Network Policy Key Generation for Secure UE Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems, particularly in 5G networks, face challenges in securely informing user equipment (UE) about network configuration, capabilities, and policies due to the lack of a secure mechanism for communication with the access and mobility management function (AMF), which can be compromised by malicious entities.

Innovation Solution

Implementing a method for wireless communications that involves generating and sharing a security anchor function (SEAF) key based on network policy information to establish a secure connection, using network policy tokens and time validity checks to ensure secure transmission of network policies to the UE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If network policy information is transmitted to UE through AMF, then network configuration and capabilities can be communicated to UE, but security is compromised by malicious entities that can intercept or modify the information

Engineering Contradiction:
Improvenetwork policy information integrityVSAvoidcommunication security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent segments the security verification process by introducing a separate security anchor function (SEAF) that independently verifies network policy information. The SEAF divides the verification task from the AMF's policy transmission function, creating a dedicated security verification path that prevents malicious entities from compromising both information transmission and security verification through a single point of failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces the SEAF as an intermediary between the AMF and UE for security verification. The SEAF receives network policy information from the AMF, independently verifies its authenticity using stored security credentials, and then provides verification results to the UE. This intermediary role separates the policy transmission function (AMF) from the security verification function (SEAF), preventing malicious entities from intercepting or modifying information without detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secure verification mechanism is implemented using SEAF, then network policy integrity can be verified, but system complexity increases due to additional security functions

Engineering Contradiction:
Improvecommunication securityVSAvoidsecurity function architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functionality in the SEAF, which serves both as a security verification entity and as part of the access and mobility management architecture. The SEAF utilizes existing security credentials and authentication mechanisms already present in the 5G system, rather than introducing entirely new security protocols. This approach verifies network policy integrity while leveraging existing infrastructure to minimize additional system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3692733B1Incorporating network policies in key generation
Publication Date: 2026.04.01 QUALCOMM INC
  • EP3692733B1 patent drawingFigure 1
  • EP3692733B1 patent drawingFigure 2
  • EP3692733B1 patent drawingFigure 3

AI summary

The present disclosure provides techniques that may be applied, for example, for providing network policy information in a secure manner. In some cases, a UE may receive a first message for establishing a secure connection with a network, wherein the first message comprises network policy information, generate a first key based in part on the network policy information, and use the first key to verify the network policy information.