AKMA Roaming Security Context Segmentation for Legal Interception
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 3GPP TS 33.535 specifications for Authentication and Key Management for Applications (AKMA) lack the feature of roaming, preventing Legal Interception (LI) in visited public land mobile networks (VPLMN) as they establish secured tunnels that prevent LI from being performed, and LI requirements are not met when the Mobile Network Operator (MNO) is involved in key material distribution.
Innovation Solution
The proposed solution involves a UE providing a Serving Network Name (SN) to an Application Function (AF) to route key requests to the VPLMN, where the Visited AKMA Anchor Function (V-AAnF) detects the home PLMN realm and selects an Anchor Function (AAnF) to generate and relay the AKMA security context, enabling LI independently in each jurisdiction without explicit HPLMN support.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AKMA security context is established for AF not in the same network, then data traffic security protection is improved, but Legal Interception capability deteriorates
Solution Approach 1:
The patent segments the AKMA security context into two parts: a first security context established between UE and AF in the HPLMN, and a second security context established between the UE and the V-AAnF in the VPLMN. This segmentation allows the VPLMN to have access to the second security context for Legal Interception while the first security context maintains end-to-end security protection.
Solution Approach 2:
The V-AAnF (Visited AKMA Anchor Function) acts as an intermediary in the VPLMN that receives and stores the second security context. This intermediary enables the VPLMN to perform Legal Interception by accessing the security context without compromising the overall security architecture established by the HPLMN.
2Reliability
If secured tunnel is established between UE and AF, then data security is improved, but Legal Interception in VPLMN deteriorates
Solution Approach 1:
The security context is segmented into a first security context for end-to-end security and a second security context for VPLMN access. The V-AAnF stores the second security context locally, enabling Legal Interception in the VPLMN while the first security context maintains the secured tunnel between UE and AF.
3Reliability
If AKMA key material distribution is implemented, then authentication security is improved, but Legal Interception requirement satisfaction deteriorates
Solution Approach 1:
The key material distribution is segmented into HPLMN-managed first key material for authentication security and VPLMN-accessible second key material for Legal Interception. The V-AAnF stores the second key material, allowing the VPLMN to satisfy Legal Interception requirements without compromising the HPLMN's authentication security.
Solution Approach 2:
The V-AAnF serves as an intermediary that holds the second key material and provides it to the VPLMN when needed for Legal Interception. This intermediary approach allows key material distribution to satisfy both authentication security and Legal Interception requirements.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for enabling roaming with authentication and key management for applications. An apparatus includes a processor that determines a serving network of a user equipment (“UE”) device, the serving network comprising a visited public land mobile network (“VPLMN”) that is different from a home PLMN (“HPLMN”) associated with the UE. The processor selects a network function within the serving network for provisioning an authentication and key management for applications (“AKMA”) security context for an application function (“AF”) based on a name for the serving network. The apparatus includes a transceiver that sends the security context to the network function.


