5G Security Function Entity Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing security negotiation methods in 4G networks are inadequate for the 5G network architecture, where security isolation between different network slices and between mobility management and session management entities is required, due to the abstraction of 5G networks into independent control plane and user plane functions.

Innovation Solution

A security negotiation method that involves a security function entity performing Authentication and Key Agreement with user equipment (UE) and generating security keys between the UE and core network elements, including mobility management and session management entities, based on authentication requests and key requests, using identification information for secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single MME handles both mobility management and session management in 4G networks, then the negotiation process is simplified, but security isolation between different network slices and functions cannot be achieved in 5G networks

Engineering Contradiction:
Improvenegotiation process simplicityVSAvoidsecurity isolation
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the security key generation process by introducing a security function entity that independently generates security parameters for different network slices and core network elements (MMF, SMF). This allows each slice and entity to have isolated security keys derived from the base key Kasme, achieving security isolation while maintaining the simplified AKA negotiation process inherited from 4G.

Inventive Principle:
Principle #1Segmentation

2Reliability

If 5G networks are abstracted into independent control plane and user plane functions with multiple network slices, then security isolation is achieved, but the existing AKA and algorithm negotiation method becomes inadequate

Engineering Contradiction:
Improvesecurity isolationVSAvoidnegotiation method compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a security function entity as an intermediary between the UE and core network elements. This intermediary receives the authentication result and base key Kasme from the AKA process, then independently generates appropriate security parameters for each network slice and core network element, making the existing AKA negotiation method compatible with the new 5G security isolation requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate AKA and algorithm negotiation results are required for each network slice and entity in 5G, then security isolation is ensured, but the complexity of the negotiation process increases

Engineering Contradiction:
Improvesecurity isolationVSAvoidnegotiation process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the security function entity generate all necessary security parameters for different network slices and core network elements in advance, based on the base key Kasme obtained from the single AKA negotiation. This pre-generation approach avoids the need for separate AKA negotiations with each entity, reducing overall negotiation complexity while ensuring security isolation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3468241B1Security negotiation method, security functional entity, core network element, and user equipment
Publication Date: 2021.08.25 HUAWEI TECH CO LTD
  • EP3468241B1 patent drawingFigure 1
  • EP3468241B1 patent drawingFigure 2
  • EP3468241B1 patent drawingFigure 3

AI summary

Embodiments of the present invention provide a security negotiation method, a security function entity, a core network element, and user equipment. The method includes: receiving, by a security function entity, an authentication request sent by a core network element, where the authentication request is generated by the core network element based on a request message of user equipment UE; performing, by the security function entity, Authentication and Key Agreement with the UE based on the authentication request, and generating a security parameter, where the security parameter includes a first key; receiving, by the security function entity, a key request sent by the core network element; and generating, by the security function entity, a security key between the core network element and the UE based on the key request and the first key. In the method, NAS security for a 5G network architecture can be negotiated, thereby meeting a security requirement of a 5G network.