AKMA Rekeying for Session Continuity Without Reauthentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security management systems in 5G networks face challenges in efficiently managing application function keys without the need for reauthentication, particularly when key lifetimes expire, leading to the need to update all associated keys.
Innovation Solution
Implement rekeying techniques that generate new application function keys using random values, allowing sessions to continue without reauthentication by updating only the affected keys, thus avoiding the need to update other keys in the AKMA context.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If reauthentication is performed when an application function key expires, then security is maintained, but session continuity is disrupted and additional authentication overhead is introduced
Solution Approach 1:
The patent segments the key management process by introducing a key update function that operates independently from the authentication function. When an application function key expires, a new key is generated and distributed to relevant entities without triggering a full reauthentication sequence, thus maintaining session continuity while preserving security through key rotation.
Solution Approach 2:
The patent introduces a key management function as an intermediary between the authentication mechanism and application functions. This intermediary handles key generation, distribution, and updates, allowing key expiration to be managed without involving the authentication process directly, thereby avoiding session disruption.
2Reliability
If all keys associated with an AKMA context are updated when one key expires, then security consistency is maintained, but signaling overhead and processing time increase significantly
Solution Approach 1:
The patent applies local quality by updating only the specific application function key that has expired rather than all keys in the AKMA context. The key update is localized to the affected key pair, leaving other keys intact and functional, thus reducing unnecessary signaling overhead and processing time while maintaining security consistency in the affected area.
Solution Approach 2:
Instead of performing a complete key update across all AKMA context keys (excessive action), the patent implements a partial update approach that refreshes only the expired application function key. This partial action is sufficient to maintain security consistency without the overhead of updating unrelated keys.
3Reliability
If reauthentication is triggered by key expiry, then security protocols are strictly followed, but network efficiency and user convenience are reduced
Solution Approach 1:
The patent extracts the key management functionality from the authentication flow by introducing a separate key update mechanism. This allows key expiration to be handled independently through key generation and distribution without triggering the authentication protocol, thereby maintaining security protocol compliance for actual authentication events while improving network efficiency by eliminating unnecessary reauthentication signaling.
Data Source
AI summary
Techniques for authentication and key management for applications (AKMA) in a communication network are disclosed. For example, a method comprises receiving an indication from an application function that a first expiry time of a first application function key, generated using a first random value and configured to enable user equipment to participate in a session with the application function, has expired. The method generates a second application function key for the application function, using a second random value, with a second expiry time.


