Generic key-decision mechanism for gaa
Abstract
This record has no abstract on file.
Term
Term ended
Projected expiry passed 4 April 2026, 0.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
16 claims: 9 independent, 7 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method including:1. Sposób obejmujący: odbiór (200) żądania ze sprzętu użytkownika, aby dostarczyć informację autoryzującą do funkcji aplikacji sieciowej;receiving (200) a request from the user equipment to provide authorization information for the network application function;determining (210) a generic authorization architecture key to integrate additional web application servers by extending the existing user security standard;and providing (220) authorization information for the functions of the web application;określenie (210) klucza generycznej architektury autoryzującej, aby zintegrować dodatkowe serwery aplikacji sieciowej przez rozbudowę istniejącego standardu ustawień bezpieczeństwa użytkownika;i dostarczenie (220) informacji autoryzującej do funkcji aplikacji sieciowej;przy czym istniejący standard ustawień bezpieczeństwa użytkownika jest rozbudowany przez: whereby the existing standard of user security settings is expanded by: providing data on the type of smart card or secure environment in the user equipment in the user's security settings;and providing a flagged field that informs whether the generic bootstrapping architecture, along with integrated improvements based on integrated circuits (GBA U), supports the universal subscriber identity module, subscriber identity module, IMS SIM card or a secure environment. zapewnienie danych dotyczących rodzaju inteligentnej karty lub bezpiecznego środowiska w sprzęcie użytkownika w ustawieniach bezpieczeństwa użytkownika;i zapewnienie oflagowanego pola informującego, czy generyczna architektura bootstrapping wraz ze zintegrowanymi udoskonaleniami w oparciu o układy scalone (GBA U) obsługuje uniwersalny moduł tożsamości abonenta, moduł tożsamości abonenta, kartę SIM IMS lub bezpieczne środowisko.
- 2A method including:2. Sposób obejmujący: odbiór (200) żądania ze sprzętu użytkownika, aby dostarczyć informację autoryzującą do funkcji aplikacji sieciowej;receiving (200) a request from the user equipment to provide authorization information for the network application function;determining (210) a generic authorization architecture key to integrate additional web application servers by extending the existing user security standard;and providing (220) authorization information for the functions of the web application;określenie (210) klucza generycznej architektury autoryzującej, aby zintegrować dodatkowe serwery aplikacji sieciowej przez rozbudowę istniejącego standardu ustawień bezpieczeństwa użytkownika;i dostarczenie (220) informacji autoryzującej do funkcji aplikacji sieciowej;przy czym istniejący standard ustawień bezpieczeństwa użytkownika jest rozbudowany przez: whereby the existing standard of user security settings is expanded by: providing the first and second flagged fields in user security settings that are transferred in the specification authorization header, with the first flagged field, the first key obtained (Ks int NAF) is used in enhancements based on integrated circuits (GBAU) and the second flagged the field uses the second obtained key (Ks_ext_NAF) or the third obtained key (Ks NAF). zapewnienie pierwszego i drugiego oflagowanego pola w ustawieniach bezpieczeństwa użytkownika, które są przenoszone w nagłówku autoryzacyjnym specyfikacji, przy czym w pierwszym oflagowanym polu, pierwszy uzyskany klucz (Ks int NAF) jest wykorzystywany w ulepszeniach w oparciu o układy scalone (GBAU), a w drugim oflagowanym polu jest wykorzystywany drugi uzyskany klucz (Ks_ext_NAF) lub trzeci uzyskany klucz (Ks NAF).
- 3The method of any of the preceding claims, wherein the determining step comprises determining at least one of:3. Sposób według dowolnego z powyższych zastrzeżeń, w którym etap określania obejmuje określenie co najmniej jednego spośród: local configuration of key usage directly in the network application function during configuration of the network application function;lokalnej konfiguracji wykorzystania klucza bezpośrednio w funkcji aplikacji sieciowej podczas konfiguracji funkcji aplikacji sieciowej;local configuration of key usage in the server bootstrapping function;lokalnej konfiguracji wykorzystania klucza w funkcji serwera bootstrapping;- providing an additional field in the user's security settings, saved in the subscriber's home server, which is transferred in the function of the bootstrapping server;and using the pair-value-attribute stored in the bootstrapping server function, which indicates key usage. -12zapewnienia dodatkowego pola w ustawieniach bezpieczeństwa użytkownika, zapisanych w domowym serwerze abonenta, które jest przekazywane w funkcji serwera bootstrapping;i wykorzystania atrybutu-wartości-pary zapisanej w funkcji serwera bootstrapping, która informuje o wykorzystaniu klucza.
