Method, Apparatus and Computer Program Product for Providing Key Management for a Mobile Authentication Architecture
An apparatus for providing key management for a mobile authentication architecture may include a processor. The processor may be configured to provide a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function, and cancel key information associated with the request for key revocation.
1 . A method comprising:
providing a key revocation message over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and
canceling key information associated with the key revocation message.
2 . The method of claim 1 , wherein providing the key revocation message comprises communicating a key cancellation message from the bootstrapping server function in response to a user initiated request.
3 . The method of claim 2 , wherein providing the key revocation message comprises communicating the key cancellation message to at least one different network application function in response to an indication of a user request for cancellation of an identified key received from the network application function and cancellation of the key information at the bootstrapping server function.
4 . The method of claim 3 , further comprising determining the at least one different network application function to be a network application function having the identified key prior to communicating the key cancellation message.
5 . The method of claim 1 , wherein providing the key revocation message comprises communicating the key revocation message from the network application function in response to receipt of a user initiated request indicative of a key to be revoked, the network application function being associated with a service using the key to be revoked.
6 . The method of claim 1 , wherein providing the key revocation message comprises providing the key revocation message in response to an operator initiated request indicative of a key to be revoked.
7 . The method of claim 1 , wherein providing the key revocation message comprises communicating a key cancellation message in response to an indication of an account cancellation, the bootstrapping server function being associated with a home network of a user associated with the canceled account.
8 . The method of claim 1 , wherein providing the key revocation message comprises providing a request to revoke all keys associated with a shared secret generated pursuant to a generic bootstrapping architecture framework or providing a request to revoke an application specific key associated with the shared secret.
9 . The method of claim 1 , wherein providing the key revocation message comprises communicating a key cancellation message in response to receiving a request redirected from a service provider associated with a service from which a user communicating the request wishes to logout, in which the service is accessible through a single sign on procedure, and wherein canceling the key information provides a single sign on logout function by deleting keys associated with the user at both the bootstrapping server function and the network application function.
10 . A computer program product comprising at least one computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:
a first executable portion for providing a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and
a second executable portion for canceling key information associated with the request for key revocation.
11 . The computer program product of claim 10 , wherein the first executable portion includes instructions for communicating a key cancellation message from the bootstrapping server function in response to a user initiated request.
12 . The computer program product of claim 11 , wherein the first executable portion includes instructions for communicating the key cancellation message to at least one different network application function in response to an indication of a user request for cancellation of an identified key received from the network application function and cancellation of the key information at the bootstrapping server function.
13 . The computer program product of claim 12 , further comprising a third executable portion for determining the at least one different network application function to be a network application function having the identified key prior to communicating the key cancellation message.
14 . The computer program product of claim 10 , wherein the first executable portion includes instructions for communicating the key revocation message from the network application function in response to receipt of a user initiated request indicative of a key to be revoked, the network application function being associated with a service using the key to be revoked.
15 . The computer program product of claim 10 , wherein the first executable portion includes instructions for providing the key revocation message in response to an operator initiated request indicative of a key to be revoked.
16 . An apparatus comprising a processor configured to:
provide a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and
cancel key information associated with the request for key revocation.
17 . The apparatus of claim 16 , wherein the processor is configured to communicate a key cancellation message from the bootstrapping server function in response to a user initiated request.
18 . The apparatus of claim 17 , wherein the processor is further configured to communicate the key cancellation message to at least one different network application function in response to an indication of a user request for cancellation of an identified key received from the network application function and cancellation of the key information at the bootstrapping server function.
19 . The apparatus of claim 18 , wherein the processor is further configured to determine the at least one different network application function to be a network application function having the identified key prior to communicating the key cancellation message.
20 . The apparatus of claim 16 , wherein the processor is further configured to communicate the key revocation message from the network application function in response to receipt of a user initiated request indicative of a key to be revoked, the network application function being associated with a service using the key to be revoked.
21 . The apparatus of claim 16 , wherein the processor is further configured to provide the key revocation message in response to an operator initiated request indicative of a key to be revoked.
22 . The apparatus of claim 16 , wherein the processor is further configured to communicate a key cancellation message in response to an indication of an account cancellation, the bootstrapping server function being associated with a home network of a user associated with the canceled account.
23 . The apparatus of claim 16 , wherein the processor is further configured to provide a request to revoke all keys associated with a shared secret generated pursuant to a generic bootstrapping architecture framework or providing a request to revoke an application specific key associated with the shared secret.
24 . The apparatus of claim 16 , wherein the processor is further configured to communicate a key cancellation message in response to receiving a request redirected from a service provider associated with a service from which a user communicating the request wishes to logout, in which the service is accessible through a single sign on procedure, and wherein the processor is further configured to cancel the key information to provide a single sign on logout function by deleting keys associated with the user at both the bootstrapping server function and the network application function.
25 . A method comprising:
receiving a request for key revocation over an interface otherwise defined for sharing key acquisition information between a bootstrapping server function and a network application function; and
canceling key information associated with the request for key revocation.