AKMA Session Security for Fine-Grained AF Communication Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing 5G communication system's AKMA architecture lacks the capability to implement end-to-end security protection between a terminal device and an application function network element (AF) at a finer granularity than the AF identifier, failing to meet diverse service requirements.

Innovation Solution

A communication protection method and apparatus that enables end-to-end security protection by negotiating security keys and algorithms between a terminal device and an AF, allowing for confidentiality and integrity protection, and includes mechanisms for security capability negotiation and key generation based on AKMA keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a key at AF identifier granularity is negotiated between UE and AF in existing AKMA architecture, then key negotiation is simplified, but end-to-end security protection for different service requirements cannot be implemented

Engineering Contradiction:
Improvesecurity protection adaptabilityVSAvoidkey negotiation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the key negotiation process into two distinct phases: first negotiating a base key at AF identifier granularity, then negotiating service-specific keys at finer granularity for different service requirements. This segmentation allows the system to maintain the simplicity of coarse-grained key management while enabling fine-grained security protection when needed, resolving the contradiction between adaptability and complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic key negotiation capability that can adapt to different service requirements. The system dynamically selects whether to use the base key or negotiate additional service-specific keys based on the security requirements of each service, making the key management system flexible and adaptable without being overly complex for all scenarios.

Inventive Principle:
Principle #15Dynamics

2Reliability

If end-to-end security protection is implemented for different service requirements, then security protection capability is improved, but key negotiation complexity increases

Engineering Contradiction:
Improveend-to-end security protectionVSAvoidkey negotiation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary key negotiation at the AF identifier level before specific service communication occurs. This base key is established in advance and can be reused across multiple services, reducing the need for repeated key negotiations and minimizing the complexity increase while ensuring security protection is available when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial key negotiation by only negotiating service-specific keys when actually needed for particular services, rather than pre-negotiating all possible service keys. This approach provides end-to-end security protection where required while avoiding the complexity of managing keys for all potential services, applying the principle of doing just enough rather than everything.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12627639B2Communication protection method and apparatus
Publication Date: 2026.05.12 HUAWEI TECH CO LTD
  • US12627639B2 patent drawing
  • US12627639B2 patent drawing
  • US12627639B2 patent drawing

AI summary

Embodiments of this disclosure provide a communication protection method that includes: a terminal device sends an application session establishment request message to a first application function network element (AF), where the application session establishment request message includes an authentication and key management for application (AKMA) key identifier; and the terminal device receives an application session establishment response message from the first AF, where the application session establishment response message includes a security activation indication. The security activation indication indicates whether to activate security protection on communication between the terminal device and a second AF. The security protection includes confidentiality protection and/or integrity protection performed based on a security key, and the security key is generated based on an AKMA key corresponding to the AKMA key identifier.