- 4The method of any of the preceding claims, further comprising:4. Sposób według dowolnego z powyższych zastrzeżeń, obejmujący ponadto: using the pair-value-attribute to specify the type of derivative key used, or the type of smart card or secure environment supported, where the type of derived key includes KsintNAF, Ks_ext_NAF or Ks NAF, and the smart card or secure environment includes GBA U. wykorzystanie atrybutu-wartości-pary do określenia rodzaju wykorzystywanego klucza pochodnego albo obsługiwanego rodzaju inteligentnej karty lub bezpiecznego środowiska, przy czym rodzaj klucza pochodnego obejmuje KsintNAF, Ks_ext_NAF lub Ks NAF, a inteligentna karta lub bezpieczne środowisko obejmuje GBA U.
- 8The method of any of the preceding claims, further comprising:8. Sposób według dowolnego z powyższych zastrzeżeń, obejmujący ponadto: local configuration of key usage in the bootstrapping server (BSF) function, providing an additional field in the user security settings saved in the subscriber's home server (HSS). lokalną konfigurację wykorzystania klucza w funkcji serwera bootstrapping (BSF), zapewniając dodatkowe pole w ustawieniach bezpieczeństwa użytkownika, zapisanych w domowym serwerze abonenta (HSS).
- 9A device containing:9. Urządzenie zawierające: a receiving means (152) for receiving a request from the user equipment to provide authorization information for the function of the network application;the determining means (154) for determining the generic authorization architecture key to integrate additional network application servers by extending the existing user security settings standard;and a first providing means (156) for providing authorization information for the functions of the web application, wherein the existing standard of user security settings is enhanced by: środek odbierający (152) do odbioru żądania ze sprzętu użytkownika, aby dostarczyć informację autoryzującą do funkcji aplikacji sieciowej;środek określający (154) do określania klucza generycznej architektury autoryzującej, aby zintegrować dodatkowe serwery aplikacji sieciowej przez rozbudowę istniejącego standardu ustawień bezpieczeństwa użytkownika;i pierwszy środek dostarczający (156) do dostarczania informacji autoryzującej do funkcji aplikacji sieciowej, przy czym istniejący standard ustawień bezpieczeństwa użytkownika jest rozbudowany o: - a second delivery means for providing data on the type of smart card or secure environment in the user equipment in the user security settings;and a third delivery means to provide a flagged field informing whether the generic bootstrapping architecture with integrated integrated circuits (GBA U) supports the universal subscriber identity module, subscriber identity module, IMS SIM card or secure environment. -13drugi środek dostarczający do dostarczania danych dotyczących rodzaju inteligentnej karty lub bezpiecznego środowiska w sprzęcie użytkownika w ustawieniach bezpieczeństwa użytkownika;i trzeci środek dostarczający do zapewniania oflagowanego pola informującego, czy generyczna architektura bootstrapping wraz ze zintegrowanymi udoskonaleniami w oparciu o układy scalone (GBA U) obsługuje uniwersalny moduł tożsamości abonenta, moduł tożsamości abonenta, kartę SIM IMS lub bezpieczne środowisko.
