NAF Key Establishment via BSF Inversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for establishing a security association between a client terminal and a service node in 3G networks are vulnerable to threats such as manipulation and replay attacks, especially when the service node initiates the connection, as they rely on insecure communication channels like SMS for push-type services.
Innovation Solution
A method where the Network Application Function (NAF) initiates the establishment of a security association with the User Equipment (UE) by requesting a NAF key from the Bootstrapping Server Function (BSF), using identities and a shared secret to generate and sign key material, allowing the UE to derive and verify the NAF key for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the service node initiates connection using SMS or similar channels to establish security association, then the service can be delivered to users, but the communication channel is vulnerable to manipulation and replay attacks
Solution Approach 1:
The patent applies preliminary action by establishing the security association before the actual service data transmission. The NAF initiates the security association setup in advance, obtaining security context and keys before pushing service information to the UE. This pre-establishment of security credentials prevents manipulation and replay attacks on the service delivery channel, as the security framework is already in place before any service communication occurs.
2Reliability
If the UE initiates the security association establishment by sending B-TID to NAF, then the security association can be established, but the UE must continuously initiate requests which reduces efficiency
Solution Approach 1:
The patent applies inversion by reversing the traditional initiation direction. Instead of the UE initiating the security association establishment by sending B-TID to the NAF, the NAF initiates the process by sending a request to the BSF to obtain security context. This role reversal allows the service node to proactively establish security associations, eliminating the need for continuous UE-initiated requests and significantly improving efficiency for push-type services.
3Reliability
If the NAF requests security context from BSF using UE identity, then the security association can be established before data transmission, but additional signaling steps are required
Solution Approach 1:
The patent applies the intermediary principle by introducing the BSF as a mediator between the NAF and the security credential storage. The NAF sends a request to the BSF containing the UE identity, and the BSF retrieves the appropriate security context (including B-TID and authentication vectors) from the HSS or local storage. This intermediary approach streamlines the process by centralizing security credential management, reducing the complexity that would otherwise exist if the NAF directly managed security credentials for multiple UEs.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
A method for establishing a security association between a User Equipment and a Network Application Function for the purpose of pushing information from the Network Application Function to the User Equipment, where the User Equipment and a Home Subscriber Server share a secret. The method comprises sending a request for generation and provision of a NAF key from the Network Application Function to a Bootstrapping Server Function, the request identifying the User Equipment and the Network Application Function, generating a NAF key at the Bootstrapping Server Function using the identities of the User Equipment and the Network Application Function, the secret, and additional information, and sending the NAF key to the Network Application Function together with said additional information, forwarding said additional information from the Network Application Function to the User Equipment, and at the User Equipment, generating said NAF key using the received additional information and the secret.