AKMA Application Key Control for Roaming UE Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing AKMA frameworks do not adequately address the management of cryptographic keys for both roaming and non-roaming UEs, particularly in scenarios involving visited and home networks, failing to consider regulatory and policy compliance.
Innovation Solution
Implementing a system that includes an AKMA application key controller to manage cryptographic keys for roaming UEs, considering factors such as lawful intercept regulations and network policies, by utilizing components like NEF, UDM, AUSF, and AAnF to determine and provide AKMA application keys based on UE status and network permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AKMA framework provides cryptographic keys to all UEs uniformly, then key management is simple, but security compliance for roaming UEs cannot be ensured
Solution Approach 1:
The patent segments UE management into roaming UEs and non-roaming UEs, with different key management procedures for each. The NEF determines UE roaming status and applies different policies: for roaming UEs, keys are controlled based on visited network permissions and home network policies; for non-roaming UEs, standard AKMA key provision is used. This segmentation resolves the contradiction by enabling compliance-specific management without applying complexity universally.
Solution Approach 2:
The patent implements local quality by applying different key management qualities to different UE types. Roaming UEs receive enhanced security control with permission verification, while non-roaming UEs receive standard service. The system adjusts key provision quality locally based on UE status, ensuring compliance where needed while maintaining simplicity elsewhere.
2Reliability
If AKMA framework implements roaming UE key control, then security compliance is improved, but system complexity increases
Solution Approach 1:
The patent introduces the NEF as an intermediary between the AF and the roaming UE key management process. The NEF receives key provision requests from the AF, determines UE roaming status, verifies visited network permissions, and coordinates with the home network. This intermediary handles the complexity of regulatory compliance, allowing the AF to maintain its original function while ensuring compliance through the NEF's mediation.
Solution Approach 2:
The patent implements preliminary action by having the NEF determine UE roaming status and verify permissions before the AF provisions cryptographic keys. The system performs compliance checks in advance, obtaining necessary permissions from visited networks and verifying home network policies before key generation. This preliminary compliance verification prevents later security issues without requiring complex post-provisioning controls.
3Reliability
If AKMA framework verifies visited network permissions, then lawful intercept compliance is ensured, but key provision time increases
Solution Approach 1:
The patent applies preliminary action by having the NEF obtain visited network permissions and verify home network policies before the AF provisions cryptographic keys for roaming UEs. This advance verification ensures lawful intercept compliance is established prior to key generation, preventing delays during actual key provision and service establishment.
Solution Approach 2:
The patent implements feedback mechanisms where the NEF receives permission status information from visited networks and home networks, and uses this feedback to determine whether to proceed with key provision. The system continuously monitors permission status and adjusts key management decisions based on received feedback, ensuring compliance while optimizing timing based on actual network responses.
Data Source
AI summary
A device may include a processor. The processor may be configured to: receive, from an Application Function (AF), a request for an Authentication and Key Management for Applications (AKMA) Application key; and determine whether a User Equipment device (UE) that sent a session request to the AF is attached to a visiting network or a home network. When the UE is determined to be attached to the visiting network, the processor may be configured to: determine whether to include the AKMA application key in a first reply to the AF; and send the first reply to the AF. When the UE is determined to be attached to the home network, the processor may be configured to: obtain the AKMA application key; and send a second reply that includes the AKMA application key to the AF.


