AKMA Authentication Profiles for RADIUS and IPsec Compatibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems, particularly in 5G networks, lack efficient methods for secure authentication and key management between Personal Internet of Things (IoT) network elements and Authentication, Authorization, and Accounting (AAA) servers, especially when using protocols like RADIUS and IPsec, which are not supported by the current Authentication and Key Management for Applications (AKMA) specification.

Innovation Solution

Implementing new AKMA profiles that support the use of RADIUS and IPsec protocols for secure communication between Personal IoT network elements and AAA servers, enabling secure authentication and key management through extended AKMA specifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If AKMA specification is used for authentication and key management, then security is improved, but compatibility with RADIUS and IPsec protocols is lost

Engineering Contradiction:
ImprovesecurityVSAvoidprotocol compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the AKMA specification to support multiple security protocols (RADIUS, IPsec, and other IKE-based protocols) through a unified framework. The AAA server can selectively apply different protocols based on device type and service requirements, making the system universally applicable across diverse network elements while maintaining the core AKMA security architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces protocol selection parameters and configuration options that allow the AKMA system to dynamically adjust its behavior. By changing protocol parameters and enabling/disabling specific protocol support based on operational context, the system maintains security while adapting to different protocol requirements.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If new AKMA profiles supporting RADIUS and IPsec are implemented, then protocol compatibility is improved, but system complexity increases

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the protocol support into distinct profiles and modules within the AKMA framework. Each protocol (RADIUS, IPsec) is handled as a separate configurable component, allowing the system to enable only what is needed for specific deployments. This modular approach reduces complexity by avoiding the need to implement all protocols simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The AAA server acts as an intermediary that manages protocol selection and translation. It receives authentication requests, determines the appropriate protocol based on device capabilities and service requirements, and handles the protocol-specific processing. This centralizes complexity in the server rather than distributing it across all network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4322469B1Apparatus, method, and computer program
Publication Date: 2025.11.05 NOKIA TECHNOLOGIES OY
  • EP4322469B1 patent drawingFigure 1A
  • EP4322469B1 patent drawingFigure 1B
  • EP4322469B1 patent drawingFigure 2

AI summary

There is provided an apparatus, method and computer program for causing a first apparatus to: obtain an identifier of a cryptographic key according to a first security communication protocol; signal, to a second apparatus, a first authentication request according to a second security communication protocol, the first authentication request comprising the identifier of the cryptographic key and a first verifying information according to a second security communication protocol, wherein the first verifying information comprises a first value calculated using the cryptographic key; receive, from the second apparatus, an authentication response according to the second security communication protocol, the authentication response comprising a second verifying information according to the second security communication protocol, wherein the second verifying information comprises a second value; and verify the second apparatus for the second security communication protocol using the second value and the cryptographic key.