- 10A device containing:10. Urządzenie zawierające: a receiving means (152) for receiving a request from the user equipment to provide authorization information for the function of the network application;the determining means (154) for determining the generic authorization architecture key to integrate additional network application servers by extending the existing user security settings standard;and a first providing means (156) for providing authorization information for the functions of the network application;środek odbierający (152) do odbioru żądania ze sprzętu użytkownika, aby dostarczyć informację autoryzującą do funkcji aplikacji sieciowej;środek określający (154) do określania klucza generycznej architektury autoryzującej, aby zintegrować dodatkowe serwery aplikacji sieciowej przez rozbudowę istniejącego standardu ustawień bezpieczeństwa użytkownika;i pierwszy środek dostarczający (156) do dostarczenia informacji autoryzującej do funkcji aplikacji sieciowej;przy czym istniejący standard ustawień bezpieczeństwa użytkownika jest rozbudowany przez: whereby the existing standard of user security settings is expanded by: a second delivery means to provide the first and second flagged fields in the user security settings that are carried in the specification authorization header, wherein in the first flagged field, the first key obtained (KsintNAF) is used in integrated circuit improvements (GBA U), and the second flagged field uses the second key obtained (Ks_ext_NAF) or the third key obtained (Ks NAF) drugi środek dostarczający do zapewniania pierwszego i drugiego oflagowanego pola w ustawieniach bezpieczeństwa użytkownika, które są przenoszone w nagłówku autoryzacyjnym specyfikacji, przy czym w pierwszym oflagowanym polu, pierwszy uzyskany klucz (KsintNAF) jest wykorzystywany w ulepszeniach w oparciu o układy scalone (GBA U), a w drugim oflagowanym polu jest wykorzystywany drugi uzyskany klucz (Ks_ext_NAF) lub trzeci uzyskany klucz (Ks NAF)
- 15The device according to any of claims 9 to 14, also containing:15. Urządzenie według dowolnego z zastrz. 9 do 14, zawierające ponadto: a third encoding means persistent for local configuration of key usage in the bootstrapping server (BSF) function, providing an additional field in the user security settings stored on the subscriber's home server (HSS). trzeci środek kodowania trwały do lokalnej konfiguracji wykorzystania klucza w funkcji serwera bootstrapping (BSF), zapewniając dodatkowe pole w ustawieniach bezpieczeństwa użytkownika, zapisanych w domowym serwerze abonenta (HSS).
- 16A computer program contained in a computer-readable medium, the computer program being configured to implement a method comprising all the steps of any one of claims. 1 to 8. 16. Program komputerowy zawarty w nośniku czytelnym dla komputera, przy czym program komputerowy jest skonfigurowany to realizacji sposobu obejmującego wszystkie etapy z dowolnego z zastrz. 1 do 8. Prepared and verified Sporządziła i zweryfikowała Grażyna Palka Patent Attorney Grażyna Palka Rzecznik patentowy -15FIG. 1 A -15FIG. 1 A. -16FIG. IB -16FIG. IB -17FIG, 2 dd funkcji aplikacji sieciowej -17FIG, 2 dd network application functions FIG. 3 FIG. 3 -18FIG. 4 -18FIG. 4 300 300
Independent claims9
102 paragraphs, as filed
[0001] The invention relates to a generic mechanism for an application server which determines which of the GAA (Generic Authentication Architecture) keys will allow easy integration of additional application servers by extending the existing USS (User Security Settings) standard.
2. Description of the Related Art [0002] Pre-authorization (i.e. bootstrapping) in 3GPP (Third Generation Project Partnership) of GAA (Generic Authentication Architecture) is based on the AKA (Authentication and Key Agreement Protocol). Depending on the mobile terminal, for example a mobile phone and the Integrated Circuit Card (UICC) of the UMTS (Universal Mobile Telecommunications System) or the subscriber's identity module entered into the mobile terminal, the GAA (Generic Authentication Architecture) 3GPP might have the following keys: Ks int NAF, Ks_ext_NAF and KsNAF. Currently, the number of services using GAA is quite small and determining which key to use, in the case of a given smart card or subscriber identity module, can be entered directly on the NAF server (Network Application Function), which offers the user a given service. However, this type of server introduction is not scalable enough or easy to manage in the event of changes, such as new uses and changes or upgrades of existing services, or the user obtaining a new smart card. NAF changes or updates require manual configuration, which is extremely difficult if the NAF is not in the user's or subscriber's home network, but in a third party network.
[0003] The key Ks int NAF is used to secure the HTTPS (Hypertext Transport Protocol) between the smart card or subscriber identity module and the NAF application server. The application can be present on a smart card or subscriber identity module, and the mobile terminal can only be used as a modem. This mechanism can serve as an alternative to current OTA SMS configuration messages to download new updates or other types of SAT applications.
[0004] Currently, the only application of the Ks int NAF key is MBMS (Multimedia Broadcast / Multicast Service). In MBMS, NAF is configured according to the definition in TS33.246 3GPP specification, attached here as Annex A, the content of which has been introduced by reference. In MBMS, the choice of which key to use is defined based on the description of specific keys in the TS33.246 specification. Therefore, in this case, no key selection mechanism is required because the key is entered directly into NAF, which offers the MBMS service to the user.
