Network Application Function Security Feature Profile via Bootstrapping Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the Generic Bootstrapping Architecture (GBA), service providers lack a means to determine if a user equipment (UE) supports specific security features for establishing a security association, particularly when the Network Application Function (NAF) resides outside the operator network and does not have a direct interface to the Home Subscriber Server (HSS).

Innovation Solution

A method where a network application function determines a list of desired user equipment security features, ordered by preference, and sends this list to a database via a bootstrapping server function, receiving a security features response comprising a security key derived from stored information, thereby informing the network application function of the availability of desired security features in the user equipment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If the NAF queries the HSS directly to obtain security feature information, then the NAF can obtain accurate security feature support information, but the NAF cannot access the HSS directly when it resides outside the operator network

Engineering Contradiction:
Improvesecurity feature informationVSAvoidnetwork interface complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent introduces the BSF as an intermediary component between the NAF and HSS. The BSF receives security feature requests from the NAF, queries the HSS on behalf of the NAF, and returns the security feature information to the NAF. This mediator approach allows external NAFs to obtain HSS security information without requiring direct HSS access interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system establishes multiple security associations with different security features, then the service provider can ensure secure communication, but the signaling load increases

Engineering Contradiction:
Improvesecurity association establishmentVSAvoidsignaling load
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent implements preliminary action by having the NAF query the HSS for the user's security feature support capabilities before establishing security associations. This advance knowledge allows the NAF to select the most appropriate security features and establish security associations efficiently without unnecessary trial-and-error signaling exchanges.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables dynamic selection of security features based on the user equipment's supported capabilities. The system can adaptively choose from multiple security feature options (such as different authentication methods or encryption algorithms) depending on what the UE supports, optimizing the balance between security and signaling efficiency for each specific connection.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2510717B1Smart card security feature profile in home subscriber server
Publication Date: 2020.03.04 NOKIA TECHNOLOGIES OY
  • EP2510717B1 patent drawingFigure 1~2
  • EP2510717B1 patent drawingFigure 3
  • EP2510717B1 patent drawingFigure 4A~4B

AI summary

In accordance with the exemplary embodiments of the invention there is at least a method, an executable computer program, and an apparatus to determine at a network application function a list of desired user equipment security features to be used, the security features of the list ordered by preference of the network application function, send the list to a database of user security settings via a bootstrapping server function, and receive by the network application function, via the bootstrapping server function, a security features response including a security key,derived from information stored in the database, corresponding to a desired security feature contained in the list, thereby informing the network application function of the availability of at least one of the desired security features in the user equipment.