AKMA Application Key Deletion via Key Anchor Node Notification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G networks, the deletion of AKMA contexts is incomplete, allowing user equipment to continue using application keys despite subscription updates or network changes, compromising network security and reliability.
Innovation Solution
An application key deletion method involving a key anchor node and application server that receives context deletion requests, searches for corresponding identifiers, and sends deletion messages to ensure application keys are removed, thereby maintaining network security and reliability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AAnF deletes the AKMA context, then the network management and security are improved, but the user equipment can still use the application key to conduct services with the AF, causing security risks and service reliability issues
Solution Approach 1:
The patent applies preliminary action by notifying the application server to delete the application key before or during the AKMA context deletion process. This ensures that the application key is removed in advance, preventing any subsequent unauthorized service usage by user equipment even after the AKMA context is deleted. The notification mechanism proactively addresses the security risk before it can manifest.
Solution Approach 2:
The patent implements feedback by establishing a notification mechanism where the AAnF informs the application server about the AKMA context deletion. This feedback loop ensures that the application server is aware of the context deletion and can take corresponding actions to delete its stored application keys, thereby maintaining synchronization and security across the system.
2Stability of the object's composition
If the application key is retained after AKMA context deletion, then service continuity is maintained, but network security and management are compromised
Solution Approach 1:
The patent applies the taking out principle by separating the application key deletion action from the AKMA context deletion. The application key is extracted and deleted independently from the AKMA context, ensuring that no residual keys remain that could compromise security. This separation allows complete removal of security credentials while maintaining proper service management.
Data Source
AI summary
Provided are an application key deletion method, a key anchor node, a server, a system and a medium. The application key deletion method includes: receiving an AKMA context deletion request, where a user identifier is carried in the AKMA context deletion request; according to the user identifier, searching a corresponding AKMA context and an application server identifier corresponding to the AKMA context; and in response to finding the application server identifier, sending an application key deletion request message and deleting the AKMA context.