[0005] A further state of the art is: 3GPP DRAFT; S3-030729, "UE triggered unsolicited push from BSF to NAFs" NOKIA and 3GPP TS 33.220 version 6.4.0 release 6; Generic bootstrapping architecture (GAA); ETSI TS 133 220.
Summary of the Invention [0006] The invention is defined in the appended claims.
[0007] According to an embodiment of the invention, a method of providing a generic mechanism for a web application server is provided. The method includes receiving a request from the user equipment to provide authorization information for the network application function. The method includes specifying a generic authorization architecture key to integrate additional network application servers by extending the existing user security standard. The method further includes providing authorization information for the functions of the web application.
[0008] According to an embodiment of the invention, a device is provided that provides a generic mechanism for a network application server. A receiving means for receiving a request from the user equipment to provide authorization information for the function of the web application. A determining agent for determining the generic authorization architecture key to integrate additional web application servers by extending the existing user security standard. The first delivery means to provide authorization information for the functions of the web application.
[0009] According to an embodiment of the invention, a device is provided that provides a generic mechanism for a network application server. The receiver receives requests from the user equipment to provide authorization information for the function of the network application. The determining unit defines the key of the generic authorization architecture to integrate additional web application servers by extending the existing user security settings standard. The delivery unit provides authorization information for the functions of the web application.
Brief description of the drawings [0010] The accompanying drawings, which have been introduced here for further explanation of the invention, form part of the description and present examples of the embodiment of the invention, and together with the description explain the advantages and principles of the invention, in which:
FIG. 1A shows a device providing a generic mechanism for a network application server, according to an embodiment of the invention;
FIG. IB illustrates an example network architecture in which the function of the network application is in a visited network, according to an embodiment of the invention;
FIG. 2 illustrates a device providing a generic mechanism for a network application server, according to an embodiment of the invention;
FIG. 3 illustrates a method providing a generic mechanism for a network application server according to an embodiment of the invention; and
-3FIG. 4 illustrates a method providing a generic mechanism for a network application server according to another embodiment of the invention.
Shortcut table [0011]
3GPP - 3<sup>rd</sup> Generation Partnership Project [third generation partner project]
3GPP2 - 3<sup>rd</sup> Generation Partnership Project 2 [3rd generation partner project] ACM —Address Complete Message
AKA - Authentication and Key Agreement [key authorization and agreement]
Auth -Authentication [authorization]
AUTHR —Authentication Response [authorization reaction]
AVP - Attribute-Value-Pair [attribute-value-pair]
BS —Base Station [base station]
BSC —Base Station Controller [base station controller]
BSF —Bootstrapping Server Function [bootstrapping server function]
BTS —Bas e station Transceiver Subsystem [base station transceiver subsystem]
CK - Confidentiality Key [confidential key]
CM - Cellular Message [cell message]
GAA - Generic Authentication Architecture [generic authorization architecture]
GBA - Generic Bootstrapping Architecture [generic bootstrapping architecture]
GBA U - GBA with UICC-based enhancements [BGA with improvements based on UICC]
GUSS - GBA User Security Settings [GBA user security settings]
HSS - Home Subscriber Server [home subscriber server]
HTTP - Hypertext Transport Protocol [protocol for sending hypertext documents]
HTTPS - Secured Hypertext Transport Protocol [secured protocol for sending hypertext documents]
IK - Integrity Key [integration key]
IMS —IP Multimedia Subsystem [IP multimedia subsystem]
IMSI — International Mobile Subscriber Identity [international identity of a mobile subscriber]
-4IP — Internet Protocol
ISIM - IMS SIM card [SIMIMS card]
Kc - Ciphering Key [encryption key]
Ki —Individual Subscriber Authentication Key [individual subscriber authorization key]
Ks - Key Material
KsintNAF - Derived key in GBAU which remains on UICC [A7wcz resulting in GBAU, which remains on UICC]
Ks_ext_NAF - Derived key in GBA U [result key in GBA U]
KsNAF — Derived Key in GBA ME [result key in GBAME]
MAP —Mobile Application Part [part of the mobile application]
MBMS - Multimedia Broadcast / Multicast Service
ME - Mobile Eqipment [mobile equipment]
MIN —Mobile Identification Number [mobile authorization number]
MNO - Home Mobile NetWork Operator [home mobile network operator]
MO —Mobile Originated [mobile]
NAF - Network Application Function
NE - Network Element [network element]
OTA — Over The Air
PDSN —Packet Data Service Node [packet data service node]
PLC — Private Long Coda [long private code]
PLCM -PLC Mask
PSTN —Public Switched Telephone Network
RAN — Radio Access Network [radio network]
RAND —Random Challenge Data
SAT —SIM Application Toolkit
SIM —Subscriber Identity Module [subscriber identity module]
SMS —Short Message Service [short message services]
UE - User Eąuipment [user equipment]
UICC - UMTS Integrated Circuit Card [UMTS integrated card]
-5UMTS - Universal Mobile Telecommunications System [universal mobile telecommunications system]
USIM —Universal SIM card [universal SIM card \
USS - User Security Settings [user security settings]
Ub —Bootstrapping air interface (from UE to BSF) [wireless bootstrapping interface (from UE to BSF)]
Zh —HSS interface from BSF [HSS interface from BSF]
Detailed Description of Preferred Embodiments [0012] 3GPP is the proposed authorization infrastructure (3GPP TS 33.220, incorporated herein as Annex B, the content of which is incorporated by reference). This infrastructure can be used to run the application functions on the network side and on the user side to communicate in situations where the network side and user side could not otherwise connect. This function is called "application security bootstrapping" or more generally simply "bootstrapping".
