating in end-to-end communications based on a mobile network, applied to a system including a first service entity requesting a service, a second service entity providing the service and an entity authentication center, EAC; respectively performing a mutual authentication between the first service entity and the EAC and that between the second service entity and the EAC according to the negotiated authentication mode; if the first service entity requests the second service entity to provide the service, the EAC providing authentication inquiring for the first service entity and the second service entity according to the negotiated authentication mode, and generating a shared derived key according to the negotiated authentication mode; and the first service entity and the second service entity authenticating each other according to the shared derived key and the negotiated authentication mode, and generating a session key for protecting the service.