AKMA Key Management for Re-Authentication Consistency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current AKMA procedures do not consider re-authentication, leading to inconsistencies in communication keys between terminal devices and application function network elements, which can result in service interruptions, increased latency, and poor user experience.
Innovation Solution
A key management method that ensures terminal devices and application function network elements consistently agree on communication keys by using a first key generated before re-authentication, even after re-authentication occurs, thereby maintaining secure communication and avoiding service disruptions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If re-authentication is performed in the AKMA procedure, then security is improved, but communication key consistency deteriorates
Solution Approach 1:
The terminal device determines whether to delete the first key based on timing relationships established before re-authentication occurs. By checking whether the first application session establishment request message was sent before the first authentication request message, the device makes a preliminary decision about key retention, ensuring key consistency is maintained when needed while allowing security updates when appropriate.
Solution Approach 2:
The key management mechanism dynamically adjusts key retention behavior based on the temporal relationship between authentication and session establishment messages. The decision to keep or delete the first key is not static but adapts according to whether the session establishment request preceded the authentication request, allowing the system to balance security and consistency requirements in different operational contexts.
2Reliability
If the first key is deleted after re-authentication, then security is improved, but service continuity deteriorates
Solution Approach 1:
The system performs a preliminary check of the timing relationship between the first application session establishment request message and the first authentication request message before deleting the first key. This preliminary action ensures that key deletion only occurs when it will not disrupt ongoing services, thereby maintaining service continuity while still allowing security improvements when safe to do so.
Solution Approach 2:
The terminal device uses feedback from the timing relationship analysis to determine key retention. By monitoring whether the session establishment request was sent before authentication, the system receives feedback about service state that informs the key management decision, preventing deletions that would harm service continuity while enabling deletions that improve security.
3Reliability
If key update is performed during re-authentication, then security is improved, but service latency increases
Solution Approach 1:
The terminal device performs a preliminary determination of key retention status based on message timing relationships before proceeding with re-authentication. This preliminary action prevents unnecessary key updates that would increase service latency, while still allowing security improvements when the timing conditions indicate it is safe to do so.
Solution Approach 2:
The key update mechanism dynamically responds to the temporal context of authentication and session establishment messages. By adjusting key retention behavior based on whether the session establishment request preceded authentication, the system optimizes the balance between security updates and service latency, performing updates only when timing conditions are favorable.
Data Source
AI summary
This application provides a key management method, a device, and a system. The method includes: A terminal device sends a first application session establishment request message to a first application function network element, where the establishment request message carries identification information of a first key, and the first key is an authentication and key management for applications AKMA key. The terminal device receives a first authentication request message in a procedure of the re-authentication. The terminal device sends a response message for the first authentication request message in the procedure of the re-authentication. The terminal device receives a response message for the establishment request message. The terminal device derives a communication key between the terminal device and the first application function network element by using the first key.