[0013] The general principle of bootstrapping is that the generic BSF (bootstrapping server function) allows user equipment (UE) to authorize and reconcile session keys. Such authorization may be based on AKA (authentication and key agreement). By launching AKA, the mobile terminal and the network authorize each other and agree on the keys, primarily the confidentiality key (CK) and the integrity key (IK). After authorization, UE and NAF (network application function), which can also be called a service provider, can support some application-specific protocol in which message authorization is based on session keys agreed between UE and BSF.
[0014] The bootstrapping function is not dependent on any particular function of the network application. The server implementing the bootstrapping function must have operator confidence and be able to support authorization vectors. The functions of the web application can be supported by the operator's home network, visited network or third party network.
[0015] FIG. IA illustrates an example network architecture according to an embodiment of the invention. The network architecture includes user equipment (UE) 100, at least one network application function (NAF) 102, bootstrapping server function (BSF) 104 and home subscriber system (HSS) 106. BSF 104 and HSS 106 are part of the mobile home network operator (MNO) 108. UE 100 connects to MNO 108 according to well-known mobile communication techniques.
[0016] NAF 102 is located in the network element, under the control of MNO 108, for example BSF can also be located in the network element and be controlled by MNO 108. Thus, for practical reasons, each NAF 102 and BSF 104 can be considered as network element.
[0017] As shown in FIG. IA, UE 100 communicates with NAF 102 via interface Ua 110. UE 100 communicates with BSF 104 via interface Ub 112. NAF 102 communicates with BSF 104 via interface Zn 114. BSF 104 communicates with HSS 106 via interface Zh 116.
[0018] NAF 102 can be provided in another separate network. For example, as shown in FIG. IB, an example network architecture is located in NAF 102 in a visited network. In the event that the UE 100 has contacted the NAF 102, which is served in a different network than the home network, the NAF 102 visited will use the Diameter proxy (D-Proxy) 118 of the NAF network to communicate with the subscriber's BSF (i.e. home BSF) 104 . NAF 102 communicates with BSF 104 via the Zn 114 interface to D-Proxy 118 and via the Zn '120 interface to BSF 104. The D-Proxy 118 function can be introduced as a separate network element or be part of any network element (NE) in a visited network that supports the Diameter proxy function (an example of this type of NE is the BSF of the network to which the visited NAF 102 or AAA server belongs).
[0019] In FIG. IA and IB, the principle of bootstrapping is that the UE 100 and bootstrapping function authorize each other, for example, using the AKA protocol and agree on a master shared secret. Then, the main shared secret is used to obtain one or more specific secrets of common network application functions that are used between the UE 100 and specific network application functions (NAFs). The NAF secret key is generated independently for each function of the web application. Upon completion of the bootstrapping task, UE 100 and the network application function can run a specific protocol in which message security will be based on keys generated during mutual authorization between the UE 100 and the bootstrapping server function. Thus, the keys can be used to authorize and protect integrity and to ensure confidentiality. The web application function may then acquire a specific common NAF secret resulting from the main shared secret established between the user equipment and the bootstrapping server function.
[0020] The Ub 112 communication interface supports bootstrapping authorization and key reconciliation protocol to ensure mutual authorization and key agreement between UE 100 and BSF 104. The protocol may be based, for example, on 3GPP AKA.
