AKMA Authentication Proxy for Aggregated 5G Application Key Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing AKMA authentication procedures in 5G networks are inefficient as each Application Function (AF) separately requests keying material from the AKMA Anchor Function (AAnF) for application sessions, which can be burdensome on the AAnF and NEF.

Innovation Solution

An AKMA authentication proxy is introduced to interact with the AAnF on behalf of multiple AFs, collectively obtaining and managing AKMA application keys, reducing the burden on individual AFs and optimizing key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each Application Function (AF) separately requests keying material from the AKMA Anchor Function (AAnF), then individual AFs can obtain necessary keys for application sessions, but the burden on the AAnF and NEF increases significantly

Engineering Contradiction:
Improvekeying material deliveryVSAvoidburden on AAnF
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an Authentication Proxy as an intermediary component between the AFs and the AAnF. The proxy receives authentication requests from multiple AFs, aggregates them, and communicates with the AAnF in a consolidated manner. This mediator role reduces the direct burden on the AAnF by filtering and batching requests, while still ensuring reliable keying material delivery to the appropriate AFs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines multiple separate authentication requests from different AFs into a single aggregated request handled by the Authentication Proxy. Instead of each AF independently communicating with the AAnF, the proxy merges these communications into unified interactions, reducing the overall number of transactions and lowering the burden on the anchor function.

Inventive Principle:
Principle #5Merging (Combining)

2Ease of operation

If each AF separately obtains keying material from the AAnF, then key management can be distributed, but the authentication process becomes inefficient and time-consuming

Engineering Contradiction:
Improvekey management distributionVSAvoidauthentication process time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The Authentication Proxy performs preliminary aggregation of authentication requests before forwarding them to the AAnF. By collecting and consolidating requests in advance rather than processing them individually as they arrive, the system reduces the total authentication time while maintaining distributed key management capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The proxy maintains continuous operation by batching and processing authentication requests in an ongoing manner rather than handling them as discrete, separate events. This continuous processing approach improves efficiency by keeping the authentication pipeline active and reducing idle time between individual authentication operations.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP4271014B1Authentication proxy for AKMA authentication service
Publication Date: 2026.03.25 NOKIA TECHNOLOGIES OY
  • EP4271014B1 patent drawingFigure 1~2
  • EP4271014B1 patent drawingFigure 3
  • EP4271014B1 patent drawingFigure 4

AI summary

Systems, methods, and software of performing an Authentication and Key Management for Applications (AKMA) authentication service. An AKMA authentication proxy resides between User Equipment (UE) and a plurality of Application Functions (AFs). The AKMA authentication proxy receive an application session establishment request message from the UE requesting an application session with a first application function, sends a key request message toward an AKMA anchor function (AAnF) requesting AKMA application keys for a plurality of application functions, receives a key response message sent from the AAnF that includes the AKMA application keys, identifies a first AKMA application key for the first application function from the AKMA application keys derived by the AAnF, and forwards the application session establishment request message to the first application function with the first AKMA application key.