Proximity Service Relay Authorization Using AKMA Validation Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems lack effective authorization mechanisms for proximity-based services, making them vulnerable to unauthorized access and attacks via UE-to-network relays, particularly in 5G networks.

Innovation Solution

A system and method for authorization using Authentication and Key Management for Applications (AKMA) services, where a first wireless communication device sends an AKMA key identifier and freshness parameter to a second device as a relay node, generating validation tokens with a proximity-based service function key to ensure secure network access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If wireless communication systems enable proximity-based services via relay nodes, then network access capability is improved, but security vulnerability increases due to lack of authorization mechanisms

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary authorization actions by generating and validating tokens before allowing proximity-based service access. The first wireless communication device generates a token using the freshness parameter and KPBSF key, and the remote PBSF validates this token before granting network access through the relay node, preventing unauthorized access in advance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authorization mechanism involving tokens, freshness parameters, and KPBSF keys that mediate between the first wireless communication device and the relay node. The remote PBSF acts as an intermediary authority that validates tokens and controls access, adding a security layer without blocking legitimate network access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authorization mechanisms are implemented for proximity-based services, then security is improved, but system complexity increases due to additional authentication steps

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization mechanism uses universal cryptographic primitives (tokens, freshness parameters, KPBSF keys) that can be applied across different proximity-based services and wireless communication scenarios. The same token validation framework handles multiple authorization requirements without needing separate mechanisms for each service type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The first wireless communication device autonomously generates the token using its own freshness parameter and KPBSF key without requiring manual intervention. The remote PBSF independently validates the token using stored keys, enabling self-service authorization that reduces operational complexity despite adding security layers

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12593204B2Systems and methods for authorization of proximity based services
Publication Date: 2026.03.31 ZTE CORP
  • US12593204B2 patent drawing
  • US12593204B2 patent drawing
  • US12593204B2 patent drawing

AI summary

Presented are systems and methods for authorization of proximity based services. A first wireless communication device may send, to a second wireless communication device, a message to access a network via the second wireless communication device as a relay node, using at least one authentication and key management for applications (AKMA) service. The message may include an AKMA key identifier (A-KID) and a freshness parameter. The first wireless communication device may generate a validation token to validate against another validation token of the second wireless communication device. The first wireless communication device may generate the validation token using the freshness parameter and a proximity based service function (PBSF) key (KPBSF).