AKMA Key Management via Proxy Mediation for Roaming AF Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions fail to provide an AKMA service to non-trusted application functions outside the 3GPP service provider domain in terminal roaming scenarios.

Innovation Solution

A key management method involving a proxy entity in the serving network, network exposure function, application function, and home network entity to facilitate AKMA key management by exchanging AKMA key identifiers and application key information across different network entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If AKMA service is provided to non-trusted application functions outside the 3GPP service provider domain in roaming scenarios, then service coverage and adaptability are improved, but key management security and control become more difficult

Engineering Contradiction:
Improveservice coverageVSAvoidkey management security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a proxy entity as an intermediary between the AF and the home network. This proxy entity receives key management requests from the AF, forwards them to the home network, and relays responses back. By inserting this trusted intermediary in the communication path, the system enables service access for external non-trusted AFs while maintaining security control through the proxy's mediation, thus resolving the contradiction between service coverage and key management security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If key management requests are processed through multiple network entities (AF, proxy entity, home network), then service adaptability is improved, but system complexity and processing time increase

Engineering Contradiction:
Improveservice adaptabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the key management system into distinct functional entities: the AF for service initiation, the proxy entity for request forwarding and local coordination, and the home network for authoritative key management. This segmentation allows each entity to perform its specific function independently, improving service adaptability while managing complexity through clear functional boundaries and standardized interfaces between entities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250350938A1Key management method and apparatus, device, and storage medium
Publication Date: 2025.11.13 BEIJING XIAOMI MOBILE SOFTWARE CO LTD
  • US20250350938A1 patent drawing
  • US20250350938A1 patent drawing
  • US20250350938A1 patent drawing

AI summary

A method, apparatus and computer readable medium for key management in a roaming scenario. The key management is performed by: receiving an AKMA key identifier and an AF identifier from an AF, where the AKMA key identifier is used to indicate an AKMA key of a terminal, and the AF identifier is used to indicate the AF; sending the AKMA key identifier and the AF identifier to an AAnF in a home network; receiving AKMA application key information of the AF sent by the AAnF in the home network; and feeding back the AKMA application key information of the AF to the AF.