KMSF Security Policy Provisioning for Cross-Domain Session Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Authentication Server Function (AUSF) in 3GPP-based wireless communication systems lacks authorization capabilities, provides only integrity protection without confidentiality, is limited to handling keys within the 3GPP domain, and does not support hardware security modules, leading to unsatisfactory security and performance issues in 5G networks.
Innovation Solution
Introduce a Key Management Server Function (KMSF) that generates and stores security policies, providing both authentication and authorization services, supports end-to-end integrity, confidentiality, and replay protection, and operates within a hardware security module (HSM) to handle keys across various domains, including non-3GPP domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the existing Authentication Server Function (AUSF) is used in 3GPP-based wireless communication systems, then authentication services can be provided, but authorization capabilities are lacking and security protection is incomplete (only integrity protection without confidentiality)
Solution Approach 1:
The patent introduces a Key Management Server Function (KMSF) that combines both authentication and authorization capabilities in a single unified system. The KMSF can generate multiple types of keys (authentication keys, authorization keys, encryption keys) and provide comprehensive security services including integrity protection and confidentiality protection, thereby resolving the limitation of the AUSF which only provides authentication and integrity protection.
2Adaptability or versatility
If the AUSF handles keys within the 3GPP domain, then authentication can be performed, but the system is limited and cannot handle keys across various domains including non-3GPP domains
Solution Approach 1:
The KMSF is designed as a universal key management system that can handle keys across multiple domains including 3GPP and non-3GPP domains. It generates domain-specific keys (such as N1 keys for non-3GPP domains) while maintaining a unified architecture, thereby expanding domain coverage without proportionally increasing system complexity.
Solution Approach 2:
The patent segments key management into domain-specific key generation functions within a unified KMSF architecture. Different key types are generated for different domains (3GPP domain keys, non-3GPP domain keys, application-specific keys), allowing the system to handle multiple domains independently while maintaining overall system coherence and manageability.
3Reliability
If the AUSF operates without hardware security module support, then system simplicity is maintained, but security assurance is insufficient
Solution Approach 1:
The patent introduces a Hardware Security Module (HSM) as a separate intermediary component that works in conjunction with the KMSF. The HSM provides secure key storage and cryptographic operations with high security assurance, while the KMSF handles the logical key management functions. This separation allows the system to achieve high security assurance without embedding complex hardware security directly into the key management server, thereby managing overall system complexity.
4Productivity
If traditional key management systems are used, then basic authentication is possible, but scalability and performance in 5G networks are degraded
Solution Approach 1:
The KMSF implements dynamic key management capabilities that adapt to different service requirements, network conditions, and security policies. It can dynamically generate, update, and revoke keys as needed, and provides on-demand key derivation services to multiple network functions simultaneously. This dynamic operation enables the system to scale efficiently with 5G network demands while maintaining performance.
Data Source
AI summary
In some implementations, an key management server function (KMSF) may generate a security policy, wherein the security policy is an application function (AF)-specific security policy or a network function (NF)-specific security policy. The KMSF may transmit, to one of an AF or an NF, the security policy, wherein the AF-specific security policy is associated with a derivation of an AF-specific session key, or the NF-specific security policy is associated with a derivation of an NF-specific session key.


