Network Slice Authentication via AMF Key Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication networks face challenges in efficiently shielding communication between terminal devices and new network slices, particularly in scenarios where mutually exclusive network slices are controlled by non-business partner tenants with conflicting interests, requiring enhanced access restriction and security isolation.
Innovation Solution
A method and system for network slice isolation, where a terminal device performs a slice authentication procedure with a target Access Management Function, creating and activating a security context based on a mutual secret to isolate the target network slice from the source Access Management Function, thereby ensuring secure access and preventing key compromise across slices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the source AMF derives a new AMF key for the target AMF, then backward security is improved (previous communication is shielded), but the target AMF cannot recover the key used between the terminal device and the source AMF
Solution Approach 1:
The patent segments the key management system by introducing multiple key derivation functions (KDFs) that operate independently for different purposes. The source AMF uses a first KDF to derive a new AMF key for the target AMF, while the terminal device uses a second KDF to derive both the new AMF key and the source AMF key. This segmentation allows the target AMF to obtain only the new key without access to the source key, resolving the contradiction between backward security and key recoverability.
Solution Approach 2:
The patent applies local quality by making the key derivation process location-specific and purpose-specific. Different KDFs are applied at different locations (source AMF vs. terminal device) with different inputs and outputs. The source AMF's KDF outputs only the new AMF key, while the terminal device's KDF outputs both the new AMF key and the source AMF key, allowing each entity to have the specific keys it needs without exposing other keys.
2Reliability
If the target AMF triggers a new authentication run, then forward security is improved (future communication is shielded), but additional authentication overhead is introduced
Solution Approach 1:
The patent implements preliminary action by performing key derivation in advance during the AMF change process, rather than waiting for a full authentication run. The source AMF derives the new AMF key beforehand and provides it to the terminal device through a secure information transfer. This preliminary key derivation eliminates the need for a complete new authentication run, reducing time loss while maintaining forward security through the use of fresh keys derived from the long-term key.
Solution Approach 2:
The patent uses the new AMF key as an intermediary that bridges the old and new authentication states. Instead of requiring a full authentication run, the system uses this intermediate key to transition security contexts. The new AMF key serves as a mediator that allows the terminal device to establish secure communication with the target AMF without exposing the long-term key or requiring full re-authentication, thus reducing overhead while maintaining security.
3Productivity
If network slicing is implemented to increase performance and resource utilization, then network capacity is improved, but access restriction and security isolation between slices are weakened
Solution Approach 1:
The patent segments the security context by introducing slice-specific identifiers (slice IDs) into the key derivation process. Each network slice has its own dedicated KDF that incorporates the slice ID as an input parameter. This ensures that keys derived for one slice cannot be used to access or decrypt traffic from another slice, maintaining strong security isolation while allowing multiple slices to coexist on the same physical infrastructure, thus preserving both network capacity and security.
Solution Approach 2:
The patent applies local quality by making security parameters slice-specific. Each slice has its own key derivation function with unique inputs (including slice-specific identifiers), creating locally optimized security contexts tailored to each slice's requirements. This allows different slices to have different security characteristics and key materials while sharing the same physical network resources, thereby maintaining both high network capacity and strong security isolation between slices.
Data Source
AI summary
Arrangements for network slice isolation. A method is performed by a terminal device. The method includes determining to shift from accessing a first service using a current network slice to accessing a second service using a target network slice. Network access to the current network slice is handled by a source Access Management Function. Network access to the target network slice is handled by a target Access Management Function. The method includes performing a slice authentication procedure in response thereto. During the authentication procedure a mutual secret is shared between the terminal device and the target Access Management Function. The method includes creating a security context for the target network slice based on the mutual secret. The method includes activating the security context, thereby security isolating the target network slice from the source Access Management Function.


