AKMA Key Management via Proxy Mediation for Roaming AF Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions fail to provide an AKMA service to non-trusted application functions outside the 3GPP service provider domain in terminal roaming scenarios.
Innovation Solution
A key management method involving a proxy entity in the serving network, network exposure function, application function, and home network entity to facilitate AKMA key management by exchanging AKMA key identifiers and application key information across different network entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If AKMA service is provided to non-trusted application functions outside the 3GPP service provider domain in roaming scenarios, then service coverage and adaptability are improved, but key management security and control become more difficult
Solution Approach 1:
The patent introduces a proxy entity as an intermediary between the AF and the home network. This proxy entity receives key management requests from the AF, forwards them to the home network, and relays responses back. By inserting this trusted intermediary in the communication path, the system enables service access for external non-trusted AFs while maintaining security control through the proxy's mediation, thus resolving the contradiction between service coverage and key management security.
2Adaptability or versatility
If key management requests are processed through multiple network entities (AF, proxy entity, home network), then service adaptability is improved, but system complexity and processing time increase
Solution Approach 1:
The patent segments the key management system into distinct functional entities: the AF for service initiation, the proxy entity for request forwarding and local coordination, and the home network for authoritative key management. This segmentation allows each entity to perform its specific function independently, improving service adaptability while managing complexity through clear functional boundaries and standardized interfaces between entities.
Data Source
AI summary
A method, apparatus and computer readable medium for key management in a roaming scenario. The key management is performed by: receiving an AKMA key identifier and an AF identifier from an AF, where the AKMA key identifier is used to indicate an AKMA key of a terminal, and the AF identifier is used to indicate the AF; sending the AKMA key identifier and the AF identifier to an AAnF in a home network; receiving AKMA application key information of the AF sent by the AAnF in the home network; and feeding back the AKMA application key information of the AF to the AF.


