AUSF Key Identifier Generation for UE-AF Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional communication technologies lack a method for generating and updating unique key identifiers (KID) for key negotiation between user equipment (UE) and application functions (AF), leading to inefficiencies in key management and security.

Innovation Solution

A method and apparatus for obtaining an authentication and key management for applications anchor key (K AKMA) and unique key identifier (KID) are introduced, where the authentication server function (AUSF) receives messages from access and mobility management functions or security anchor functions to generate or obtain KID and K AKMA based on indication information, ensuring authorized key generation and reduction of unnecessary key storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional key management methods are used without KID generation and update mechanisms, then key negotiation between UE and AF cannot be performed, but implementing KID generation and update mechanisms increases system complexity

Engineering Contradiction:
Improvekey negotiation capabilityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management system is segmented into distinct components: KID generation function, KID update function, and key negotiation function. This segmentation allows each component to be independently managed and implemented, reducing overall system complexity while enabling reliable key negotiation between UE and AF through standardized interfaces

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The KID is generated and stored in advance before key negotiation occurs. The AUSF generates the KID during authentication, and it is pre-stored in both the UE and the AAnF. This preliminary action ensures that when key negotiation is needed, the KID is already available, eliminating the need for complex real-time generation mechanisms during negotiation

Inventive Principle:
Principle #10Preliminary action

2Reliability

If KID and K AKMA are generated for all UEs regardless of need, then key negotiation can be performed, but unnecessary key storage and management overhead increases

Engineering Contradiction:
Improvekey negotiation capabilityVSAvoidkey storage quantity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The KID generation and storage mechanism is made dynamic rather than static. Keys are generated and stored based on actual needs: when a UE performs authentication and accesses an AF, the KID is generated and stored. When the UE leaves the network or stops using services, the corresponding keys can be deleted. This dynamic approach ensures key negotiation capability is maintained when needed while minimizing unnecessary key storage

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of key lifecycle management from permanent storage to conditional storage based on UE network status and service usage. By monitoring parameters such as UE attachment state and service activation, the system dynamically adjusts key retention, ensuring keys are stored only when required for key negotiation and eliminating unnecessary key storage overhead

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4089977B1Key acquisition method and device
Publication Date: 2024.05.15 HUAWEI TECH CO LTD
  • EP4089977B1 patent drawingFigure 1~2
  • EP4089977B1 patent drawingFigure 3
  • EP4089977B1 patent drawingFigure 4A

AI summary

This application discloses a key obtaining method, where the method includes: obtaining, by an AUSF, an authentication and key management for applications anchor function AKMA key and/or a unique key identifier KID of the AKMA key; obtaining, by an AMF/SEAF, a fourth message from the AUSF; and sending a fifth message to UE based on the fourth message, so that the UE obtains the KID and/or the AKMA key based on the fifth message. Embodiments of this application disclose a method for obtaining or generating the AKMA key and the unique key identifier corresponding to the AKMA key, to ensure smooth key negotiation between the UE and an AF and improve communication security between the UE and the AF.