AKMA Roaming Key Management for 5G Lawful Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing AKMA roaming architecture lacks support for lawful interception and does not adequately address roaming scenarios, particularly in 5G networks, and there is a need for improved security and cost-effective solutions to manage encryption keys.

Innovation Solution

The proposed solution introduces an authentication proxy and key management mechanisms to enable lawful interception by deriving or indicating the AKMA encryption key, ensuring that the home PLMN can decrypt user services and support lawful interception, even when the external AF is used, by using key derivation functions or special keys, and utilizing network elements like NEF and AAnF to facilitate key transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the AKMA roaming architecture is implemented without authentication proxy and key management mechanisms, then the architecture is simpler, but lawful interception capability is lost and security tasks cannot be performed effectively

Engineering Contradiction:
Improvelawful interception capabilityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An authentication proxy is introduced as an intermediary component between the UE and the network. The authentication proxy receives authentication requests from UEs, forwards them to the AAnF, and manages the derivation and distribution of encryption keys to appropriate network elements. This intermediary enables lawful interception capabilities without requiring fundamental changes to the entire AKMA architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication and key management functions are segmented into separate components: the authentication proxy handles authentication requests and key derivation, the AAnF manages anchor keys, and the AF handles application-specific encryption. This segmentation allows each component to perform its specialized function while maintaining overall system simplicity and enabling targeted implementation of lawful interception.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If application servers perform all security tasks including encryption key management, then security control is centralized, but processing costs and server load increase

Engineering Contradiction:
Improveprocessing costVSAvoidsecurity task performance
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

Security tasks related to authentication and key management are extracted from the application servers and delegated to specialized components: the authentication proxy handles authentication requests and key derivation, while the AAnF manages anchor keys. This extraction reduces the processing burden on application servers and lowers overall processing costs while maintaining security effectiveness through specialized components.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If the home PLMN cannot derive or obtain the AKMA encryption key, then key management is simpler, but the home PLMN cannot decrypt user services for lawful interception

Engineering Contradiction:
Improvelawful interception capabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication proxy performs preliminary key derivation during the authentication process. When a UE authenticates, the authentication proxy derives the AKMA encryption key from the anchor key and distributes it to the home PLMN's lawful interception function in advance. This preliminary action ensures that the home PLMN has the necessary keys for lawful interception without requiring complex on-demand key management mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication proxy acts as an intermediary that facilitates key distribution to the home PLMN. It receives the anchor key from the AAnF, derives the AKMA encryption key, and selectively distributes it to authorized network elements including the home PLMN's lawful interception function. This intermediary mechanism enables controlled key distribution without requiring the home PLMN to implement complex key derivation infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12563400B2Method and apparatus for lawful interception for AKMA roaming architecture
Publication Date: 2026.02.24 NOKIA TECHNOLOGIES OY
  • US12563400B2 patent drawing
  • US12563400B2 patent drawing
  • US12563400B2 patent drawing

AI summary

A method, apparatus, and computer program for receiving an application session establishment request comprising an authentication and key management for applications, AKMA, Key Identifier, A-KID; producing an application key request (Naanf_AKMA_ApplicationKey_Get_request) comprising information elements AKMA Key Identifier A-KID; an application function identifier, AF_ID; and an application encryption key indication (Nnef_AKMA_AF_Encryption_Key_Indication); and sending the produced application key request (Naanf_AKMA_ApplicationKey_Get_request) to a home AKMA anchor function, hAAnF, or to a network exposure function, NEF, for enabling lawful interception in the VPLMN.