Key Change Notification for Authentication and Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The AKMA system faces challenges in determining whether the KAKMA is still valid and has been replaced, and in ensuring that only the latest and valid key material is used for secure communication between the UE and the network, due to implicit bootstrapping and explicit lifetimes.

Innovation Solution

A notification procedure is implemented to allow network nodes to subscribe to updates on the authentication status of wireless devices, enabling the UDM and AUSF to track the latest KAKMA and notify AAnF of changes, ensuring that only valid key material is used for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If implicit bootstrapping is used with explicit lifetimes for KAF, then key material can be efficiently managed with clear validity periods, but the system cannot determine whether KAKMA is still valid or has been replaced

Engineering Contradiction:
ImproveKAF lifetimeVSAvoidKAKMA validity determination
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the AUSF notifies the AAnF when KAKMA status changes. The AAnF subscribes to notifications from the AUSF about KAKMA validity changes, and the AUSF sends notifications when KAKMA is replaced or becomes invalid. This feedback loop resolves the contradiction by providing real-time information about KAKMA validity while maintaining the explicit lifetime structure for KAF.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by having the AAnF subscribe to KAKMA status notifications in advance. This subscription is established before any key replacement occurs, ensuring that the AAnF is immediately notified when KAKMA becomes invalid or is replaced, allowing proactive updates to the key cache rather than reactive discovery of key invalidity.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple AUSF instances generate KAKMA, then authentication capacity is increased, but tracking the latest valid KAKMA becomes complex

Engineering Contradiction:
Improveauthentication capacityVSAvoidKAKMA tracking
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces the AUSF as an intermediary that centralizes the tracking and management of KAKMA across multiple AUSF instances. Each AUSF instance notifies the AAnF about KAKMA status changes for its associated UEs. The AAnF maintains a unified view of KAKMA validity by receiving notifications from multiple AUSF instances, resolving the complexity of tracking keys across distributed instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Each AUSF instance autonomously manages its own KAKMA generation and validity tracking for the UEs it serves. When a KAKMA is generated or replaced in any AUSF instance, that instance automatically notifies the AAnF. This self-service approach allows multiple AUSF instances to operate independently while collectively maintaining accurate KAKMA status information through standardized notification procedures.

Inventive Principle:
Principle #25Self-service

3Speed

If AAnF caches KAKMA for efficiency, then key retrieval speed is improved, but the system may use invalid key material if KAKMA is replaced

Engineering Contradiction:
Improvekey retrieval speedVSAvoidkey material validity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the AAnF subscribes to notifications from the AUSF about KAKMA status changes. When the AUSF generates a new KAKMA or determines that a cached KAKMA is no longer valid, it sends a notification to the AAnF. This feedback loop ensures that the AAnF's cached KAKMA remains valid by providing real-time updates on key status changes, resolving the contradiction between caching efficiency and key validity.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20230054571A1Key Change Notification for Authentication and Key Management for Applications
Publication Date: 2023.02.23 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US20230054571A1 patent drawing
  • US20230054571A1 patent drawing
  • US20230054571A1 patent drawing

AI summary

A method performed by a first network node includes transmitting a first subscription request message indicating a request to subscribe to receive notification of changes in an authentication status of a wireless device. A first notification message is received. The first notification message includes an indication of a change in the authentication status of the wireless device.