AKMA and GBA Negotiation for 5G Edge Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication mechanisms for Edge Enabler Client (EEC) in 5G networks, such as AKMA and GBA, do not enable application servers to determine whether a User Equipment's (UE) Home Public Land Mobile Network (HPLMN) supports AKMA, GBA, or both, leading to ambiguity and incompatibility in edge computing deployments.

Innovation Solution

A negotiation mechanism is introduced where the UE sends a message with pre-shared key (PSK) identity hints and security key identifiers to the edge data network server, allowing the server to determine supported authentication procedures and establish secure connections using TLS certificates when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication mechanisms (AKMA/GBA) are used without negotiation, then authentication can be performed, but the server cannot determine HPLMN support status leading to ambiguity and incompatibility

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidHPLMN support information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary action by having the UE send PSK identity hints and security key identifiers to the server before actual authentication takes place. This advance information exchange enables the server to determine HPLMN support status for AKMA and GBA, allowing proper authentication procedure selection without ambiguity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses PSK identity hints as an intermediary mechanism that carries information about HPLMN support status. These hints act as a mediator between the UE's authentication capabilities and the server's authentication procedure selection, enabling the server to make informed decisions about which authentication method to use.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple authentication procedures are supported, then versatility is improved, but negotiation complexity increases

Engineering Contradiction:
Improveauthentication procedure supportVSAvoidnegotiation mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication negotiation by separating different authentication procedures (AKMA and GBA) into distinct, identifiable components. Each procedure has its own PSK identity hint and security key identifier, allowing the server to evaluate and select appropriate procedures independently based on HPLMN support status without complex interdependencies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses parameter changes by encoding HPLMN support information for different authentication procedures into PSK identity hints. The server changes its authentication procedure selection based on these parameters, enabling versatile support for multiple procedures while keeping the negotiation mechanism relatively simple through structured parameter exchange.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4480203B1Negotiation mechanisms for AKMA and gba
Publication Date: 2026.01.28 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP4480203B1 patent drawingFigure 1~2
  • EP4480203B1 patent drawingFigure 3
  • EP4480203B1 patent drawingFigure 4

AI summary

Embodiments include methods performed by a user equipment (UE) configured with a client for an edge data network. Such methods include sending, to a server in the edge data network, a first message that includes one of the following contents: at least one pre-shared key (PSK) identity hint that is supported by the UE and the UE's home public land mobile network (HPLMN), and one or more security key identifiers corresponding to respective one or more of a plurality of authentication procedures supported by at least the HPLMN; an indication of the UE's HPLMN; all valid PSK identity hints, and the one or more security key identifiers; or all valid PSK identity hints, and the indication of the HPLMN. Such methods also include receiving from the server a second message that includes one of the following contents: all valid PSK identity hints; or a PSK identity hint that is supported by at least the UE's HPLMN.