Network Access Server GBA Security Association Setup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing GBA authentication procedure in mobile networks requires separate and consecutive authentication steps, leading to redundant signaling and complexity, particularly requiring the mobile terminal to open an HTTP connection for security association establishment, which is not necessary for all IP connections.
Innovation Solution
Integrating the GBA security association setup with network attachment operations in a network access server, using Diameter protocol requests and responses to provide security association parameters directly to the terminal, eliminating the need for a separate HTTP connection and simplifying the authentication process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the terminal opens an HTTP connection to establish GBA security association, then the security association can be established with the BSF server, but the signaling overhead increases and the process becomes more complex
Solution Approach 1:
The patent combines the GBA security association establishment process with the existing network attachment procedure. The network access server integrates both functions, allowing the terminal to establish security associations during network attachment without requiring a separate HTTP connection to the BSF server. This merging eliminates redundant signaling and simplifies the overall authentication process while maintaining security association establishment reliability.
2Reliability
If separate authentication steps are performed for network attachment and GBA security association, then each authentication can be completed thoroughly, but the overall authentication time increases
Solution Approach 1:
The patent performs the GBA security association establishment as a preliminary action during the network attachment process. The network access server retrieves security association parameters from the BSF server and provides them to the terminal before the terminal needs to establish IP connections. This preliminary action ensures authentication completeness is achieved while reducing the time required for subsequent authentication operations.
3Reliability
If the terminal performs double authentication (network connection and application security association), then security is enhanced, but the signaling overhead increases
Solution Approach 1:
The network access server is designed to perform multiple functions: it handles both network attachment authentication and GBA security association establishment. By making the network access server universal, the patent eliminates the need for separate HTTP-based authentication signaling to the BSF server. The security is maintained through proper integration of GBA parameters, while signaling overhead is reduced by consolidating authentication functions in a single server.
Data Source
Figure 1
Figure 2
AI summary
The invention relates to a method of putting in place a security association of GBA type for a terminal, comprising the following steps, executed in a network access server, following the receipt of a request for attachment to the network from the terminal: dispatching (E2) of a request for association of security to a priming function server, reception (E5) of a response comprising security association parameters, from the priming function server, dispatching (E5) of a message comprising the security association parameters to the terminal.