Network Server Authentication Key Management for Wireless Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication and key management methods for terminal devices in wireless communication networks incur significant signaling overhead, particularly for 5G networks and cellular Internet of Things (CIoT) devices with limited hardware capabilities.

Innovation Solution

A method performed by a network server for authentication and key management, which involves authenticating the terminal device during a primary authentication session, obtaining a first key, and generating bootstrapping security parameters including a second key derived from the first key and a temporary identifier. These parameters are then stored and provided to authentication servers, reducing the need for additional signaling and credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication and key management methods (GBA/GAA) are used in wireless communication networks, then authentication functionality is provided, but signaling overhead increases significantly

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines the authentication server function (AUSF) and the authentication and key management for applications (AKMA) anchor function into a single network server. This merging eliminates the need for separate GBA bootstrapping procedures and key derivation processes, thereby reducing signaling overhead while maintaining authentication functionality. The unified server structure allows authentication and key management to be performed in an integrated manner, avoiding redundant signaling messages between separate network entities.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If additional bootstrapping procedures are implemented for key management, then security is enhanced, but device complexity increases for CIoT devices with limited hardware capabilities

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network server performs key derivation and security parameter generation autonomously without requiring additional bootstrapping procedures or complex client-side operations. The terminal device simply authenticates and receives security parameters, while the network server independently derives the application key (KAF) from the authentication key (KAUSF) and manages security contexts. This self-service approach enhances security through proper key derivation while minimizing the computational burden and complexity on CIoT devices with limited hardware capabilities.

Inventive Principle:
Principle #25Self-service

3Reliability

If separate authentication and key management procedures are used, then authentication is achieved, but processing time increases

Engineering Contradiction:
ImproveauthenticationVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network server derives the application key (KAF) and generates security parameters in advance during the authentication process, before they are needed for application-specific security operations. By performing key derivation and security context setup as preliminary actions during the initial authentication phase, the system avoids time-consuming separate key management procedures later. This preliminary action approach maintains robust authentication while reducing overall processing time by eliminating sequential delays.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12342164B2Methods for authentication and key management in a wireless communications network and related apparatuses
Publication Date: 2025.06.24 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12342164B2 patent drawing
  • US12342164B2 patent drawing
  • US12342164B2 patent drawing

AI summary

A method performed by a network server is provided for authentication and key management for a terminal device in a wireless communication network. The method includes authenticating the terminal device during a primary authentication session for the terminal device. The method further includes responsive to a successful authentication of the terminal device, obtaining a first key. The method further includes generating bootstrapping security parameters. The parameters include a second key derived from the first key and a temporary identifier. The temporary identifier identifies the terminal device and the bootstrapping security parameters.