[0021] The Zh 116 interface allows BSF 104 to provide all required authorization information and subscriber profile information from HSS 106. The Ua 110 interface supports any application-specific protocol that is secured using a specific common NAF secret resulting from a main common secret between the EU 100 a BSF 104, based on the protocol provided by the Ub 112 interface. The Zn 114 interface is used by NAF 102 to obtain a specific common NAF secret that results from the main common secret agreed in the protocol supported on the Ub 112 interface with BSF 104. The Zn 114 interface can also be used to obtain information about a subscriber profile from BSF 104.
[0022] The message sent from BSF 104 to NAF 102 contains bootstrapping information. Bootstrapping information may include a transaction identifier, a specific NAF common secret, and optional subscriber profile information ("profnaf" or "any USS specified for NAF [any NAF specific USSs]"). The common specific NAF secret, designated as KsNAF, is established between UE 100 and BSF 104 and can be modified for specific use in communication between UE 100 and a specific NAF. Ks NAF results from Ks using the parameters specified in 3GPP TS 33.220 Annex B (Annex A). Fr is the main common secret, and Fr NAF is the specific common secret of NAF. The bootstrapping information sent to each NAF is thus unique for a given NAF, according to the specific common secrets of the NAF Account for such NAF.
[0023] A set of all user security settings GUSS includes a specific BSF information element and a set of all application-specific USS. A set of all user security settings (USS), i.e.GUSS, is stored in the HSS. In the case where the subscriber has multiple subscriptions, i.e. many ISIM or USIM applications on UICC, HSS will contain one or more GUSS that can be mapped to one or several identities, e.g. IMPI (IP Multimedia Private Identity) and IMSI (International Mobile Subscriber Identity).
[0024] The introduction of a new case for two specific common NAF secrets in GB AU, where one is used on UICC (KsintNAF) and the other on mobile equipment (Ks_ext_NAF). This case requires some "decision logic" regarding which key to use, ie Ks int NAF or Ks_ext_NAF. The introduction of new services to this kind of "logic" should be possible without reconfiguring the smart card mounted on the mobile terminal. If NAF supports more than one type of key, all types of security-level attacks should be prevented. This attack could be based on the fact that NAF would be deceived and would use a lower security key instead of requiring Ks int NAF.
[0025] According to an embodiment of the invention, a generic mechanism is provided for the application server that allows to find out which of the GAA (Generic Authentication Architecture) keys will allow easy integration of additional application servers by extending the existing USS (User Security Settings) standard. AVP (Attribute-Value-Pairs) are defined in 3GPP TS 29.109, Zn GAA interface of Bootstrapping-InfoRequest / Answer messages, attached here in the form of Annex C, the content of which has been introduced by reference, and additional new Diameter AVP are defined in 3GPP TS 29.229 , attached here as Annex D, the content of which has been introduced by reference.
[0026] The generic mechanism can be introduced in the form of an invariant value or by locally configuring the use of the key directly in the software in each NAF during configuration of the NAF (locally in the NAF), in the form of the invariant use of the key in the BSF (BSF instructs passing only the key to the NAF), providing
-8 additional fields in the user security settings (USS), stored in the Home Subscriber Server (HSS), which are sent to BSF and / or using AVP saved in BSF, which informs about key usage. If BSF will provide only key keys to NAF, NAF will not have information on the security quality communicated and the type of key it uses.
[0027] The 3GPP standard and existing User Security Settings (USS) can be extended and used to show which key to use. This would allow the user's home operator full and flexible control, especially in the case where the service is offered by a third party NAF and the service is settled by the home operator.
[0028] According to an embodiment of the invention, there are at least two possible embodiments. In a first embodiment of the invention, the USS may indicate the type of smart card or secure environment that the user has. In addition, the first embodiment provides information on whether the Universal SIM (USIM) card, the IMS SIM card (ISIM) supports GBA U or not. In the first embodiment, there may be a flagged field that indicates whether the card or secure environment supports GBA U.
[0029] In a second embodiment of the invention, the USS may include one or two flagged authorization fields that are transmitted in the USS of the existing 3GPP TS 29.109 specification, attached herein as Annex D, the content of which is incorporated herein by reference. In the first flagged field, if the field is present and informs about the use of a shared secret based on UICC (Ks int NAF) it is mandatory. The second flagged field may be an optional field in which, if the second flagged field is present, it informs about the use of a shared secret based on ME (Ks_ext_NAF or KsNAF) usage.
