5G Session Management Using KAKMA Identifier for Service Differentiation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G core network elements are unable to identify or differentiate services that use application-layer keys generated by the AKMA scheme, limiting the provision of differentiated services based on these keys.
Innovation Solution
The proposed solution involves an anchor entity generating and sending the KAKMA identifier and corresponding session policy to the Policy Control Function (PCF), which allows the Session Management Function (SMF) to include the KAKMA identifier in the session establishment process, enabling network elements to identify and provide differentiated services for sessions using AKMA application-layer keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AKMA scheme is used to generate application-layer keys, then security and authentication capabilities are improved, but network elements are unable to identify or differentiate services using these keys
Solution Approach 1:
The patent introduces a Policy Control Function (PCF) as an intermediary entity that receives the KAKMA identifier from the anchor entity and translates it into service differentiation policies. The PCF acts as a mediator between the authentication system (AKMA) and the service management system, enabling network elements to identify and differentiate services without directly handling the cryptographic keys themselves.
Solution Approach 2:
The patent segments the service identification function from the key management function. Instead of requiring network elements to directly process and identify application-layer keys, the system separates the key generation (anchor entity), identifier transmission (to PCF), and service differentiation (by network elements based on PCF policies) into distinct functional components. This segmentation allows each element to perform its specialized function without complexity.
2Adaptability or versatility
If application-layer keys are generated for each service, then service differentiation capability is improved, but network complexity increases
Solution Approach 1:
The PCF serves as an intermediary that manages the complexity of service differentiation. Instead of requiring each network element to independently handle multiple application-layer keys and make differentiation decisions, the PCF centralizes this function by receiving the KAKMA identifier and distributing appropriate service policies to network elements, thereby reducing their complexity while maintaining adaptability.
Solution Approach 2:
The patent changes the parameter used for service differentiation from the complex application-layer keys themselves to a simplified KAKMA identifier. This parameter change allows network elements to differentiate services based on the identifier and associated policies rather than directly processing cryptographic keys, reducing computational complexity while preserving service differentiation capabilities.
3Measurement precision
If network elements directly process application-layer keys, then service identification accuracy is improved, but security risks increase
Solution Approach 1:
The PCF acts as a security intermediary that handles the transmission and distribution of service identification information without exposing application-layer keys to network elements. The PCF receives the KAKMA identifier from the anchor entity and translates it into service policies, ensuring that network elements can accurately identify services without directly accessing or processing sensitive cryptographic keys, thereby maintaining security.
Solution Approach 2:
The patent extracts the service identification function from the cryptographic key processing function. Instead of requiring network elements to process application-layer keys directly, the system extracts and transmits only the necessary identification information (KAKMA identifier and associated policies) to network elements, separating the identification task from the sensitive key material and reducing security exposure.
Data Source
AI summary
A method, device, and system for configuring a session for communication between electronic devices includes sending, by a session management entity of a wireless network, a first request message to a policy control entity of the wireless network, the first request message comprising a key identifier, receiving, by the session management entity, a first response message from the policy control entity, wherein the first response message corresponds to a response to the first request message, and the first response message comprises a session policy for a communication session corresponding to the key identifier, and configuring, by the session management entity, the communication session based at least in part on the session policy.


