Service-Specific Identity Binding for Privacy-Preserving Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in wireless communication networks, such as the 3GPP/GAA/SSC procedure, lack the ability to support certificate-based authentication for multiple identities or service-specific identities, making it difficult for users to access multiple services without revealing their real identity or compromising privacy.

Innovation Solution

A method is introduced where a user is allocated multiple service-specific identities, and a request is made to a certification authority to issue a public key certificate binding the service-specific identity with a public key, allowing the user to access specific services while maintaining privacy by using a service identifier and requester identifier pair for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single certificate contains multiple identities, then authentication versatility is improved, but identity privacy and security are worsened because discovering bindings between identities becomes easy

Engineering Contradiction:
Improveauthentication versatilityVSAvoididentity privacy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides a single multi-identity certificate into multiple separate service-specific certificates. Each certificate contains only one service-specific identity bound to a public key, rather than combining multiple identities in one certificate. This segmentation prevents easy discovery of identity bindings while maintaining authentication versatility across multiple services.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a certification authority as an intermediary that issues service-specific certificates based on service identifiers and requester identifiers. The CA maps these identifiers to service-specific identities and issues appropriate certificates, acting as a mediator between the user and service providers while protecting identity privacy through controlled disclosure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If service-specific identities are allocated for each service, then identity privacy is improved, but authentication complexity increases due to multiple certificates and identity mappings

Engineering Contradiction:
Improveidentity privacyVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal certification authority that handles multiple services and issues service-specific certificates through a standardized process. The CA receives service identifiers and requester identifiers as universal inputs and produces appropriate service-specific certificates, simplifying the overall system despite the multiplicity of service-specific identities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent performs preliminary mapping of service identifiers and requester identifiers to service-specific identities before certificate issuance. The certification authority pre-establishes these mappings and issues certificates in advance, so that when authentication is needed, the service-specific identity and certificate are already ready, reducing real-time authentication complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional certificate authentication is used, then authentication reliability is improved, but adaptability to service-specific identities is worsened

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidservice-specific identity support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by making each certificate service-specific rather than generic. Each certificate is tailored to a particular service with its own service-specific identity, allowing the authentication system to maintain reliable certificate-based authentication while adapting to the specific requirements of different services through locally optimized certificate properties.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS7788493B2Authenticating users
Publication Date: 2010.08.31 NOKIA TECHNOLOGIES OY
  • US7788493B2 patent drawing
  • US7788493B2 patent drawing
  • US7788493B2 patent drawing

AI summary

A method of authenticating a user seeking access to a service from a service provider in a communication network, the method comprising: allocating to a user a plurality of service-specific identities for accessing respective services; issuing a request from the user, the request identifying the service to be accessed and including a public key of the user; at a certification authority, authenticating the request and issuing a public key certificate for binding the service-specific identity with the public key in the request, and returning the public key certificate to the user.