[0030] If the mobile subscriber is provided in the form of a home operator having a new subscriber identity module, the USS can be easily updated to require the safer KsintNAF key from now on. Both alternatives provide protection against attacks, i.e. the Ks_ext_NAF key is used instead of the more secure Ks int NAF.
[0031] FIG. 2 shows a device 150 providing a generic mechanism for a network application server, according to an embodiment of the invention. The device 150 includes a receiving unit 152 that receives requests from the user equipment to provide authorization information for the function of the network application. The device 150 further includes a determining unit 154 that specifies a generic authorization architecture key to integrate additional network application servers by extending the existing user security settings standard. The device 150 also includes a first delivery unit 156 that provides authorization information for the functions of the network application.
[0032] FIG. 3 illustrates a method providing a generic mechanism for a network application server according to an embodiment of the invention. During step 200, the method receives a request from the user equipment to provide authorization information for the network application function. During step 210, the method specifies a generic authorization architecture key to integrate additional network application servers by extending the existing user security standard. During step 220, authorization information for the functions of the web application is provided. According to an embodiment of the invention, the USS may inform what type of smart card the user has or what type (i.e. Ks_ext_NAF or Ks int NAF) of the common secret should be used. During step 230, the method determines whether the Universal SIM (USIM) card, IMS SIM (ISIM) card or other secure environment supports GBA U or not. In the first embodiment, there may be a flagged field that indicates whether the card or secure environment supports GBA U.
[0033] FIG. 4 illustrates a method providing a generic mechanism for a network application server according to another embodiment of the invention. During step 300, the method receives a request from the user equipment to provide authorization information for the function of the network application. During step 310, the method specifies a generic authorization architecture key to integrate additional web application servers by extending the existing user security standard. During step 320, authorization information for the functions of the web application is provided. According to an embodiment of the invention, the USS may inform what kind of smart card or secure environment the user has or what kind of shared secret should be used. During step 330, the method determines whether the USS contains one or two flagged fields carried in the Authorization header of the existing 3GPP TS 29.109 specification, attached here as Annex C. In the first flagged field, if the field is present and informs about the use of a shared secret based on UICC (Ks int NAF) it is mandatory. The second flagged field may be an optional field in which, if the second flagged field is present, it indicates the use of a shared secret based on ME (Ks_ext_NAF or KsNAF).
[0034] If a new application server has been configured in the operator's network, it does not need to know which key to use for a given user or whether the user will be equipped with a new SIM card in the near future. NAF will then obtain the necessary information on key selection from BSF.
[0035] According to an embodiment of the invention, a new AVP may be used to show the type of key used. For example, the new AVP may indicate whether the generated key is Ks int NAF or another type of key. The new AVP will inform you if the card or secure environment supports GB AU or, alternatively, which key to use. Depending on the flag, NAF may use a shared secret key based on UICC (Ks int NAF). That is, AVP informs that the card or secure environment supports GB AU or AVP only informs about the use
-10KsintNAF. NAF will then require the use of this key instead of another one with a lower security level.
