Roaming Security Key Transfer for VPLMN Legal Interception

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems fail to support legal interception (LI) when a user equipment (UE) roams, as they do not provide necessary security keys to visited public land mobile networks (VPLMNs) that do not support Authentication and Key Management for Applications (AKMA), hindering lawful interception capabilities.

Innovation Solution

Establish a secure connection between the UE and the home network's Application Function (AF) using an application session key, which is then communicated to the VPLMN's network entity, either a VAAnF if AKMA is supported or a Network Exposure Function (NEF) if not, ensuring LI context is stored, thus enabling LI even in non-AKMA-supporting VPLMNs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security keys are not provided to VPLMN, then home network security is maintained, but legal interception capability is lost in roaming scenarios

Engineering Contradiction:
Improvelegal interception capabilityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the AAnF as an intermediary entity that manages security keys between the home network and VPLMN. The AAnF receives security context from the home network and selectively provides necessary keys to VPLMN, enabling legal interception capability while maintaining centralized control and avoiding direct complex key management in roaming networks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security key management into distinct components: the home network generates and holds the master security context, the AAnF manages key distribution and derivation, and the VPLMN receives only the specific keys needed for legal interception. This segmentation allows each entity to have simplified responsibilities while achieving overall LI capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If application session key is communicated to VPLMN, then legal interception is enabled, but security key exposure risk increases

Engineering Contradiction:
Improvelegal interception supportVSAvoidsecurity key exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the master security context into derived application session keys through cryptographic parameter changes. The AAnF uses key derivation functions to generate specific session keys from the master context, ensuring that even if session keys are exposed to VPLMN, the master context remains secure and can derive new keys when needed.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent performs preliminary cryptographic transformations to create security contexts and derived keys before transmission to VPLMN. The home network and AAnF prepare the security context in advance, establishing encryption parameters and derived keys that enable legal interception without exposing the master secret, thereby preventing future security risks.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20260082216A1Providing security keys to a serving network of a user equipment
Publication Date: 2026.03.19 LENOVO (SINGAPORE) PTE LTD
  • US20260082216A1 patent drawing
  • US20260082216A1 patent drawing
  • US20260082216A1 patent drawing

AI summary

Various aspects of the present disclosure relate to situations where a secure connection is established, e.g., using an application session key, between a user equipment (UE) and an application function (AF) in a home public land mobile network (HPLMN) of the UE. The AF communicates the application session key to an authentication and key management for applications (AKMA) anchor function (AAnF) in the HPLMN, also referred to as a home AAnF (HAAnF). The user can roam with the UE to a visited public land mobile network (VPLMN) and the AAnF transmits the application session key to a network entity in the VPLMN. A security context that includes the application session key is stored in the VPLMN. Any refreshes of the application session key or other keys derived from the application session key are similarly communicated to the AAnF in the HPLMN and a network entity in the VPLMN.