5G Key Synchronization via Identifier Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G networks, the status of keys KSEAF and KAUSF is undefined, leading to unclear usage and synchronization issues between the UE and network elements, particularly due to the separation of Authentication Server Function (AUSF) and Access and Mobility Management Function (AMF) or Security Anchor Function (SEAF), resulting in potential key overwriting and service disruptions.
Innovation Solution
The method involves deriving and storing identifiers for KAUSF and KSEAF at both the UE and network elements, such as AUSF and SEAF, using key derivation functions, to ensure synchronization and track key usage, thereby resolving the ambiguity and ensuring correct key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the AUSF stores KAUSF before authentication completion, then the key is available for use, but the key can be overwritten by serving networks triggering new authentication
Solution Approach 1:
The AUSF stores the KAUSF and its identifier before the authentication procedure is fully completed. This preliminary storage enables the key to be available for subsequent procedures while the authentication is still in progress, resolving the contradiction between key availability and key integrity.
2Reliability
If the serving network triggers authentication to overwrite KAUSF, then fresh keys are generated, but synchronization between UE and network elements is lost
Solution Approach 1:
The system implements feedback mechanisms where the AUSF tracks the status of KAUSF and communicates this status to relevant network elements. When authentication completes or fails, the AUSF updates the key status and informs the SEAF and UE, ensuring all parties have synchronized understanding of which keys are valid and active.
Solution Approach 2:
The AUSF acts as an intermediary that coordinates between the UE and SEAF regarding key status. It maintains the authoritative record of KAUSF status and mediates information flow between authentication entities, preventing synchronization loss when keys are generated or overwritten.
3Adaptability or versatility
If multiple security contexts are maintained in UE, then authentication flexibility is improved, but key tracking and usage clarity deteriorates
Solution Approach 1:
Instead of storing complete key material for multiple security contexts, the UE stores compact identifiers (such as ngKSI) that represent each security context. These identifiers allow the UE to reference and switch between multiple security contexts efficiently without managing the full complexity of each key set, reducing device complexity while maintaining authentication flexibility.
Data Source
AI summary
The present disclosure provides a terminal including a memory; and a processor, comprising hardware, configured to perform a primary authentication between the terminal and a network in 5G for a third party service, derive a security key, KAUSF, and derive an identifier for the security key from the security key.


