5G Service Discovery Security Key Distribution via Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the service-based architecture of 5G networks, the current method for secure communication between network functions (NFs) involves the network repository function (NRF) sharing security keys, leading to increased communication complexity.
Innovation Solution
The proposed method allows direct authentication of a security key between the first and second NFs, with the NRF determining and sending a security parameter, eliminating the need for NRF to communicate with the second NF, thereby reducing communication complexity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the NRF shares security keys with both the first NF and the second NF to ensure secure communication, then security authentication is achieved, but the communication complexity increases
Solution Approach 1:
The patent extracts the security key sharing process from the NRF and transfers it to the first NF. The first NF generates the security key and shares it directly with the second NF, eliminating the need for the NRF to communicate with the second NF for key distribution. This reduces the communication complexity while maintaining security authentication.
Solution Approach 2:
The first NF performs self-service by generating and managing the security key itself, rather than relying on the NRF to distribute keys. The first NF autonomously establishes secure communication with the second NF using the generated key, reducing the burden on the NRF and simplifying the overall communication process.
2Reliability
If the NRF communicates with the second NF to share the security key, then secure communication is established, but the number of communication steps increases
Solution Approach 1:
The patent removes the NRF from the security key distribution process between the first NF and the second NF. The first NF directly generates and shares the security key with the second NF in a single communication step, eliminating the additional communication steps that would otherwise be required for the NRF to interact with the second NF.
Solution Approach 2:
The first NF performs preliminary action by generating the security key before communication with the second NF. This pre-generated key is then directly shared with the second NF, eliminating the need for subsequent key distribution communications through the NRF and reducing the overall number of communication steps.
3Reliability
If the NRF generates and distributes security keys to multiple NFs, then security is maintained, but the device complexity and communication overhead increase
Solution Approach 1:
Each NF performs self-service by generating its own security keys autonomously. The first NF generates a security key and manages its distribution to the second NF without requiring the NRF's involvement in the key distribution process. This self-service approach eliminates the communication overhead associated with the NRF managing keys for multiple NFs.
Solution Approach 2:
The patent segments the security key management responsibility from the NRF and assigns it to individual NFs. Each NF independently generates and manages its own security keys, dividing the centralized key management function into distributed autonomous operations. This segmentation reduces the communication overhead on the NRF while maintaining security.
Data Source
AI summary
A discovery method and apparatus based on a service-based architecture, where the method includes a control network element sending a discovery response to a first functional network element, where the discovery response includes a determined security parameter and an access address or an identifier of a second functional network element. The first functional network element receives the discovery response from the control network element, and sends an access request to the second functional network element based on the address or the identifier of the second functional network element, where the access request includes the received security parameter. The second functional network element receives the access request from the first functional network element, verifies correctness of the security parameter, and determines, based on the correctness of the security parameter, whether the access request is authorized by the first functional network element.


