Secure Subscription Mapping via Binding Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Generic Bootstrapping Architecture (GBA) lacks a defined and secure method for mapping 3GPP subscriptions to valid user accounts in services, leading to potential security threats and user account misuse.

Innovation Solution

A method is introduced that securely maps a 3GPP subscription to a service user identity by generating a token that binds the subscription to the user account, using a master key for authentication and verification, allowing users to access services using either conventional username/password authentication or GBA, and enabling secure access across multiple devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If service user identity is preconfigured in the HSS/HLR, then authentication can be performed, but security vulnerabilities arise allowing unauthorized account access

Engineering Contradiction:
Improveauthentication securityVSAvoidunauthorized account access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a token as an intermediary element that mediates between the 3GPP subscription and the service user identity. Instead of directly storing or comparing sensitive identity information in the HSS/HLR, the system uses a token that binds the subscription to the service account through a secure mapping relationship. This token acts as a safe mediator that enables authentication without exposing vulnerable direct mappings.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If multiple subscriptions are mapped to the same service account, then user convenience is improved, but security risks increase

Engineering Contradiction:
Improvemulti-device accessVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into distinct components: the service account identity, the 3GPP subscription identifiers, and the binding token. Each subscription mapping to the same service account receives its own unique token or binding relationship. This segmentation allows multiple devices to access the same account conveniently while maintaining security through individualized, verifiable binding relationships for each device.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If service user identity is configured in the network, then authentication is enabled, but the method is not securely defined

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidmapping security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent fundamentally changes the parameter being stored and verified in the network. Instead of storing and comparing service user identities directly in the HSS/HLR, the system stores a token that contains binding information. The authentication process changes from direct identity matching to token verification, where the token's binding relationship between subscription and service account is validated. This parameter change enables flexible multi-device support while ensuring secure, well-defined mapping relationships.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3180934B1Methods and nodes for mapping subscription to service user identity
Publication Date: 2018.10.31 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3180934B1 patent drawingFigure 1
  • EP3180934B1 patent drawingFigure 2
  • EP3180934B1 patent drawingFigure 3

AI summary

The disclosure relates to methods and nodes for mapping a subscription in a network (10)to a service user identity, wherein a communication device (12) accesses the network (10) using the subscription, and wherein the service user identity is used for accessing a service provided by the first network node (16). The method (30) comprises receiving (31), from the communication device (12) a request for a service, the request comprising an authenticated service user identity, providing (32), in response to the request, the communication device (12) access to the service, receiving (33), from the communication device (12), a message comprising a token identifying a mapping of the service user identity to the subscription, and verifying (34) that a service user identity obtained from the token corresponds to the service user identity used when providing access to the communication device (12).