Distributed NAS Key Hierarchy for Multi-NF Security Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G System Architecture lacks a solution for securing multiple NAS connections in a distributed manner, specifically addressing the security of multiple NAS connections in a distributed NAS terminations architecture, particularly in a distributed NAS architecture, in a distributed NAS terminations architecture, where NAS connections are terminated in multiple network functions (NFs), leading to increased attack surfaces and weakened security.

Innovation Solution

A framework for securing NAS connections in a distributed NAS terminations architecture is provided, involving the derivation and distribution of shared secret keys and associated key identifiers, using a key hierarchy with anchor keys, NAS parent keys, and NAS child keys, managed by a Security Key Management Function (SKMF), enhancing the NAS security mode command procedure and SEAF functionality to support key derivation and distribution across multiple NFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a distributed NAS terminations architecture is implemented where NAS connections are terminated in multiple network functions, then the system can support multiple NAS procedures simultaneously, but the attack surface increases and security is weakened

Engineering Contradiction:
Improvesupport for multiple NAS proceduresVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security keys into a hierarchical structure with anchor keys at the top level and NAS-specific child keys at lower levels. Each NAS connection terminates at different network functions uses dedicated child keys derived from parent keys, ensuring that compromise of one key does not affect others. This segmentation allows multiple NAS procedures to be supported simultaneously while maintaining security isolation between them.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a Security Key Management Function (SKMF) as an intermediary component that manages the hierarchical key structure. The SKMF derives child keys from parent keys and distributes them to appropriate network functions, enabling secure key management across the distributed architecture without requiring each network function to manage all keys independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique shared secret keys are derived for each NAS connection in the distributed architecture, then security is enhanced, but the key management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hierarchical key structure segments key management into manageable layers. Anchor keys are derived at the top level and used to generate parent keys, which in turn generate child keys for specific NAS procedures. This segmentation allows the system to derive unique keys for each NAS connection while organizing them in a structured manner that reduces management complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary key derivation where anchor keys and parent keys are established before specific NAS connections are needed. Child keys are pre-derived from parent keys based on NAS indicators, so when a NAS connection is established, the required keys are already available or can be quickly derived, reducing the complexity of key management during operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250374042A1Security in a distributed NAS terminations architecture
Publication Date: 2025.12.04 NOKIA TECHNOLOGIES OY
  • US20250374042A1 patent drawing
  • US20250374042A1 patent drawing
  • US20250374042A1 patent drawing

AI summary

Various embodiments provide methods and apparatus for security in a distributed NAS terminations architecture. In an embodiment, a method performed by a terminal device comprises: generating an anchor key; receiving an anchor key identifier for the anchor key; deriving a set of non-access stratum, NAS, parent keys based on the anchor key, a subscription identifier and NAS indicators indicating different NAS procedures; and obtaining, for each of the set of NAS parent keys, a NAS parent key identifier.