5G AMF Handover Security Context Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G wireless communication networks, there is a need for efficient security context management during Access and Mobility Management Function (AMF) changes without requiring re-authentication, especially when AMFs are deployed in potentially less secure locations, which is not efficiently addressed by existing mechanisms.

Innovation Solution

A mechanism is introduced where the source AMF derives a new Non-Access Stratum (NAS) key, sends it to the target AMF, and provides a key change indication to the User Equipment (UE), allowing the UE to derive the new NAS key, thereby achieving backward security without the need for re-authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the source AMF transfers the current NAS key to the target AMF during handover, then the handover process is simplified, but backward security is compromised as the target AMF can determine previous security contexts

Engineering Contradiction:
Improvehandover process simplicityVSAvoidbackward security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the security context transfer mechanism from the key management process. Instead of transferring the current NAS key, the system uses a transparent container to carry security context information between AMFs, separating the handover signaling from sensitive key material transmission

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism where the source AMF derives a new NAS key using a key derivation function with a key change indication as input. This intermediary key derivation process acts as a mediator between the old and new security contexts, preventing direct exposure of previous keys while enabling secure handover

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If re-authentication is performed during AMF change, then forward security is achieved, but network performance and user experience deteriorate due to the costly authentication procedure

Engineering Contradiction:
Improveforward securityVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the source AMF derive the new NAS key before the handover is completed. The new key is prepared in advance and transferred to the target AMF through the transparent container, so that when the handover occurs, both AMFs already have the correct key without needing to perform expensive re-authentication procedures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the security parameters by introducing a key change indication parameter that triggers key derivation. Instead of using static key transfer or full re-authentication, the system dynamically changes keys using a derivation function with a specific parameter (key change indication) that enables forward security while maintaining performance

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If AMFs are deployed in edge locations closer to users, then network flexibility and coverage are improved, but security risk increases due to potentially less secure deployment environments

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security architecture by separating the SEAF (Security Anchor Function) which holds the master key, from the AMF which handles mobility management. This segmentation allows AMFs to be deployed flexibly at the edge while the core security function remains centralized and secure. The transparent container mechanism further segments the key transfer process, ensuring that even edge AMFs cannot compromise the master key stored at the SEAF

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11388592B2Security context handling in 5G during handover
Publication Date: 2022.07.12 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11388592B2 patent drawing
  • US11388592B2 patent drawing
  • US11388592B2 patent drawing

AI summary

The present disclosure relates to methods and apparatus for flexible, security context management during AMF changes. One aspect of the disclosure is a mechanism for achieving backward security during AMF changes. Instead of passing the current NAS key to the target AMF, the source AMF derives a new NAS key, provides the new NAS key to the target AMF, and sends a key change indication to the UE, either directly or through some other network node. The UE can then derive the new NAS key from the old NAS key. In some embodiments, the AMF may provide a key generation parameter to the UE to use in deriving the new NAS key. In other embodiments, the target AMF may change one or more security algorithms.