Unidirectional GAA Authentication for Broadcast Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional 3GPP GAA and GBA mechanisms fail to perform authentication in scenarios where the client device lacks a bidirectional connection to the network, such as in broadcast networks, preventing secure communication and key derivation.
Innovation Solution
A method for authentication between a client entity and a network, involving a bootstrapping server function and a network application function, where the client entity cannot establish a bidirectional connection, by transmitting authentication information and data unidirectionally, using a network application function to request and process authentication information from the bootstrapping server function, and generating keys for secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If conventional GAA/GBA authentication mechanisms are used, then secure authentication can be achieved in bidirectional communication scenarios, but authentication fails in unidirectional broadcast scenarios where the client cannot send messages back to the network
Solution Approach 1:
The patent inverts the traditional authentication approach by having the network entity initiate and complete the authentication process unidirectionally, rather than requiring bidirectional interaction. The network entity sends authentication information to the client, and the client authenticates the network without needing to send authentication challenges or responses back to the network, thus resolving the contradiction between adaptability to unidirectional scenarios and authentication reliability.
2Adaptability or versatility
If bidirectional communication is required for GAA/GBA authentication, then proper mutual authentication can be established, but the system cannot be applied to broadcast networks with unidirectional connections
Solution Approach 1:
The patent extracts the essential authentication functionality from the bidirectional GAA/GBA protocol, keeping only the necessary unidirectional components. The network entity performs authentication by sending authentication information to the client, and the client uses this information to authenticate the network and derive session keys without requiring any return communication, thus enabling broadcast network applicability while maintaining operational simplicity.
3Adaptability or versatility
If unidirectional authentication is implemented, then broadcast scenarios are supported, but the authentication mechanism deviates from standard GAA/GBA protocols
Solution Approach 1:
The patent implements preliminary action by having the network entity prepare and send all necessary authentication information in a single unidirectional message to the client. The client receives this pre-prepared authentication information and can immediately authenticate the network and derive session keys without needing to engage in further protocol exchanges, thus supporting unidirectional connections while keeping the protocol relatively simple.
Data Source
AI summary
Methods, a client entity, network entities, a system, and a computer program product perform authentication between a client entity and a network. The network includes at least a bootstrapping server function entity and a network application function entity. The client entity is not able to communicate with both of the network entities in a bidirectional manner. The 3GPP standard Ub reference point between the client entity and the bootstrapping server function entity is not utilized for authentication purposes, such as authentication using GAA functionality for unidirectional network connections.


