Network Access Server GBA Security Association Setup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing GBA authentication procedure in mobile networks requires separate and consecutive authentication steps, leading to redundant signaling and complexity, particularly requiring the mobile terminal to open an HTTP connection for security association establishment, which is not necessary for all IP connections.

Innovation Solution

Integrating the GBA security association setup with network attachment operations in a network access server, using Diameter protocol requests and responses to provide security association parameters directly to the terminal, eliminating the need for a separate HTTP connection and simplifying the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal opens an HTTP connection to establish GBA security association, then the security association can be established with the BSF server, but the signaling overhead increases and the process becomes more complex

Engineering Contradiction:
Improvesecurity association establishmentVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the GBA security association establishment process with the existing network attachment procedure. The network access server integrates both functions, allowing the terminal to establish security associations during network attachment without requiring a separate HTTP connection to the BSF server. This merging eliminates redundant signaling and simplifies the overall authentication process while maintaining security association establishment reliability.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If separate authentication steps are performed for network attachment and GBA security association, then each authentication can be completed thoroughly, but the overall authentication time increases

Engineering Contradiction:
Improveauthentication completenessVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs the GBA security association establishment as a preliminary action during the network attachment process. The network access server retrieves security association parameters from the BSF server and provides them to the terminal before the terminal needs to establish IP connections. This preliminary action ensures authentication completeness is achieved while reducing the time required for subsequent authentication operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the terminal performs double authentication (network connection and application security association), then security is enhanced, but the signaling overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The network access server is designed to perform multiple functions: it handles both network attachment authentication and GBA security association establishment. By making the network access server universal, the patent eliminates the need for separate HTTP-based authentication signaling to the BSF server. The security is maintained through proper integration of GBA parameters, while signaling overhead is reduced by consolidating authentication functions in a single server.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2692164B1Putting in place of a security association of gba type for a terminal in a mobile telecommunications network
Publication Date: 2019.12.11 ORANGE SA
  • EP2692164B1 patent drawingFigure 1
  • EP2692164B1 patent drawingFigure 2

AI summary

The invention relates to a method of putting in place a security association of GBA type for a terminal, comprising the following steps, executed in a network access server, following the receipt of a request for attachment to the network from the terminal: dispatching (E2) of a request for association of security to a priming function server, reception (E5) of a response comprising security association parameters, from the priming function server, dispatching (E5) of a message comprising the security association parameters to the terminal.