Secure Element Pre-Authentication for GBA TLS Handshake Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems in mobile networks require inefficient bootstrapping operations, leading to increased time and message overhead during TLS handshakes, especially when a fresh bootstrapping operation is needed.

Innovation Solution

A secure element with a secure control unit that determines whether a fresh bootstrapping operation is required directly after session initialization, and if so, executes the bootstrapping operation before establishing the secure communication channel, thereby reducing the number of messages needed for TLS handshake.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fresh bootstrapping operation is performed during TLS handshake, then security authentication is achieved, but the number of messages increases and handshake time is extended

Engineering Contradiction:
Improvesecurity authenticationVSAvoidhandshake time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing the bootstrapping operation before the TLS handshake process. The secure element executes the bootstrapping to obtain a shared key in advance, so that when the TLS handshake occurs, the key is already available. This eliminates the need to perform bootstrapping during the handshake, reducing message exchanges and time consumption while maintaining security authentication.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a fresh bootstrapping operation is performed during TLS handshake, then security authentication is achieved, but the number of messages increases

Engineering Contradiction:
Improvesecurity authenticationVSAvoidnumber of messages
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by performing the bootstrapping operation before the TLS handshake process. The secure element executes the bootstrapping to obtain a shared key in advance, so that when the TLS handshake occurs, the key is already available. This eliminates the need to perform bootstrapping during the handshake, reducing message exchanges and time consumption while maintaining security authentication.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the terminal device waits for NAF decision on PSK usage, then authentication flexibility is maintained, but communication efficiency is reduced

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidcommunication efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the terminal device proactively determine whether PSK authentication is needed before initiating the TLS handshake. The secure element checks if a shared key exists and prepares the authentication method in advance. This allows the device to immediately use the most efficient authentication method without waiting for NAF decisions during the handshake, improving communication efficiency while maintaining authentication flexibility through the pre-check mechanism.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250181721A1Secure element, system, and method for efficient authentication in generic bootstrapping architecture (GBA)
Publication Date: 2025.06.05 GIESECKE DEVRIENT MOBILE SECURITY GERMANY GMBH
  • US20250181721A1 patent drawing
  • US20250181721A1 patent drawing
  • US20250181721A1 patent drawing

AI summary

Provided is a secure element to securely communicate over a mobile communication network, the secure element comprising a secure control unit which is configured to determine, directly after a session with a mobile network entity via a mobile core network being initialized, whether a fresh bootstrapping operation is required, wherein the bootstrapping operation is configured to generate a shared key for establishing a secure communication channel to the mobile network entity, and subsequently establish the secure communication channel to the mobile network entity.