AKMA Rekeying for Session Continuity Without Reauthentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security management systems in 5G networks face challenges in efficiently managing application function keys without the need for reauthentication, particularly when key lifetimes expire, leading to the need to update all associated keys.

Innovation Solution

Implement rekeying techniques that generate new application function keys using random values, allowing sessions to continue without reauthentication by updating only the affected keys, thus avoiding the need to update other keys in the AKMA context.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If reauthentication is performed when an application function key expires, then security is maintained, but session continuity is disrupted and additional authentication overhead is introduced

Engineering Contradiction:
ImprovesecurityVSAvoidsession continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the key management process by introducing a key update function that operates independently from the authentication function. When an application function key expires, a new key is generated and distributed to relevant entities without triggering a full reauthentication sequence, thus maintaining session continuity while preserving security through key rotation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key management function as an intermediary between the authentication mechanism and application functions. This intermediary handles key generation, distribution, and updates, allowing key expiration to be managed without involving the authentication process directly, thereby avoiding session disruption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all keys associated with an AKMA context are updated when one key expires, then security consistency is maintained, but signaling overhead and processing time increase significantly

Engineering Contradiction:
Improvesecurity consistencyVSAvoidkey update time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by updating only the specific application function key that has expired rather than all keys in the AKMA context. The key update is localized to the affected key pair, leaving other keys intact and functional, thus reducing unnecessary signaling overhead and processing time while maintaining security consistency in the affected area.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of performing a complete key update across all AKMA context keys (excessive action), the patent implements a partial update approach that refreshes only the expired application function key. This partial action is sufficient to maintain security consistency without the overhead of updating unrelated keys.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If reauthentication is triggered by key expiry, then security protocols are strictly followed, but network efficiency and user convenience are reduced

Engineering Contradiction:
Improvesecurity protocol complianceVSAvoidnetwork efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the key management functionality from the authentication flow by introducing a separate key update mechanism. This allows key expiration to be handled independently through key generation and distribution without triggering the authentication protocol, thereby maintaining security protocol compliance for actual authentication events while improving network efficiency by eliminating unnecessary reauthentication signaling.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12627490B2Rekeying in authentication and key management for applications in communication network
Publication Date: 2026.05.12 NOKIA TECHNOLOGIES OY
  • US12627490B2 patent drawing
  • US12627490B2 patent drawing
  • US12627490B2 patent drawing

AI summary

Techniques for authentication and key management for applications (AKMA) in a communication network are disclosed. For example, a method comprises receiving an indication from an application function that a first expiry time of a first application function key, generated using a first random value and configured to enable user equipment to participate in a session with the application function, has expired. The method generates a second application function key for the application function, using a second random value, with a second expiry time.