5G Security Function Entity Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing security negotiation methods in 4G networks are inadequate for the 5G network architecture, where security isolation between different network slices and between mobility management and session management entities is required, due to the abstraction of 5G networks into independent control plane and user plane functions.
Innovation Solution
A security negotiation method that involves a security function entity performing Authentication and Key Agreement with user equipment (UE) and generating security keys between the UE and core network elements, including mobility management and session management entities, based on authentication requests and key requests, using identification information for secure authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single MME handles both mobility management and session management in 4G networks, then the negotiation process is simplified, but security isolation between different network slices and functions cannot be achieved in 5G networks
Solution Approach 1:
The patent segments the security key generation process by introducing a security function entity that independently generates security parameters for different network slices and core network elements (MMF, SMF). This allows each slice and entity to have isolated security keys derived from the base key Kasme, achieving security isolation while maintaining the simplified AKA negotiation process inherited from 4G.
2Reliability
If 5G networks are abstracted into independent control plane and user plane functions with multiple network slices, then security isolation is achieved, but the existing AKA and algorithm negotiation method becomes inadequate
Solution Approach 1:
The patent introduces a security function entity as an intermediary between the UE and core network elements. This intermediary receives the authentication result and base key Kasme from the AKA process, then independently generates appropriate security parameters for each network slice and core network element, making the existing AKA negotiation method compatible with the new 5G security isolation requirements.
3Reliability
If separate AKA and algorithm negotiation results are required for each network slice and entity in 5G, then security isolation is ensured, but the complexity of the negotiation process increases
Solution Approach 1:
The patent applies preliminary action by having the security function entity generate all necessary security parameters for different network slices and core network elements in advance, based on the base key Kasme obtained from the single AKA negotiation. This pre-generation approach avoids the need for separate AKA negotiations with each entity, reducing overall negotiation complexity while ensuring security isolation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present invention provide a security negotiation method, a security function entity, a core network element, and user equipment. The method includes: receiving, by a security function entity, an authentication request sent by a core network element, where the authentication request is generated by the core network element based on a request message of user equipment UE; performing, by the security function entity, Authentication and Key Agreement with the UE based on the authentication request, and generating a security parameter, where the security parameter includes a first key; receiving, by the security function entity, a key request sent by the core network element; and generating, by the security function entity, a security key between the core network element and the UE based on the key request and the first key. In the method, NAS security for a 5G network architecture can be negotiated, thereby meeting a security requirement of a 5G network.