Direct NF Security Key Derivation for Terminal Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network architectures rely solely on the access and mobility management function (AMF) for security protection between terminals and other network functions, failing to meet future communication requirements for secure direct communication between terminals and multiple network functions.
Innovation Solution
A security key determining method where network functions other than the AMF can directly communicate with terminals, deriving or obtaining keys to establish secure connections, reducing processing and communication overheads by utilizing existing network functions like SEAF or AMF for key derivation and ensuring communication security through unique key determination based on terminal and network information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all control plane messages are forwarded by the AMF for security protection, then communication security between terminal and network functions is ensured, but the system cannot meet future communication requirements for direct terminal-to-network-function communication
Solution Approach 1:
The patent segments the security protection function from the AMF by introducing a separate key derivation mechanism. Each network function (NF) can independently derive security keys for direct communication with terminals, rather than relying on AMF-forwarded messages. This segmentation enables flexible direct communication while maintaining security through distributed key management.
Solution Approach 2:
The patent introduces a key derivation mechanism as an intermediary between the terminal and network functions. This intermediary enables secure direct communication by providing each NF with the capability to derive appropriate security keys, acting as a mediator that facilitates both security and architectural flexibility without requiring AMF involvement in every communication.
2Productivity
If network functions directly communicate with terminals without AMF forwarding, then communication overhead is reduced and future requirements are met, but security protection must be established for each network function
Solution Approach 1:
The patent applies universality by enabling the AMF to serve multiple functions: it continues to perform access and mobility management, and simultaneously acts as a key derivation anchor for other network functions. This multi-functionality reduces overall system complexity by consolidating key management capabilities rather than requiring separate independent key management systems for each NF.
Solution Approach 2:
The patent implements preliminary action by pre-establishing key derivation relationships between the AMF and other network functions before direct communication occurs. The AMF derives and provides security keys to NFs in advance, enabling them to establish secure connections with terminals without requiring complex real-time key negotiation, thus simplifying the security management process.
3Device complexity
If the AMF derives security keys for all network functions, then security protection is centralized and simplified, but processing overheads increase when multiple network functions need direct communication
Solution Approach 1:
The patent introduces dynamics by enabling on-demand key derivation. Instead of the AMF proactively deriving keys for all possible network functions, the system dynamically derives keys only when a specific network function needs to communicate directly with a terminal. This dynamic approach reduces processing overheads by avoiding unnecessary key derivation operations while maintaining security simplicity.
Data Source
AI summary
This application pertains to the field of communication technologies, and provides a security key determining method and apparatus, to resolve a problem that a future communication requirement cannot be met only by ensuring communication security between a terminal and an AMF. In the method, a terminal may directly communicate with a first network function in a network, and after the first network function receives a first request initiated by the terminal, a security connection may be established between the first network function and the terminal by determining a security key. In other words, a message between the first network function and the terminal may be protected by using the security key.


