Trusted Application Authentication for Mobile GAA Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for mobile terminals struggle to effectively manage access permissions for client applications to NAF specific credentials, particularly in ensuring only trusted applications can access these credentials, and authenticating applications to a GAA_ME server in a mobile terminal is challenging, especially in split-terminal scenarios.
Innovation Solution
A method involving a trusted server application external to a universal integrated circuit card performing bootstrapping procedures with a bootstrapping server function to derive a shared key and provide a bootstrapping transaction identifier, allowing authentication and marking applications as trusted, thereby controlling access to NAF specific credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication is performed for every application accessing NAF credentials, then security is improved, but service provider costs increase significantly
Solution Approach 1:
The patent segments the authentication process by introducing a trusted application in the mobile terminal that acts as an intermediary. This trusted application authenticates client applications locally using stored credentials, eliminating the need for the service provider to perform repeated authentication operations for each application access. The segmentation divides the authentication function between the mobile terminal (trusted application) and the service provider, reducing the computational burden and costs for the service provider while maintaining security.
2Reliability
If long-term security associations are maintained with each deployed application copy, then access control is improved, but maintenance complexity and costs increase
Solution Approach 1:
The patent extracts the authentication and access control functionality from the service provider's infrastructure and places it within the mobile terminal's trusted application. By taking out the security association management from the service provider domain and embedding it in the client domain (mobile terminal), the system eliminates the need for the service provider to maintain complex long-term security associations with each application copy. The trusted application stores credentials locally and performs authentication autonomously, significantly reducing maintenance complexity for the service provider.
3Reliability
If NAF specific shared secret is made application-specific with access restrictions, then security is improved, but configuration complexity increases
Solution Approach 1:
The patent implements self-service by enabling the trusted application within the mobile terminal to autonomously manage application-specific access to NAF credentials. The trusted application maintains a local registry of authorized applications and their associated credentials, allowing it to independently authenticate client applications without external intervention. This self-service mechanism simplifies configuration by eliminating the need for complex external configuration management systems, as the trusted application autonomously enforces access restrictions based on locally stored security policies.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
One aspect of the invention discloses a method of authenticating an application. The method comprising performing, with a server application (408), bootstrapping procedures (412) between the server application (408) and a bootstrapping server function (400); deriving (420, 422) a shared key based on at least a key received from the bootstrapping server function server (400) during the bootstrapping procedures (412) and a network application function identifier; providing (414) an application (406) with a bootstrapping transaction identifier, the bootstrapping transaction identifier being received from the bootstrapping server function server (400) during the bootstrapping procedures (412); receiving a response from the application (406); and authenticating (426) the application by validating the response with the shared key.