Trusted Application Authentication for Mobile GAA Credentials

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for mobile terminals struggle to effectively manage access permissions for client applications to NAF specific credentials, particularly in ensuring only trusted applications can access these credentials, and authenticating applications to a GAA_ME server in a mobile terminal is challenging, especially in split-terminal scenarios.

Innovation Solution

A method involving a trusted server application external to a universal integrated circuit card performing bootstrapping procedures with a bootstrapping server function to derive a shared key and provide a bootstrapping transaction identifier, allowing authentication and marking applications as trusted, thereby controlling access to NAF specific credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication is performed for every application accessing NAF credentials, then security is improved, but service provider costs increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidservice provider costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the authentication process by introducing a trusted application in the mobile terminal that acts as an intermediary. This trusted application authenticates client applications locally using stored credentials, eliminating the need for the service provider to perform repeated authentication operations for each application access. The segmentation divides the authentication function between the mobile terminal (trusted application) and the service provider, reducing the computational burden and costs for the service provider while maintaining security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If long-term security associations are maintained with each deployed application copy, then access control is improved, but maintenance complexity and costs increase

Engineering Contradiction:
Improveaccess controlVSAvoidmaintenance complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and access control functionality from the service provider's infrastructure and places it within the mobile terminal's trusted application. By taking out the security association management from the service provider domain and embedding it in the client domain (mobile terminal), the system eliminates the need for the service provider to maintain complex long-term security associations with each application copy. The trusted application stores credentials locally and performs authentication autonomously, significantly reducing maintenance complexity for the service provider.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If NAF specific shared secret is made application-specific with access restrictions, then security is improved, but configuration complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the trusted application within the mobile terminal to autonomously manage application-specific access to NAF credentials. The trusted application maintains a local registry of authorized applications and their associated credentials, allowing it to independently authenticate client applications without external intervention. This self-service mechanism simplifies configuration by eliminating the need for complex external configuration management systems, as the trusted application autonomously enforces access restrictions based on locally stored security policies.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2005702B1Authenticating an application
Publication Date: 2017.12.20 NOKIA TECHNOLOGIES OY
  • EP2005702B1 patent drawingFigure 1
  • EP2005702B1 patent drawingFigure 2
  • EP2005702B1 patent drawingFigure 3

AI summary

One aspect of the invention discloses a method of authenticating an application. The method comprising performing, with a server application (408), bootstrapping procedures (412) between the server application (408) and a bootstrapping server function (400); deriving (420, 422) a shared key based on at least a key received from the bootstrapping server function server (400) during the bootstrapping procedures (412) and a network application function identifier; providing (414) an application (406) with a bootstrapping transaction identifier, the bootstrapping transaction identifier being received from the bootstrapping server function server (400) during the bootstrapping procedures (412); receiving a response from the application (406); and authenticating (426) the application by validating the response with the shared key.