AMF Re-allocation Key Restriction for NAS Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile network technologies face challenges in ensuring the secure transfer and usage of NAS security contexts during AMF re-allocation, as they cannot prevent misuse by compromised RAN nodes or unprotected interfaces, and do not guarantee the integrity of the initial Registration Request message sent to the target AMF.
Innovation Solution
A method involving the generation of a key (KAMF) for NAS SMC procedures, where the key's use is restricted to specific procedures, ensuring secure transfer and usage, and the implementation of a mechanism to verify the integrity of the Registration Request message by using indicators and message types to authenticate and authorize the AMF relocation process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the NAS security context is transferred from source AMF to target AMF during re-allocation, then the UE can be served by the appropriate AMF according to network slicing requirements, but the security context may be misused by compromised RAN nodes or unprotected interfaces
Solution Approach 1:
The patent segments the security context transfer process by introducing separate security mechanisms for different phases: integrity protection for the Registration Request message during transfer, and restricted key usage (KAMF limited to NAS SMC procedure only) at the target AMF. This segmentation allows the security context to be transferred for adaptability while maintaining reliability through phase-specific security measures.
Solution Approach 2:
The patent introduces the RAN node as a controlled intermediary in the security context transfer process. The RAN node is authorized to forward the Registration Request message and security context between AMFs but is restricted from using the security context for other purposes. This intermediary mechanism enables AMF re-allocation while preventing misuse by the intermediary itself.
2Productivity
If the NAS security context is made available to the target AMF for processing, then the AMF re-allocation procedure can be completed, but the initial Registration Request message may be tampered with during transmission
Solution Approach 1:
The patent applies preliminary action by implementing integrity protection on the Registration Request message before it is forwarded to the target AMF. The source AMF or RAN node applies integrity protection mechanisms in advance, ensuring that any tampering during transmission can be detected. This preliminary security measure enables the re-allocation procedure to complete while maintaining message integrity.
3Reliability
If the KAMF key is generated and made available for NAS SMC procedure, then secure communication can be established with the target AMF, but the key may be misused for unauthorized procedures
Solution Approach 1:
The patent applies local quality by assigning specific, limited functions to the KAMF key rather than making it a general-purpose security key. The KAMF is restricted to being used only for the NAS SMC procedure with the target AMF, while other security procedures use different keys or mechanisms. This localized key usage policy enhances security by preventing key misuse while maintaining manageable complexity through clear key purpose definitions.
Data Source
AI summary
A method performed by a wireless device is provided. The method comprises identifying that an Access and Mobility Management Function (AMF) relocation procedure with re-route via a Radio Access Network (RAN) node is being performed for the wireless device and generating a key associated with a primary authentication of the wireless device. The method further comprises using the key for performing a Non Access Stratum Security Mode Control (NAS SMC) procedure with a first network node operating as a target AMF, and wherein the use of the key by the wireless node is restricted such that the wireless device is restricted from using the key for at least one procedure other than the NAS SMS procedure with the first network node operating as the target AMF.


