SET Token Authentication for Discovered Location Servers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SUPL authentication methods are inadequate for discovered location servers (D-SLPs) to authenticate SUPL Enabled Terminals (SETs) due to lack of necessary information or capabilities, particularly when conventional methods like ACA or GBA are not deployable or applicable.

Innovation Solution

The client token method, specifically the SET Token method, is employed, where the Home SLP (H-SLP) provides a digitally signed token containing SET and H-SLP related information to the SET, which the SET then uses to authenticate with the D-SLP, enabling secure access even when conventional authentication methods fail.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods (ACA or GBA) are used for discovered location servers, then authentication can be performed using pre-established trust relationships, but discovered location servers cannot authenticate terminals due to lack of necessary information or capabilities

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication method applicability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a token as an intermediary authentication mechanism. The home location server generates a digitally signed token that serves as a mediator between the terminal and the discovered location server. This token contains terminal identification information and is signed with the home location server's private key, allowing the discovered location server to verify terminal authenticity without needing direct authentication capabilities with the terminal.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into two distinct phases: (1) token generation by the home location server using its private key, and (2) token verification by the discovered location server using the home location server's public key. This segmentation allows each entity to perform only the authentication function it is capable of, while relying on cryptographic mechanisms to bridge the gap.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If discovered location servers are used to provide location services, then service coverage and accessibility are improved, but security cannot be ensured due to inability to authenticate terminals

Engineering Contradiction:
Improvelocation service accessibilityVSAvoidcommunication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The digitally signed token acts as a secure intermediary that bridges the terminal and discovered location server. The token contains terminal identification information signed by the home location server's private key, enabling the discovered location server to verify terminal authenticity and establish secure communication without direct authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameter from direct mutual authentication (which requires pre-established relationships) to token-based authentication (which relies on cryptographic verification). This parameter change enables security in scenarios where conventional authentication methods are not deployable.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If mutual authentication is implemented between terminals and location servers, then secure communication is established, but discovered location servers cannot verify terminal identities due to lack of terminal information

Engineering Contradiction:
Improvemutual authentication securityVSAvoidterminal identification information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The home location server acts as an information intermediary by generating a token that encapsulates terminal identification information. This token is created using the home location server's private key and can be verified by any discovered location server using the home location server's public key, eliminating the need for discovered servers to directly obtain or store terminal information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The home location server performs preliminary authentication and information verification before the terminal communicates with the discovered location server. By generating the authenticated token in advance, the home location server ensures that the terminal's identity is verified before the terminal interacts with any discovered location server.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2813099B1Enabling secure access to a discovered location server for a mobile device
Publication Date: 2019.04.24 QUALCOMM INC
  • EP2813099B1 patent drawingFigure 1A
  • EP2813099B1 patent drawingFigure 1B
  • EP2813099B1 patent drawingFigure 2

AI summary

A method for obtaining a secure connection between a first server and a client. The method may comprise establishing a secure communication session between a second server and the client, wherein the second server is trusted by the first server, and the second server is configured to authenticate the client. The client may receive a client token, wherein the client token contains data associated with the first server, the second server, the client, and a digital signature. Then, the client may request secure communication access to the first server, wherein the request includes transferring the client token to the first server. Finally, the client may receive a grant of secure communication access to the first server based on authentication of the client by the first server, wherein the authentication is based on the client token validating the client and the digital signature validating the client token.