Roaming Application Key Delivery via Visitor PLMN Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, especially during roaming, existing authentication mechanisms face challenges in securely managing application encryption keys across different public land mobile networks (PLMNs), leading to potential security breaches and compliance issues with lawful interception requirements.

Innovation Solution

The proposed solution involves an apparatus and method where an authentication server function of a home PLMN transmits an anchor key registration request to an application security function, including a registered serving network identifier, to manage and control the use of application encryption keys across visitor PLMNs, ensuring secure key management and compliance with LI requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing authentication mechanisms are used during roaming, then authentication can be performed across different PLMNs, but secure management of application encryption keys cannot be ensured leading to security breaches

Engineering Contradiction:
Improveauthentication securityVSAvoidsecurity breaches
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an application security function (AF) as an intermediary component that mediates between the authentication server function (AUSF) and the application function (AF) in visitor PLMNs. This intermediary manages application encryption keys securely by receiving anchor keys from the home PLMN and distributing them to authorized visitor PLMNs, preventing direct exposure of sensitive keying material and eliminating security breaches associated with existing roaming authentication mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If application encryption keys are distributed across visitor PLMNs, then application sessions can be encrypted, but key management complexity increases leading to compliance issues with lawful interception requirements

Engineering Contradiction:
Improvekey management securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments key management into distinct functional components: the authentication server function (AUSF) in the home PLMN generates and manages anchor keys, while the application security function (AF) in visitor PLMNs manages application-specific encryption keys. This segmentation allows complex key management to be distributed across multiple specialized functions, reducing overall system complexity while maintaining security and enabling lawful interception compliance through proper key separation

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If anchor key registration is implemented in home PLMN, then key distribution can be controlled, but authentication protocol complexity increases

Engineering Contradiction:
Improvekey distribution controlVSAvoidauthentication protocol complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having the authentication server function (AUSF) in the home PLMN pre-register anchor keys with the application security function (AF) before actual application sessions are established. This preliminary key registration creates a ready-to-use keying infrastructure that simplifies subsequent authentication operations, as visitor PLMNs can directly utilize pre-distributed keys without complex real-time key derivation or negotiation

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230413045A1Application key delivery in a roaming situation
Publication Date: 2023.12.21 NOKIA TECHNOLOGIES OY
  • US20230413045A1 patent drawing
  • US20230413045A1 patent drawing
  • US20230413045A1 patent drawing

AI summary

Various example embodiments relate to authentication in case of roaming. An apparatus may be configured to receive, by an application function of a first visitor public land mobile area network (PLMN) or a second visitor PLMN of a device, a registered serving network identifier of the device indicative of the first visitor PLMN; and transmit, based on the registered serving network identifier, an encryption key to an application security function of the first visitor PLMN for encryption of an application session of the device.