Key Change Notification for Authentication and Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The AKMA system faces challenges in determining whether the KAKMA is still valid and has been replaced, and in ensuring that only the latest and valid key material is used for secure communication between the UE and the network, due to implicit bootstrapping and explicit lifetimes.
Innovation Solution
A notification procedure is implemented to allow network nodes to subscribe to updates on the authentication status of wireless devices, enabling the UDM and AUSF to track the latest KAKMA and notify AAnF of changes, ensuring that only valid key material is used for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If implicit bootstrapping is used with explicit lifetimes for KAF, then key material can be efficiently managed with clear validity periods, but the system cannot determine whether KAKMA is still valid or has been replaced
Solution Approach 1:
The patent implements a feedback mechanism where the AUSF notifies the AAnF when KAKMA status changes. The AAnF subscribes to notifications from the AUSF about KAKMA validity changes, and the AUSF sends notifications when KAKMA is replaced or becomes invalid. This feedback loop resolves the contradiction by providing real-time information about KAKMA validity while maintaining the explicit lifetime structure for KAF.
Solution Approach 2:
The system performs preliminary actions by having the AAnF subscribe to KAKMA status notifications in advance. This subscription is established before any key replacement occurs, ensuring that the AAnF is immediately notified when KAKMA becomes invalid or is replaced, allowing proactive updates to the key cache rather than reactive discovery of key invalidity.
2Adaptability or versatility
If multiple AUSF instances generate KAKMA, then authentication capacity is increased, but tracking the latest valid KAKMA becomes complex
Solution Approach 1:
The patent introduces the AUSF as an intermediary that centralizes the tracking and management of KAKMA across multiple AUSF instances. Each AUSF instance notifies the AAnF about KAKMA status changes for its associated UEs. The AAnF maintains a unified view of KAKMA validity by receiving notifications from multiple AUSF instances, resolving the complexity of tracking keys across distributed instances.
Solution Approach 2:
Each AUSF instance autonomously manages its own KAKMA generation and validity tracking for the UEs it serves. When a KAKMA is generated or replaced in any AUSF instance, that instance automatically notifies the AAnF. This self-service approach allows multiple AUSF instances to operate independently while collectively maintaining accurate KAKMA status information through standardized notification procedures.
3Speed
If AAnF caches KAKMA for efficiency, then key retrieval speed is improved, but the system may use invalid key material if KAKMA is replaced
Solution Approach 1:
The patent implements a feedback mechanism where the AAnF subscribes to notifications from the AUSF about KAKMA status changes. When the AUSF generates a new KAKMA or determines that a cached KAKMA is no longer valid, it sends a notification to the AAnF. This feedback loop ensures that the AAnF's cached KAKMA remains valid by providing real-time updates on key status changes, resolving the contradiction between caching efficiency and key validity.
Data Source
AI summary
A method performed by a first network node includes transmitting a first subscription request message indicating a request to subscribe to receive notification of changes in an authentication status of a wireless device. A first notification message is received. The first notification message includes an indication of a change in the authentication status of the wireless device.


