AKMA Roaming Root-Key Delivery After Subscriber Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a roaming scenario, ensuring secure communication between user equipment and a visited application function network element is challenging due to the need for protecting communication security between the UE and the vAF.

Innovation Solution

The visited authentication and key management for applications anchor function network element verifies the subscriber permanent identifier of the terminal device and sends a root key to the visited application function network element only when verification succeeds, ensuring secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the visited authentication and key management for applications anchor function network element sends the root key to the visited application function network element without verifying the subscriber permanent identifier, then the communication setup process is faster, but the communication security and reliability deteriorate due to potential service failures caused by incorrect identifiers

Engineering Contradiction:
Improvecommunication securityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing verification of the subscriber permanent identifier before sending the root key. The visited authentication and key management for applications anchor function network element verifies the subscriber permanent identifier in advance to ensure it is correct, preventing service failures and ensuring communication security before the actual key transmission occurs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the visited authentication and key management for applications anchor function network element verifies the subscriber permanent identifier before sending the root key, then the communication security improves, but the communication process time increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication setup time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification is performed as a preliminary action before root key transmission, ensuring that security checks are completed in advance. This prevents potential service failures and ensures that the correct subscriber is being served, while the verification process is integrated efficiently into the existing communication setup流程 to minimize time loss.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If the visited authentication and key management for applications anchor function network element performs verification of the subscriber permanent identifier, then service performance improves by avoiding service failures, but the device complexity and processing overhead increase

Engineering Contradiction:
Improveservice performanceVSAvoidverification mechanism complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The verification mechanism enables the system to self-validate the subscriber permanent identifier correctness. The visited authentication and key management for applications anchor function network element autonomously performs the verification to ensure service continuity and avoid failures, improving service performance through self-checking capabilities without requiring external intervention.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250279885A1Communication method and communication apparatus
Publication Date: 2025.09.04 HUAWEI TECH CO LTD
  • US20250279885A1 patent drawing
  • US20250279885A1 patent drawing
  • US20250279885A1 patent drawing

AI summary

This application provides a communication method and a communication apparatus, and may be applied to an AKMA roaming scenario. The method may include: A visited authentication and key management for applications anchor function network element receives an application key get request message from a visited application function network element. The application key get request message requests a root key used to protect communication data between the visited application function network element and a terminal device. The visited authentication and key management for applications anchor function network element obtains a verification result of a subscriber permanent identifier of the terminal device based on the application key get request message. When verification on the subscriber permanent identifier succeeds, the visited authentication and key management for applications anchor function network element sends the root key to the visited application function network element.