5G AMF SMF Security Key Segmentation for Enhanced UE Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems, particularly in the context of 5G, lack advanced security measures for Mobility Management (MM) and Session Management (SM) processes, making it difficult to provide robust security for user equipment (UE) and user data.

Innovation Solution

Implementing a communication system with an Access and Mobility Management Function (AMF) entity and a Session Management Function (SMF) entity, where security keys are applied to MM and SM messages separately, ensuring encryption and integrity protection for secure communication between the communication terminal and these entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single security key is used for both MM and SM messages, then the system complexity is reduced, but the security level is insufficient for 5G communication requirements

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security key management into separate domains: a first security key (KMM) for MM messages and a second security key (KSM) for SM messages. This segmentation allows each message type to have dedicated security protection, enhancing overall security without requiring complete redesign of the security architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security keys are applied to different message types based on their specific security requirements. MM messages use KMM while SM messages use KSM, allowing localized security optimization for each communication domain rather than applying a uniform security approach.

Inventive Principle:
Principle #3Local quality

2Reliability

If separate security keys are applied to MM and SM messages, then advanced security is achieved, but the key management complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security keys KMM and KSM are derived in advance from the master key during the authentication phase, before actual message transmission begins. This preliminary key derivation simplifies subsequent message protection operations, as the keys are already available and configured in both the UE and network entities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The AMF entity acts as an intermediary that receives both MM and SM messages from the UE, separates them, and routes them to appropriate processing entities. The AMF also participates in the key derivation and distribution process, managing the complexity of having multiple security keys by centralizing key management functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11265705B2Communication system, communication terminal, AMF entity, and communication method
Publication Date: 2022.03.01 NEC CORP
  • US11265705B2 patent drawing
  • US11265705B2 patent drawing
  • US11265705B2 patent drawing

AI summary

The present disclosure aims to provide a communication system capable of achieving advanced security in a 5G communication system. The communication system according to the present disclosure includes: a communication terminal (10); an Access and Mobility Management (AMF) entity (20) configured to execute Mobility Management (MM) processing regarding the communication terminal (10); and a Session Management Function (SMF) entity (30) configured to execute Session Management (SM) processing regarding the communication terminal (10), in which the communication terminal (10) sends an MM message used in the MM processing, a first security key having been applied to the MM message, between the communication terminal and the AMF entity (20), and sends an SM message used in the SM processing, a second security key having been applied to the SM message, between the communication terminal and the SMF entity (30) via the AMF entity (20).