Secure Subscription Mapping via Binding Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Generic Bootstrapping Architecture (GBA) lacks a defined and secure method for mapping 3GPP subscriptions to valid user accounts in services, leading to potential security threats and user account misuse.
Innovation Solution
A method is introduced that securely maps a 3GPP subscription to a service user identity by generating a token that binds the subscription to the user account, using a master key for authentication and verification, allowing users to access services using either conventional username/password authentication or GBA, and enabling secure access across multiple devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If service user identity is preconfigured in the HSS/HLR, then authentication can be performed, but security vulnerabilities arise allowing unauthorized account access
Solution Approach 1:
The patent introduces a token as an intermediary element that mediates between the 3GPP subscription and the service user identity. Instead of directly storing or comparing sensitive identity information in the HSS/HLR, the system uses a token that binds the subscription to the service account through a secure mapping relationship. This token acts as a safe mediator that enables authentication without exposing vulnerable direct mappings.
2Ease of operation
If multiple subscriptions are mapped to the same service account, then user convenience is improved, but security risks increase
Solution Approach 1:
The patent segments the authentication process into distinct components: the service account identity, the 3GPP subscription identifiers, and the binding token. Each subscription mapping to the same service account receives its own unique token or binding relationship. This segmentation allows multiple devices to access the same account conveniently while maintaining security through individualized, verifiable binding relationships for each device.
3Adaptability or versatility
If service user identity is configured in the network, then authentication is enabled, but the method is not securely defined
Solution Approach 1:
The patent fundamentally changes the parameter being stored and verified in the network. Instead of storing and comparing service user identities directly in the HSS/HLR, the system stores a token that contains binding information. The authentication process changes from direct identity matching to token verification, where the token's binding relationship between subscription and service account is validated. This parameter change enables flexible multi-device support while ensuring secure, well-defined mapping relationships.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The disclosure relates to methods and nodes for mapping a subscription in a network (10)to a service user identity, wherein a communication device (12) accesses the network (10) using the subscription, and wherein the service user identity is used for accessing a service provided by the first network node (16). The method (30) comprises receiving (31), from the communication device (12) a request for a service, the request comprising an authenticated service user identity, providing (32), in response to the request, the communication device (12) access to the service, receiving (33), from the communication device (12), a message comprising a token identifying a mapping of the service user identity to the subscription, and verifying (34) that a service user identity obtained from the token corresponds to the service user identity used when providing access to the communication device (12).