AMF Re-allocation Key Restriction for NAS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile network technologies face challenges in ensuring the secure transfer and usage of NAS security contexts during AMF re-allocation, as they cannot prevent misuse by compromised RAN nodes or unprotected interfaces, and do not guarantee the integrity of the initial Registration Request message sent to the target AMF.

Innovation Solution

A method involving the generation of a key (KAMF) for NAS SMC procedures, where the key's use is restricted to specific procedures, ensuring secure transfer and usage, and the implementation of a mechanism to verify the integrity of the Registration Request message by using indicators and message types to authenticate and authorize the AMF relocation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the NAS security context is transferred from source AMF to target AMF during re-allocation, then the UE can be served by the appropriate AMF according to network slicing requirements, but the security context may be misused by compromised RAN nodes or unprotected interfaces

Engineering Contradiction:
ImproveAMF re-allocation capabilityVSAvoidNAS security context protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security context transfer process by introducing separate security mechanisms for different phases: integrity protection for the Registration Request message during transfer, and restricted key usage (KAMF limited to NAS SMC procedure only) at the target AMF. This segmentation allows the security context to be transferred for adaptability while maintaining reliability through phase-specific security measures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the RAN node as a controlled intermediary in the security context transfer process. The RAN node is authorized to forward the Registration Request message and security context between AMFs but is restricted from using the security context for other purposes. This intermediary mechanism enables AMF re-allocation while preventing misuse by the intermediary itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the NAS security context is made available to the target AMF for processing, then the AMF re-allocation procedure can be completed, but the initial Registration Request message may be tampered with during transmission

Engineering Contradiction:
ImproveAMF re-allocation completionVSAvoidRegistration Request message integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by implementing integrity protection on the Registration Request message before it is forwarded to the target AMF. The source AMF or RAN node applies integrity protection mechanisms in advance, ensuring that any tampering during transmission can be detected. This preliminary security measure enables the re-allocation procedure to complete while maintaining message integrity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the KAMF key is generated and made available for NAS SMC procedure, then secure communication can be established with the target AMF, but the key may be misused for unauthorized procedures

Engineering Contradiction:
ImproveNAS SMC procedure securityVSAvoidKey usage restriction enforcement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning specific, limited functions to the KAMF key rather than making it a general-purpose security key. The KAMF is restricted to being used only for the NAS SMC procedure with the target AMF, while other security procedures use different keys or mechanisms. This localized key usage policy enhances security by preventing key misuse while maintaining manageable complexity through clear key purpose definitions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240064509A1AMF re-allocation handling
Publication Date: 2024.02.22 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20240064509A1 patent drawing
  • US20240064509A1 patent drawing
  • US20240064509A1 patent drawing

AI summary

A method performed by a wireless device is provided. The method comprises identifying that an Access and Mobility Management Function (AMF) relocation procedure with re-route via a Radio Access Network (RAN) node is being performed for the wireless device and generating a key associated with a primary authentication of the wireless device. The method further comprises using the key for performing a Non Access Stratum Security Mode Control (NAS SMC) procedure with a first network node operating as a target AMF, and wherein the use of the key by the wireless node is restricted such that the wireless device is restricted from using the key for at least one procedure other than the NAS SMS procedure with the first network node operating as the target AMF.