Secure Element Pre-Authentication for GBA TLS Handshake Efficiency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure communication systems in mobile networks require inefficient bootstrapping operations, leading to increased time and message overhead during TLS handshakes, especially when a fresh bootstrapping operation is needed.
Innovation Solution
A secure element with a secure control unit that determines whether a fresh bootstrapping operation is required directly after session initialization, and if so, executes the bootstrapping operation before establishing the secure communication channel, thereby reducing the number of messages needed for TLS handshake.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a fresh bootstrapping operation is performed during TLS handshake, then security authentication is achieved, but the number of messages increases and handshake time is extended
Solution Approach 1:
The patent applies preliminary action by performing the bootstrapping operation before the TLS handshake process. The secure element executes the bootstrapping to obtain a shared key in advance, so that when the TLS handshake occurs, the key is already available. This eliminates the need to perform bootstrapping during the handshake, reducing message exchanges and time consumption while maintaining security authentication.
2Reliability
If a fresh bootstrapping operation is performed during TLS handshake, then security authentication is achieved, but the number of messages increases
Solution Approach 1:
The patent applies preliminary action by performing the bootstrapping operation before the TLS handshake process. The secure element executes the bootstrapping to obtain a shared key in advance, so that when the TLS handshake occurs, the key is already available. This eliminates the need to perform bootstrapping during the handshake, reducing message exchanges and time consumption while maintaining security authentication.
3Adaptability or versatility
If the terminal device waits for NAF decision on PSK usage, then authentication flexibility is maintained, but communication efficiency is reduced
Solution Approach 1:
The patent applies preliminary action by having the terminal device proactively determine whether PSK authentication is needed before initiating the TLS handshake. The secure element checks if a shared key exists and prepares the authentication method in advance. This allows the device to immediately use the most efficient authentication method without waiting for NAF decisions during the handshake, improving communication efficiency while maintaining authentication flexibility through the pre-check mechanism.
Data Source
AI summary
Provided is a secure element to securely communicate over a mobile communication network, the secure element comprising a secure control unit which is configured to determine, directly after a session with a mobile network entity via a mobile core network being initialized, whether a fresh bootstrapping operation is required, wherein the bootstrapping operation is configured to generate a shared key for establishing a secure communication channel to the mobile network entity, and subsequently establish the secure communication channel to the mobile network entity.


