AMF Key Isolation via Segmented Handover
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In LTE and 5G mobile communication systems, the transfer of security contexts between mobility management entities poses a security risk as the communication key remains the same between source and target entities, leading to potential leakage and compromised security.
Innovation Solution
A key obtaining method where the target AMF entity receives a first message, sends a second message to the source AMF entity to obtain an intermediate key derived from the key between the source AMF entity and the terminal device, and determines the communication key based on security-related information to achieve key isolation and enhance communication security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Stability of the object's composition
If the source AMF entity sends the same communication key to the target AMF entity for continuity, then mobility management is achieved, but security is compromised due to potential key leakage
Solution Approach 1:
The communication key is segmented into two parts: a first key part generated by the terminal device and a second key part generated by the target AMF entity. These separate key parts are combined to form the complete communication key, ensuring that neither party holds the entire key alone and preventing key leakage risks during handover.
Solution Approach 2:
The terminal device pre-generates the first key part before handover and sends it to the target AMF entity in advance through the handover request message. This preliminary action ensures that when handover occurs, the target AMF entity already has the necessary key component to establish secure communication without relying on the source AMF entity's key.
2Reliability
If a new key is generated for every handover, then security is improved, but key management complexity increases
Solution Approach 1:
The key management process is segmented into two independent key generation responsibilities: the terminal device generates the first key part using its own algorithms, and the target AMF entity generates the second key part independently. This segmentation simplifies key management by distributing the burden rather than requiring one entity to manage complete key generation and distribution.
Solution Approach 2:
Both the terminal device and target AMF entity independently generate their respective key parts using their own algorithms and resources, without requiring the source AMF entity to provide or manage the complete key. This self-service approach reduces key management complexity by eliminating the need for centralized key distribution during handover.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Embodiments of this application provide a plurality of key obtaining methods and devices, and a plurality of communications systems. A target AMF entity determines, by using an intermediate key sent by a source AMF entity, a communication key used between the target AMF entity and a terminal device, or a target AMF entity requests a new key from an authentication function entity to determine a communication key used between the target AMF entity and a terminal device, and instructs the terminal device to derive a corresponding key. In this way, key isolation is achieved between the target AMF entity and the source AMF entity, thereby effectively avoiding a security risk in the prior art and improving network security.