KMSF Security Policy Provisioning for Cross-Domain Session Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Authentication Server Function (AUSF) in 3GPP-based wireless communication systems lacks authorization capabilities, provides only integrity protection without confidentiality, is limited to handling keys within the 3GPP domain, and does not support hardware security modules, leading to unsatisfactory security and performance issues in 5G networks.

Innovation Solution

Introduce a Key Management Server Function (KMSF) that generates and stores security policies, providing both authentication and authorization services, supports end-to-end integrity, confidentiality, and replay protection, and operates within a hardware security module (HSM) to handle keys across various domains, including non-3GPP domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the existing Authentication Server Function (AUSF) is used in 3GPP-based wireless communication systems, then authentication services can be provided, but authorization capabilities are lacking and security protection is incomplete (only integrity protection without confidentiality)

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthorization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a Key Management Server Function (KMSF) that combines both authentication and authorization capabilities in a single unified system. The KMSF can generate multiple types of keys (authentication keys, authorization keys, encryption keys) and provide comprehensive security services including integrity protection and confidentiality protection, thereby resolving the limitation of the AUSF which only provides authentication and integrity protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the AUSF handles keys within the 3GPP domain, then authentication can be performed, but the system is limited and cannot handle keys across various domains including non-3GPP domains

Engineering Contradiction:
Improvedomain coverageVSAvoidkey management system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The KMSF is designed as a universal key management system that can handle keys across multiple domains including 3GPP and non-3GPP domains. It generates domain-specific keys (such as N1 keys for non-3GPP domains) while maintaining a unified architecture, thereby expanding domain coverage without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments key management into domain-specific key generation functions within a unified KMSF architecture. Different key types are generated for different domains (3GPP domain keys, non-3GPP domain keys, application-specific keys), allowing the system to handle multiple domains independently while maintaining overall system coherence and manageability.

Inventive Principle:
Principle #1Segmentation

3Reliability

If the AUSF operates without hardware security module support, then system simplicity is maintained, but security assurance is insufficient

Engineering Contradiction:
Improvesecurity assuranceVSAvoidhardware security module
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Hardware Security Module (HSM) as a separate intermediary component that works in conjunction with the KMSF. The HSM provides secure key storage and cryptographic operations with high security assurance, while the KMSF handles the logical key management functions. This separation allows the system to achieve high security assurance without embedding complex hardware security directly into the key management server, thereby managing overall system complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If traditional key management systems are used, then basic authentication is possible, but scalability and performance in 5G networks are degraded

Engineering Contradiction:
ImproveperformanceVSAvoidkey management system
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The KMSF implements dynamic key management capabilities that adapt to different service requirements, network conditions, and security policies. It can dynamically generate, update, and revoke keys as needed, and provides on-demand key derivation services to multiple network functions simultaneously. This dynamic operation enables the system to scale efficiently with 5G network demands while maintaining performance.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12556912B2Systems and methods for provisioning security policies for deriving session keys
Publication Date: 2026.02.17 VERIZON PATENT & LICENSING INC
  • US12556912B2 patent drawing
  • US12556912B2 patent drawing
  • US12556912B2 patent drawing

AI summary

In some implementations, an key management server function (KMSF) may generate a security policy, wherein the security policy is an application function (AF)-specific security policy or a network function (NF)-specific security policy. The KMSF may transmit, to one of an AF or an NF, the security policy, wherein the AF-specific security policy is associated with a derivation of an AF-specific session key, or the NF-specific security policy is associated with a derivation of an NF-specific session key.