Network Server Authentication Key Management for Wireless Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication and key management methods for terminal devices in wireless communication networks incur significant signaling overhead, particularly for 5G networks and cellular Internet of Things (CIoT) devices with limited hardware capabilities.
Innovation Solution
A method performed by a network server for authentication and key management, which involves authenticating the terminal device during a primary authentication session, obtaining a first key, and generating bootstrapping security parameters including a second key derived from the first key and a temporary identifier. These parameters are then stored and provided to authentication servers, reducing the need for additional signaling and credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication and key management methods (GBA/GAA) are used in wireless communication networks, then authentication functionality is provided, but signaling overhead increases significantly
Solution Approach 1:
The patent combines the authentication server function (AUSF) and the authentication and key management for applications (AKMA) anchor function into a single network server. This merging eliminates the need for separate GBA bootstrapping procedures and key derivation processes, thereby reducing signaling overhead while maintaining authentication functionality. The unified server structure allows authentication and key management to be performed in an integrated manner, avoiding redundant signaling messages between separate network entities.
2Reliability
If additional bootstrapping procedures are implemented for key management, then security is enhanced, but device complexity increases for CIoT devices with limited hardware capabilities
Solution Approach 1:
The network server performs key derivation and security parameter generation autonomously without requiring additional bootstrapping procedures or complex client-side operations. The terminal device simply authenticates and receives security parameters, while the network server independently derives the application key (KAF) from the authentication key (KAUSF) and manages security contexts. This self-service approach enhances security through proper key derivation while minimizing the computational burden and complexity on CIoT devices with limited hardware capabilities.
3Reliability
If separate authentication and key management procedures are used, then authentication is achieved, but processing time increases
Solution Approach 1:
The network server derives the application key (KAF) and generates security parameters in advance during the authentication process, before they are needed for application-specific security operations. By performing key derivation and security context setup as preliminary actions during the initial authentication phase, the system avoids time-consuming separate key management procedures later. This preliminary action approach maintains robust authentication while reducing overall processing time by eliminating sequential delays.
Data Source
AI summary
A method performed by a network server is provided for authentication and key management for a terminal device in a wireless communication network. The method includes authenticating the terminal device during a primary authentication session for the terminal device. The method further includes responsive to a successful authentication of the terminal device, obtaining a first key. The method further includes generating bootstrapping security parameters. The parameters include a second key derived from the first key and a temporary identifier. The temporary identifier identifies the terminal device and the bootstrapping security parameters.


