Proximity Service Relay Authorization Using AKMA Validation Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication systems lack effective authorization mechanisms for proximity-based services, making them vulnerable to unauthorized access and attacks via UE-to-network relays, particularly in 5G networks.
Innovation Solution
A system and method for authorization using Authentication and Key Management for Applications (AKMA) services, where a first wireless communication device sends an AKMA key identifier and freshness parameter to a second device as a relay node, generating validation tokens with a proximity-based service function key to ensure secure network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If wireless communication systems enable proximity-based services via relay nodes, then network access capability is improved, but security vulnerability increases due to lack of authorization mechanisms
Solution Approach 1:
The system performs preliminary authorization actions by generating and validating tokens before allowing proximity-based service access. The first wireless communication device generates a token using the freshness parameter and KPBSF key, and the remote PBSF validates this token before granting network access through the relay node, preventing unauthorized access in advance
Solution Approach 2:
The patent introduces an intermediary authorization mechanism involving tokens, freshness parameters, and KPBSF keys that mediate between the first wireless communication device and the relay node. The remote PBSF acts as an intermediary authority that validates tokens and controls access, adding a security layer without blocking legitimate network access
2Reliability
If authorization mechanisms are implemented for proximity-based services, then security is improved, but system complexity increases due to additional authentication steps
Solution Approach 1:
The authorization mechanism uses universal cryptographic primitives (tokens, freshness parameters, KPBSF keys) that can be applied across different proximity-based services and wireless communication scenarios. The same token validation framework handles multiple authorization requirements without needing separate mechanisms for each service type
Solution Approach 2:
The first wireless communication device autonomously generates the token using its own freshness parameter and KPBSF key without requiring manual intervention. The remote PBSF independently validates the token using stored keys, enabling self-service authorization that reduces operational complexity despite adding security layers
Data Source
AI summary
Presented are systems and methods for authorization of proximity based services. A first wireless communication device may send, to a second wireless communication device, a message to access a network via the second wireless communication device as a relay node, using at least one authentication and key management for applications (AKMA) service. The message may include an AKMA key identifier (A-KID) and a freshness parameter. The first wireless communication device may generate a validation token to validate against another validation token of the second wireless communication device. The first wireless communication device may generate the validation token using the freshness parameter and a proximity based service function (PBSF) key (KPBSF).