[0036] For a network server in a secure environment, for example for a smart card, the client may be located on the UICC (Integrated Circuit Card) of the UMTS (Universal Mobile Telecommunications System) system, and the application will also be in a secure environment. It will usually be a Java application, XML application, C ++ application, Perl application or Visual Basic application or other similar applications. Then, UICC can also act as an application server offering a network service towards other entities, one of which can be located in another trusted domain, e.g. the second secure phone area, and Ks int NAF can be used to secure communication between network service entities. NAIC-based NAF will assume the role of WSP (Web Service Provider) as outlined in ID-WSF (Liberty Alliance Web Service Framework Specification) http.7 /<a href="http://www.proiectliberty.org/resources/specifications.php%c2%b7_UICC_mo%c5%bce_dzia%c5%82a%c4%87_jako_dostawcaus%c5%82ug_sieciowych_zgodnych_z_Liberty_Alliance_dostarczaj%c4%85c_jednostce_%c5%bc%c4%85daj%c4%85cej_(tj._klientaus%c5%82ugi_sieciowej)_wa%c5%bcne_informacje,_kt%c3%b3re_mog%c4%85_by%c4%87_autoryzowane/zabezpieczone_zapo%c5%9brednictwem_Ks_int_NAF._Pozosta%c5%82e_klucze_bazuj%c4%85ce_na_GAA_wykorzysta%c4%87_mo%c5%bcna_ponadtow_ramach_us%c5%82ug_sieciowych_dla_identyfikacji_i_bezpiecze%c5%84stwa_komunikacji._Ponadto,TS24.109_3GPP_okre%c5%9bla_interfejs_bootstrapping_(Ub)_i_interfejs_funkcji_aplikacji_sieciowej(Ua),_za%c5%82%c4%85czone_tutaj_w_postaci_Za%c5%82%c4%85cznika_E,_kt%c3%b3rego_tre%c5%9b%c4%87_wprowadzona_jest_przezodniesienie._TS29.109_3GPP_okre%c5%9bla_interfejsy_Zh_i_Zn_w_oparciu_o_protok%c3%b3%c5%82_Diameter(diameter_protocol),_za%c5%82%c4%85czone_tutaj_w_postaci_Za%c5%82%c4%85cznika_F,_kt%c3%b3rego_tre%c5%9b%c4%87_wprowadzona_jestprzez_odniesienie">www.proiectliberty.org/resources/specifications.php· UICC can act as a Liberty Alliance compliant network service provider by providing the requesting entity (i.e. network service client) with important information that can be authorized / secured via Ks int NAF. Other GAA-based keys can also be used as part of network services for communication identification and security. In addition, TS24.109 3GPP defines the bootstrapping interface (Ub) and the web application function interface (Ua), attached here as Annex E, the content of which is incorporated by reference. TS29.109 3GPP defines Zh and Zn interfaces based on the Diameter (diameter protocol) protocol, attached here as Annex F, the content of which is entered by reference</a>.
[0037] The invention provides the subscriber's home operator with full control over the level of security used. Updating user security settings in case the user has a new UICC can be centralized in the Home Service Server (HSS) and you will not need to update all NAF separately. Decision logic can be located on HSS or BSF controlled by the user. In addition, security attacks are not possible for new applications.
[0038] The above description relates to a specific embodiment of the invention. It will be appreciated that modifications of the described embodiments are possible using some or all of the functions.
Prepared and verified
Grażyna Palka Patent Attorney
20 members in 10 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 66987305 | United States of America | P | |
| 18493105 | United States of America | A | |
| 06744475 | European Patent Office (EPO) | A | |
| 2006000790 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| EP20060744475 | – | – | – |
| US20050184931 | – | – | – |
| US20050669873P | – | – | – |
| WO2006IB00790 | – | – | – |
Members20
| Document | Office | Kind | |
|---|---|---|---|
| US2006230436A1 | United States of America | A1 | |
| WO2006109122A1 | World Intellectual Property Organization (WIPO) | A1 | |
| MX2007012043A | Mexico | A | |
| KR20070116679A | Republic of Korea | A | |
| EP1875713A1 | European Patent Office (EPO) | A1 | |
| CN101156411A | China | A | |
| JP2008538471A | Japan | A | |
| ZA200709618B | South Africa | B | |
| KR100959315B1 | Republic of Korea | B1 | |
| BRPI0610400A2 | Brazil | A2 | |
| EP1875713A4 | European Patent Office (EPO) | A4 | |
| US8046824B2 | United States of America | B2 | |
| US2012011574A1 | United States of America | A1 | |
| JP2012034381A | Japan | A | |
| CN101156411B | China | B | |
| EP1875713B1 | European Patent Office (EPO) | B1 | |
| PL1875713T3This record | Poland | T3 | |
| US8990897B2 | United States of America | B2 | |
| BRPI0610400A8 | Brazil | A8 | |
| BRPI0610400B1 | Brazil | B1 |
Numbers
- Publication, DOCDB
- 1875713
- Publication, EPODOC
- PL1875713T
- Application
- 744475
- Application, DOCDB
- 06744475
- Application, EPODOC
- PL20060744475T
Titles2
- English
- GENERIC KEY-DECISION MECHANISM FOR GAA
- Polish
- Generyczny mechanizm decyzyjny klucza dla GAA
Classification
- CPC, 6
- H04L63/062
- H04L9/32
- H04W12/04
- G06F21/00
- H04W12/0431
- H04W12/122
- IPC, 2
- H04L29 06
- H04W12 04