NAF Key Establishment via BSF Inversion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for establishing a security association between a client terminal and a service node in 3G networks are vulnerable to threats such as manipulation and replay attacks, especially when the service node initiates the connection, as they rely on insecure communication channels like SMS for push-type services.

Innovation Solution

A method where the Network Application Function (NAF) initiates the establishment of a security association with the User Equipment (UE) by requesting a NAF key from the Bootstrapping Server Function (BSF), using identities and a shared secret to generate and sign key material, allowing the UE to derive and verify the NAF key for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the service node initiates connection using SMS or similar channels to establish security association, then the service can be delivered to users, but the communication channel is vulnerable to manipulation and replay attacks

Engineering Contradiction:
Improveservice delivery capabilityVSAvoidsecurity of communication channel
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by establishing the security association before the actual service data transmission. The NAF initiates the security association setup in advance, obtaining security context and keys before pushing service information to the UE. This pre-establishment of security credentials prevents manipulation and replay attacks on the service delivery channel, as the security framework is already in place before any service communication occurs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the UE initiates the security association establishment by sending B-TID to NAF, then the security association can be established, but the UE must continuously initiate requests which reduces efficiency

Engineering Contradiction:
Improvesecurity association establishmentVSAvoidefficiency of key establishment
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies inversion by reversing the traditional initiation direction. Instead of the UE initiating the security association establishment by sending B-TID to the NAF, the NAF initiates the process by sending a request to the BSF to obtain security context. This role reversal allows the service node to proactively establish security associations, eliminating the need for continuous UE-initiated requests and significantly improving efficiency for push-type services.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If the NAF requests security context from BSF using UE identity, then the security association can be established before data transmission, but additional signaling steps are required

Engineering Contradiction:
Improvesecurity of push serviceVSAvoidsignaling procedure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the intermediary principle by introducing the BSF as a mediator between the NAF and the security credential storage. The NAF sends a request to the BSF containing the UE identity, and the BSF retrieves the appropriate security context (including B-TID and authentication vectors) from the HSS or local storage. This intermediary approach streamlines the process by centralizing security credential management, reducing the complexity that would otherwise exist if the NAF directly managed security credentials for multiple UEs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2437469B1Method and apparatus for establishing a security association
Publication Date: 2013.05.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP2437469B1 patent drawingFigure 1~2
  • EP2437469B1 patent drawingFigure 3~4
  • EP2437469B1 patent drawingFigure 5~6

AI summary

A method for establishing a security association between a User Equipment and a Network Application Function for the purpose of pushing information from the Network Application Function to the User Equipment, where the User Equipment and a Home Subscriber Server share a secret. The method comprises sending a request for generation and provision of a NAF key from the Network Application Function to a Bootstrapping Server Function, the request identifying the User Equipment and the Network Application Function, generating a NAF key at the Bootstrapping Server Function using the identities of the User Equipment and the Network Application Function, the secret, and additional information, and sending the NAF key to the Network Application Function together with said additional information, forwarding said additional information from the Network Application Function to the User Equipment, and at the User Equipment, generating said NAF key using the received additional information and the secret.