AKMA Session Validation for Secure UE-AF AI Model Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The distribution of AI/ML models between a 5G Application Function (AF) and a UE poses risks of redundant communications and security and privacy issues unless adequate measures are taken.

Innovation Solution

Implementing authentication and key management (AKMA) protocols to establish secure application sessions, including maintaining AKMA context, validating AFs using secondary AKMA key identifiers, and encrypting AI models with AKMA application keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If AI/ML models are distributed between AF and UE without adequate security measures, then communication efficiency is improved, but security and privacy risks increase

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity and privacy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary authentication and key management before AI/ML model distribution. The AKMA context is established in advance, including primary and secondary key identifiers, so that when model transfer occurs, the security framework is already in place. This prevents security risks while maintaining efficient communication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism using AKMA context and key identifiers. The secondary AKMA key identifier acts as a mediator that enables the UE to validate the AF's authorization to distribute models, thus securing the communication without hindering efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and key management protocols are implemented for AI model transfer, then security is improved, but communication overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The AKMA context and key identifiers are established beforehand, so that during actual AI model transfer, authentication can occur rapidly using pre-configured credentials. This minimizes communication overhead while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses secondary AKMA key identifiers that are derived from or copied from the primary authentication context. This allows the system to verify authorization without repeating the full authentication process, reducing communication overhead while preserving security.

Inventive Principle:
Principle #26Copying

3Measurement precision

If secondary AKMA key identifiers are used for AF validation, then authorization accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveauthorization accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct components: primary AKMA context, secondary AKMA key identifiers, and validation logic. This segmentation allows each component to perform its specific function efficiently, improving authorization accuracy while keeping individual components manageable in complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secondary AKMA key identifier serves as an intermediary that simplifies the validation process. Instead of complex direct authentication between AF and UE, the secondary identifier mediates the authorization check, improving accuracy while the modular structure keeps system complexity manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250301315A1Method and apparatus for UE and application function session protection for model transfer
Publication Date: 2025.09.25 NOKIA TECHNOLOGIES OY
  • US20250301315A1 patent drawing
  • US20250301315A1 patent drawing
  • US20250301315A1 patent drawing

AI summary

In accordance with an example embodiment, a UE performs maintaining an AKMA, context including a UE identifier, an AKMA anchor key KAKMA, and a primary AKMA key identifier, A-KID; receiving from an application function, AF, a secondary AKMA key identifier, A-KID′; and validating the AF for the UE using the AKMA key identifier A-KID. The validating includes: obtaining from the secondary AKMA key identifier A-KID′ an AKMA temporary UE identifier A-TID; and verifying whether the A-TID was included in the primary AKMA key identifier A-KID. If the verifying is positive, then the UE establishes an application session with the AF; and receives an artificial intelligence, AI, model from the AF; or otherwise rejects the application session with the AF.