AKMA Roaming Security Context Segmentation for Legal Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 3GPP TS 33.535 specifications for Authentication and Key Management for Applications (AKMA) lack the feature of roaming, preventing Legal Interception (LI) in visited public land mobile networks (VPLMN) as they establish secured tunnels that prevent LI from being performed, and LI requirements are not met when the Mobile Network Operator (MNO) is involved in key material distribution.

Innovation Solution

The proposed solution involves a UE providing a Serving Network Name (SN) to an Application Function (AF) to route key requests to the VPLMN, where the Visited AKMA Anchor Function (V-AAnF) detects the home PLMN realm and selects an Anchor Function (AAnF) to generate and relay the AKMA security context, enabling LI independently in each jurisdiction without explicit HPLMN support.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If AKMA security context is established for AF not in the same network, then data traffic security protection is improved, but Legal Interception capability deteriorates

Engineering Contradiction:
Improvedata traffic security protectionVSAvoidLegal Interception capability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the AKMA security context into two parts: a first security context established between UE and AF in the HPLMN, and a second security context established between the UE and the V-AAnF in the VPLMN. This segmentation allows the VPLMN to have access to the second security context for Legal Interception while the first security context maintains end-to-end security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The V-AAnF (Visited AKMA Anchor Function) acts as an intermediary in the VPLMN that receives and stores the second security context. This intermediary enables the VPLMN to perform Legal Interception by accessing the security context without compromising the overall security architecture established by the HPLMN.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secured tunnel is established between UE and AF, then data security is improved, but Legal Interception in VPLMN deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidLegal Interception in VPLMN
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The security context is segmented into a first security context for end-to-end security and a second security context for VPLMN access. The V-AAnF stores the second security context locally, enabling Legal Interception in the VPLMN while the first security context maintains the secured tunnel between UE and AF.

Inventive Principle:
Principle #1Segmentation

3Reliability

If AKMA key material distribution is implemented, then authentication security is improved, but Legal Interception requirement satisfaction deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidLegal Interception requirement satisfaction
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The key material distribution is segmented into HPLMN-managed first key material for authentication security and VPLMN-accessible second key material for Legal Interception. The V-AAnF stores the second key material, allowing the VPLMN to satisfy Legal Interception requirements without compromising the HPLMN's authentication security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The V-AAnF serves as an intermediary that holds the second key material and provides it to the VPLMN when needed for Legal Interception. This intermediary approach allows key material distribution to satisfy both authentication security and Legal Interception requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12143812B2Enabling roaming with authentication and key management for applications
Publication Date: 2024.11.12 LENOVO (SINGAPORE) PTE LTD
  • US12143812B2 patent drawing
  • US12143812B2 patent drawing
  • US12143812B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for enabling roaming with authentication and key management for applications. An apparatus includes a processor that determines a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) that is different from a home PLMN (“HPLMN”) associated with the UE. The processor selects a network function within the serving network for provisioning an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name for the serving network. The apparatus includes a transceiver that sends the security context to the network function.