5G Key Synchronization via Identifier Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, the status of keys KSEAF and KAUSF is undefined, leading to unclear usage and synchronization issues between the UE and network elements, particularly due to the separation of Authentication Server Function (AUSF) and Access and Mobility Management Function (AMF) or Security Anchor Function (SEAF), resulting in potential key overwriting and service disruptions.

Innovation Solution

The method involves deriving and storing identifiers for KAUSF and KSEAF at both the UE and network elements, such as AUSF and SEAF, using key derivation functions, to ensure synchronization and track key usage, thereby resolving the ambiguity and ensuring correct key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the AUSF stores KAUSF before authentication completion, then the key is available for use, but the key can be overwritten by serving networks triggering new authentication

Engineering Contradiction:
Improvekey availabilityVSAvoidkey integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The AUSF stores the KAUSF and its identifier before the authentication procedure is fully completed. This preliminary storage enables the key to be available for subsequent procedures while the authentication is still in progress, resolving the contradiction between key availability and key integrity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the serving network triggers authentication to overwrite KAUSF, then fresh keys are generated, but synchronization between UE and network elements is lost

Engineering Contradiction:
Improvekey freshnessVSAvoidkey status synchronization
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms where the AUSF tracks the status of KAUSF and communicates this status to relevant network elements. When authentication completes or fails, the AUSF updates the key status and informs the SEAF and UE, ensuring all parties have synchronized understanding of which keys are valid and active.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The AUSF acts as an intermediary that coordinates between the UE and SEAF regarding key status. It maintains the authoritative record of KAUSF status and mediates information flow between authentication entities, preventing synchronization loss when keys are generated or overwritten.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple security contexts are maintained in UE, then authentication flexibility is improved, but key tracking and usage clarity deteriorates

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Instead of storing complete key material for multiple security contexts, the UE stores compact identifiers (such as ngKSI) that represent each security context. These identifiers allow the UE to reference and switch between multiple security contexts efficiently without managing the full complexity of each key set, reducing device complexity while maintaining authentication flexibility.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12075244B2Method for synchronization of home network key
Publication Date: 2024.08.27 NEC CORP
  • US12075244B2 patent drawing
  • US12075244B2 patent drawing
  • US12075244B2 patent drawing

AI summary

The present disclosure provides a terminal including a memory; and a processor, comprising hardware, configured to perform a primary authentication between the terminal and a network in 5G for a third party service, derive a security key, KAUSF, and derive an identifier for the security key from the security key.