AKMA Roaming Key Management for 5G Lawful Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing AKMA roaming architecture lacks support for lawful interception and does not adequately address roaming scenarios, particularly in 5G networks, and there is a need for improved security and cost-effective solutions to manage encryption keys.
Innovation Solution
The proposed solution introduces an authentication proxy and key management mechanisms to enable lawful interception by deriving or indicating the AKMA encryption key, ensuring that the home PLMN can decrypt user services and support lawful interception, even when the external AF is used, by using key derivation functions or special keys, and utilizing network elements like NEF and AAnF to facilitate key transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AKMA roaming architecture is implemented without authentication proxy and key management mechanisms, then the architecture is simpler, but lawful interception capability is lost and security tasks cannot be performed effectively
Solution Approach 1:
An authentication proxy is introduced as an intermediary component between the UE and the network. The authentication proxy receives authentication requests from UEs, forwards them to the AAnF, and manages the derivation and distribution of encryption keys to appropriate network elements. This intermediary enables lawful interception capabilities without requiring fundamental changes to the entire AKMA architecture.
Solution Approach 2:
The authentication and key management functions are segmented into separate components: the authentication proxy handles authentication requests and key derivation, the AAnF manages anchor keys, and the AF handles application-specific encryption. This segmentation allows each component to perform its specialized function while maintaining overall system simplicity and enabling targeted implementation of lawful interception.
2Ease of manufacture
If application servers perform all security tasks including encryption key management, then security control is centralized, but processing costs and server load increase
Solution Approach 1:
Security tasks related to authentication and key management are extracted from the application servers and delegated to specialized components: the authentication proxy handles authentication requests and key derivation, while the AAnF manages anchor keys. This extraction reduces the processing burden on application servers and lowers overall processing costs while maintaining security effectiveness through specialized components.
3Reliability
If the home PLMN cannot derive or obtain the AKMA encryption key, then key management is simpler, but the home PLMN cannot decrypt user services for lawful interception
Solution Approach 1:
The authentication proxy performs preliminary key derivation during the authentication process. When a UE authenticates, the authentication proxy derives the AKMA encryption key from the anchor key and distributes it to the home PLMN's lawful interception function in advance. This preliminary action ensures that the home PLMN has the necessary keys for lawful interception without requiring complex on-demand key management mechanisms.
Solution Approach 2:
The authentication proxy acts as an intermediary that facilitates key distribution to the home PLMN. It receives the anchor key from the AAnF, derives the AKMA encryption key, and selectively distributes it to authorized network elements including the home PLMN's lawful interception function. This intermediary mechanism enables controlled key distribution without requiring the home PLMN to implement complex key derivation infrastructure.
Data Source
AI summary
A method, apparatus, and computer program for receiving an application session establishment request comprising an authentication and key management for applications, AKMA, Key Identifier, A-KID; producing an application key request (Naanf_AKMA_ApplicationKey_Get_request) comprising information elements AKMA Key Identifier A-KID; an application function identifier, AF_ID; and an application encryption key indication (Nnef_AKMA_AF_Encryption_Key_Indication); and sending the produced application key request (Naanf_AKMA_ApplicationKey_Get_request) to a home AKMA anchor function, hAAnF, or to a network exposure function, NEF, for enabling lawful interception in the VPLMN.


