AMF Registration Access Security via AS Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication networks face challenges in efficiently managing and optimizing the communication processes between wireless devices and core networks, particularly in terms of service-based architecture, network slicing, and quality of service (QoS) management.

Innovation Solution

The implementation of a service-based architecture within the core network, which includes various network functions (NFs) that offer services to each other and to other elements of the communication network via interfaces, along with the use of network slicing to tailor logical networks for different service requirements, and advanced QoS models for prioritizing packet exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple registration access methods are supported for different wireless devices, then network coverage and accessibility are improved, but security vulnerabilities and authentication complexity increase

Engineering Contradiction:
Improveregistration access methodsVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the registration access process into multiple distinct methods (e.g., random access channel registration, dedicated channel registration, contention-based access, contention-free access). Each method is optimized for specific device types and network conditions, allowing the system to handle diverse registration scenarios while maintaining security through method-specific authentication procedures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism that mediates between different registration access methods and the core network. This intermediary layer verifies device credentials, validates registration requests, and establishes secure context before allowing access, thereby maintaining security across multiple access methods without exposing the core network to direct security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If network slicing is implemented to tailor logical networks for different services, then service quality and resource optimization are improved, but network complexity and management overhead increase

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidnetwork architecture
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements network slicing by segmenting the physical network infrastructure into multiple virtual logical networks, each tailored for specific service requirements (e.g., enhanced mobile broadband, ultra-reliable low-latency communication, massive machine type communication). Each slice operates independently with dedicated resource pools, enabling optimized resource allocation while maintaining a unified physical infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal network slicing framework that can accommodate multiple service types and quality of service requirements within a single physical network infrastructure. The slicing mechanism provides multi-functionality by allowing the same physical resources to be dynamically allocated to different logical networks based on service demands, reducing the need for separate physical infrastructures for each service type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If advanced QoS models are used to prioritize packet exchange, then service quality and user experience are improved, but processing overhead and system complexity increase

Engineering Contradiction:
Improvequality of serviceVSAvoidpacket management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements QoS management by applying local quality policies at different network nodes and layers. Each network element (base station, core network function, gateway) applies QoS rules locally based on packet characteristics, service type, and current network conditions. This distributed QoS approach prioritizes critical packets at the appropriate network layers without requiring centralized control of all packet flow, reducing processing overhead while maintaining service quality.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250071808A1Multiple Registration Access Security
Publication Date: 2025.02.27 OFINNO LLC
  • US20250071808A1 patent drawing
  • US20250071808A1 patent drawing
  • US20250071808A1 patent drawing

AI summary

An AMF receives, from a wireless device, a first registration request message for a first access path of an access type via a first access node. The AMF determines a common security context for the wireless device and sends, to the first access node, a first access stratum (AS) key, wherein the first AS key is based on a first value associated with the first access path and the common security context. The AMF receives, from the wireless device a second registration request message for a second access path of the access type via a second access node, and sends, to the second access node, a second AS key, wherein the second AS key is based on a second value associated with the second access path and the common security context.