AKMA Roaming Key Management for Secure 5G Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G communication systems with AKMA services are limited to a user's home network and disabled when the user is roaming, preventing lawful interception and secure communication outside the home network.
Innovation Solution
A method and system for enabling AKMA services in roaming scenarios by sharing and retrieving AKMA key materials through push and pull mechanisms between the home and visited networks, using notifications and configurations considering regional regulatory requirements and vertical edge configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If AKMA services are limited to home network only, then security and key management are simplified, but service availability and adaptability are reduced when users roam
Solution Approach 1:
The system segments AKMA service functionality between home network AAnF and visited network AAnF. The home network AAnF retains primary key management responsibilities while the visited network AAnF provides local service support during roaming, allowing AKMA services to function independently in each network context without requiring complete key management relocation
Solution Approach 2:
The visited network AAnF acts as an intermediary that receives notifications from the home network AAnF about key material changes and forwards relevant information to applications. This mediator role enables seamless roaming service continuity without requiring applications to directly communicate with the home network, thus maintaining security while improving service availability
2Reliability
If AKMA key material is shared with visited network AAnF, then service continuity during roaming is improved, but security risks and information exposure increase
Solution Approach 1:
The system extracts and shares only the necessary AKMA key material (specifically KAF and A-KID) with the visited network AAnF, rather than sharing all key material or establishing complete trust relationships. This selective extraction enables service continuity while minimizing security exposure by limiting the scope of shared cryptographic material
Solution Approach 2:
The visited network AAnF receives and stores AKMA key material with specific local quality requirements - the key material is stored in an isolated manner dedicated solely for forwarding to applications, with restricted access controls. This local quality differentiation ensures that even if the visited network is compromised, the exposure is contained to application-level operations rather than core network security
3Speed
If push mechanism is used to notify visited network AAnF of key changes, then service responsiveness is improved, but network signaling overhead increases
Solution Approach 1:
The home network AAnF implements periodic notification to the visited network AAnF whenever AKMA key material changes occur. Rather than continuous monitoring or event-driven approaches, the system uses structured periodic updates triggered by key generation or renewal events, which balances responsive service updates with controlled signaling volume based on actual key material lifecycle events
Data Source
AI summary
The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. Embodiments herein provide a method of enabling authentication and key management application (AKMA) services in roaming mode comprising generating a key associated with the AKMA services after a primary authentication of the UE with a wireless network; determining whether to share the at least one key associated with the AKMA services with a visited AKMA anchor function (vAAnF); and sharing the at least one key associated with the AKMA services with the vAAnF.


