5G Session Management Using KAKMA Identifier for Service Differentiation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G core network elements are unable to identify or differentiate services that use application-layer keys generated by the AKMA scheme, limiting the provision of differentiated services based on these keys.

Innovation Solution

The proposed solution involves an anchor entity generating and sending the KAKMA identifier and corresponding session policy to the Policy Control Function (PCF), which allows the Session Management Function (SMF) to include the KAKMA identifier in the session establishment process, enabling network elements to identify and provide differentiated services for sessions using AKMA application-layer keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the AKMA scheme is used to generate application-layer keys, then security and authentication capabilities are improved, but network elements are unable to identify or differentiate services using these keys

Engineering Contradiction:
Improveauthentication capabilityVSAvoidservice identification capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a Policy Control Function (PCF) as an intermediary entity that receives the KAKMA identifier from the anchor entity and translates it into service differentiation policies. The PCF acts as a mediator between the authentication system (AKMA) and the service management system, enabling network elements to identify and differentiate services without directly handling the cryptographic keys themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the service identification function from the key management function. Instead of requiring network elements to directly process and identify application-layer keys, the system separates the key generation (anchor entity), identifier transmission (to PCF), and service differentiation (by network elements based on PCF policies) into distinct functional components. This segmentation allows each element to perform its specialized function without complexity.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If application-layer keys are generated for each service, then service differentiation capability is improved, but network complexity increases

Engineering Contradiction:
Improveservice differentiation capabilityVSAvoidnetwork element complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The PCF serves as an intermediary that manages the complexity of service differentiation. Instead of requiring each network element to independently handle multiple application-layer keys and make differentiation decisions, the PCF centralizes this function by receiving the KAKMA identifier and distributing appropriate service policies to network elements, thereby reducing their complexity while maintaining adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter used for service differentiation from the complex application-layer keys themselves to a simplified KAKMA identifier. This parameter change allows network elements to differentiate services based on the identifier and associated policies rather than directly processing cryptographic keys, reducing computational complexity while preserving service differentiation capabilities.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If network elements directly process application-layer keys, then service identification accuracy is improved, but security risks increase

Engineering Contradiction:
Improveservice identification accuracyVSAvoidsecurity exposure
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The PCF acts as a security intermediary that handles the transmission and distribution of service identification information without exposing application-layer keys to network elements. The PCF receives the KAKMA identifier from the anchor entity and translates it into service policies, ensuring that network elements can accurately identify services without directly accessing or processing sensitive cryptographic keys, thereby maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the service identification function from the cryptographic key processing function. Instead of requiring network elements to process application-layer keys directly, the system extracts and transmits only the necessary identification information (KAKMA identifier and associated policies) to network elements, separating the identification task from the sensitive key material and reducing security exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11770702B2Session establishment method and means and communication system
Publication Date: 2023.09.26 ALIBABA GROUP HOLDING LTD
  • US11770702B2 patent drawing
  • US11770702B2 patent drawing
  • US11770702B2 patent drawing

AI summary

A method, device, and system for configuring a session for communication between electronic devices includes sending, by a session management entity of a wireless network, a first request message to a policy control entity of the wireless network, the first request message comprising a key identifier, receiving, by the session management entity, a first response message from the policy control entity, wherein the first response message corresponds to a response to the first request message, and the first response message comprises a session policy for a communication session corresponding to the key identifier, and configuring, by the session management entity, the communication session based at least in part on the session policy.