AKMA Session Validation for Secure UE-AF AI Model Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The distribution of AI/ML models between a 5G Application Function (AF) and a UE poses risks of redundant communications and security and privacy issues unless adequate measures are taken.
Innovation Solution
Implementing authentication and key management (AKMA) protocols to establish secure application sessions, including maintaining AKMA context, validating AFs using secondary AKMA key identifiers, and encrypting AI models with AKMA application keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If AI/ML models are distributed between AF and UE without adequate security measures, then communication efficiency is improved, but security and privacy risks increase
Solution Approach 1:
The patent implements preliminary authentication and key management before AI/ML model distribution. The AKMA context is established in advance, including primary and secondary key identifiers, so that when model transfer occurs, the security framework is already in place. This prevents security risks while maintaining efficient communication.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using AKMA context and key identifiers. The secondary AKMA key identifier acts as a mediator that enables the UE to validate the AF's authorization to distribute models, thus securing the communication without hindering efficiency.
2Reliability
If authentication and key management protocols are implemented for AI model transfer, then security is improved, but communication overhead increases
Solution Approach 1:
The AKMA context and key identifiers are established beforehand, so that during actual AI model transfer, authentication can occur rapidly using pre-configured credentials. This minimizes communication overhead while maintaining strong security.
Solution Approach 2:
The patent uses secondary AKMA key identifiers that are derived from or copied from the primary authentication context. This allows the system to verify authorization without repeating the full authentication process, reducing communication overhead while preserving security.
3Measurement precision
If secondary AKMA key identifiers are used for AF validation, then authorization accuracy is improved, but system complexity increases
Solution Approach 1:
The patent segments the authentication system into distinct components: primary AKMA context, secondary AKMA key identifiers, and validation logic. This segmentation allows each component to perform its specific function efficiently, improving authorization accuracy while keeping individual components manageable in complexity.
Solution Approach 2:
The secondary AKMA key identifier serves as an intermediary that simplifies the validation process. Instead of complex direct authentication between AF and UE, the secondary identifier mediates the authorization check, improving accuracy while the modular structure keeps system complexity manageable.
Data Source
AI summary
In accordance with an example embodiment, a UE performs maintaining an AKMA, context including a UE identifier, an AKMA anchor key KAKMA, and a primary AKMA key identifier, A-KID; receiving from an application function, AF, a secondary AKMA key identifier, A-KID′; and validating the AF for the UE using the AKMA key identifier A-KID. The validating includes: obtaining from the secondary AKMA key identifier A-KID′ an AKMA temporary UE identifier A-TID; and verifying whether the A-TID was included in the primary AKMA key identifier A-KID. If the verifying is positive, then the UE establishes an application session with the AF; and receives an artificial intelligence, AI, model from the AF; or otherwise rejects the application session with the AF.


