Secure Roaming Authentication via Identity-Bound Channels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing roaming models in 3GPP sub-system architectures face challenges in securely authenticating mobile nodes when accessing services via visited networks, particularly due to the risk of 'man-in-the-middle' attacks and inflexibility in configuration, as the mobile node cannot easily verify the trustworthiness of entities in the visited network.

Innovation Solution

A method is introduced to establish a secure transport channel bound to the identity of the service access node, with an authorization request sent to the home network, where the identity is verified through a user challenge, allowing the mobile node to confirm the identity matches the secure channel, ensuring secure access and detecting any changes to the identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the mobile node uses credentials shared only with the home network for authentication, then the authentication security is improved, but the mobile node cannot easily determine whether the entity in the visited network should be trusted

Engineering Contradiction:
Improveauthentication securityVSAvoidtrust verification
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a roaming verification token as an intermediary mechanism that bridges the mobile node and visited network entity trust verification. The token is generated by the home network's authorization node and includes the visited network entity's identity, serving as a mediator that enables the mobile node to verify trust without directly sharing credentials with the visited network entity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The home network performs preliminary authentication and generates a roaming verification token before the mobile node accesses services in the visited network. This preliminary action establishes trust in advance, allowing the mobile node to verify the visited network entity's identity without compromising authentication security during the actual service access.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If global naming restrictions are applied to all entities in the visited networks, then the mobile node can verify that a given entity belongs to a common trust domain, but configuration problems arise and the solution is not flexible

Engineering Contradiction:
Improvetrust domain verificationVSAvoidconfiguration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of applying global naming restrictions to all entities, the patent implements local verification through individual roaming verification tokens for each visited network entity. Each entity receives a specific token from the home network that contains its identity, allowing the mobile node to verify trust on a per-entity basis rather than through rigid global restrictions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The roaming verification token mechanism enables dynamic trust verification where the home network can generate and revoke tokens as needed, rather than relying on static global naming restrictions. This dynamic approach allows the system to adapt to changing configurations and business requirements while maintaining trust verification.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If the mobile node cannot easily verify the trustworthiness of entities in the visited network, then roaming model implementation is simplified, but the system becomes vulnerable to man-in-the-middle attacks

Engineering Contradiction:
Improveroaming model implementationVSAvoidman-in-the-middle attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism where the home network's authorization node verifies the mobile node's credentials and generates a roaming verification token that confirms the visited network entity's identity. This feedback loop provides the mobile node with verified information about the entity it is communicating with, preventing man-in-the-middle attacks without significantly complicating the roaming model implementation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7424284B2Secure network/service access
Publication Date: 2008.09.09 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US7424284B2 patent drawing
  • US7424284B2 patent drawing
  • US7424284B2 patent drawing

AI summary

A method of authenticating a user access network to a mobile node, where the mobile node wishes to access a service via the access network, the method comprising:establishing a secure transport channel between the mobile node and a service access node of the visited network, said channel being bound to an identity of the service access node;sending an authorization request from the mobile node to the service access node, incorporating an identity of the service access node into the request at the service access node, and forwarding the request to an authorization node of the user's home network;at said authorization node of the home network, authorizing the service access node, and sending to the service access node a user challenge including the identity of the service access node, said identity being included in such a way that a change to the identity can be detected by a recipient;at the serving access node, forwarding the received user challenge to the mobile node; andat the mobile node verifying whether or not the identity bound to the secure transport channel matches the identity contained in the received challenge.