SET Token Authentication for Discovered Location Servers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SUPL authentication methods are inadequate for discovered location servers (D-SLPs) to authenticate SUPL Enabled Terminals (SETs) due to lack of necessary information or capabilities, particularly when conventional methods like ACA or GBA are not deployable or applicable.
Innovation Solution
The client token method, specifically the SET Token method, is employed, where the Home SLP (H-SLP) provides a digitally signed token containing SET and H-SLP related information to the SET, which the SET then uses to authenticate with the D-SLP, enabling secure access even when conventional authentication methods fail.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication methods (ACA or GBA) are used for discovered location servers, then authentication can be performed using pre-established trust relationships, but discovered location servers cannot authenticate terminals due to lack of necessary information or capabilities
Solution Approach 1:
The patent introduces a token as an intermediary authentication mechanism. The home location server generates a digitally signed token that serves as a mediator between the terminal and the discovered location server. This token contains terminal identification information and is signed with the home location server's private key, allowing the discovered location server to verify terminal authenticity without needing direct authentication capabilities with the terminal.
Solution Approach 2:
The authentication process is segmented into two distinct phases: (1) token generation by the home location server using its private key, and (2) token verification by the discovered location server using the home location server's public key. This segmentation allows each entity to perform only the authentication function it is capable of, while relying on cryptographic mechanisms to bridge the gap.
2Adaptability or versatility
If discovered location servers are used to provide location services, then service coverage and accessibility are improved, but security cannot be ensured due to inability to authenticate terminals
Solution Approach 1:
The digitally signed token acts as a secure intermediary that bridges the terminal and discovered location server. The token contains terminal identification information signed by the home location server's private key, enabling the discovered location server to verify terminal authenticity and establish secure communication without direct authentication capabilities.
Solution Approach 2:
The patent changes the authentication parameter from direct mutual authentication (which requires pre-established relationships) to token-based authentication (which relies on cryptographic verification). This parameter change enables security in scenarios where conventional authentication methods are not deployable.
3Reliability
If mutual authentication is implemented between terminals and location servers, then secure communication is established, but discovered location servers cannot verify terminal identities due to lack of terminal information
Solution Approach 1:
The home location server acts as an information intermediary by generating a token that encapsulates terminal identification information. This token is created using the home location server's private key and can be verified by any discovered location server using the home location server's public key, eliminating the need for discovered servers to directly obtain or store terminal information.
Solution Approach 2:
The home location server performs preliminary authentication and information verification before the terminal communicates with the discovered location server. By generating the authenticated token in advance, the home location server ensures that the terminal's identity is verified before the terminal interacts with any discovered location server.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
A method for obtaining a secure connection between a first server and a client. The method may comprise establishing a secure communication session between a second server and the client, wherein the second server is trusted by the first server, and the second server is configured to authenticate the client. The client may receive a client token, wherein the client token contains data associated with the first server, the second server, the client, and a digital signature. Then, the client may request secure communication access to the first server, wherein the request includes transferring the client token to the first server. Finally, the client may receive a grant of secure communication access to the first server based on authentication of the client by the first server, wherein the authentication is based on the client token validating the client and the digital signature validating the client token.