AKMA Key Refresh via UDM Intermediary in 5G Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing 5G mobile communication systems face challenges in timely refreshment of AKMA and AF keys, leading to key synchronization issues and prolonged service disruptions due to the need for primary authentication, which is computationally heavy and time-consuming, and may not align context across different entities.
Innovation Solution
A method and system for generating new Authentication and Key Management for Application (AKMA) keys through Unified Data Management (UDM), Authentication Server Function (AUSF), and User Equipment (UE), where AKMA refresh parameters are used to refresh keys without requiring primary authentication, ensuring key synchronization across entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If primary authentication is performed to generate new AKMA keys, then key refreshment is achieved, but computational overhead and time consumption increase significantly
Solution Approach 1:
The system performs preliminary key refreshment by generating new AKMA keys before the existing keys expire. The UDM receives a refresh request, generates new keys using the existing KAUSF, and proactively pushes them to the UE and AAnF, preventing service disruption rather than reacting to key expiration.
Solution Approach 2:
The UDM acts as an intermediary between the AUSF and the UE/AAnF entities. It receives the refresh request, generates new AKMA keys using the existing KAUSF from AUSF, and distributes them to relevant parties, eliminating the need for direct primary authentication between UE and network.
2Reliability
If primary authentication is performed to generate new AKMA keys, then key refreshment is achieved, but computational complexity increases
Solution Approach 1:
The invention extracts the key generation function from the heavy primary authentication process. The UDM generates new AKMA keys by directly processing the existing KAUSF using a key derivation function, separating this lightweight operation from the computationally intensive primary authentication protocol.
Solution Approach 2:
The system creates copies of the key material by deriving new AKMA keys from the existing KAUSF using a deterministic key derivation function. This allows multiple key pairs to be generated from a single authentication credential without repeating the full authentication process.
3Reliability
If keys are refreshed manually or on-demand, then key security is maintained, but service disruption occurs during authentication
Solution Approach 1:
The system performs preliminary key refreshment by generating new AKMA keys before the existing keys expire. The UDM receives a refresh request, generates new keys using the existing KAUSF, and proactively pushes them to the UE and AAnF, preventing service disruption rather than reacting to key expiration.
Solution Approach 2:
The system implements a feedback mechanism where the UDM monitors key expiration status and automatically triggers key refreshment when needed. The network can detect when keys are about to expire and initiate the refresh process transparently, maintaining service continuity without user awareness.
4Reliability
If primary authentication is performed frequently, then key synchronization is maintained, but network resource consumption increases
Solution Approach 1:
The invention extracts the key generation function from the heavy primary authentication process. The UDM generates new AKMA keys by directly processing the existing KAUSF using a key derivation function, separating this lightweight operation from the computationally intensive primary authentication protocol.
Solution Approach 2:
The system creates copies of the key material by deriving new AKMA keys from the existing KAUSF using a deterministic key derivation function. This allows multiple key pairs to be generated from a single authentication credential without repeating the full authentication process.
Data Source
AI summary
The disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. Embodiments herein provide a system and method for key refresh in Authentication and Key Management for Applications (AKMA). The proposed method is to support KAKMA refresh by requesting the refreshing parameters from the network once the KAF is about to expire. Further, the proposed method is to support KAF refresh by requesting the refreshing parameters from the network once the KAF is about to expire. Further the proposed method uses certain mechanisms to provide the refresh parameter to the AUSF, AAnF and the UE as a part of AKMA Refresh procedure or as a part of UPU procedure. Further, the proposed method supports AKMA key refresh with limited impacts on AKMA services in 5G system. Furthermore, the proposed method is used to support a mechanism to address the Key synchronisation issue at a User Equipment (UE) side, AF and at the network side.


