5G Security Anchor Function for AMF Change Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G communication system faces challenges in providing efficient authentication procedures, especially during changes in Access and Mobility Management Function (AMF) deployment, which compromises forward security due to the lack of mechanisms for backward security and the inefficiency of relying solely on authentication procedures.

Innovation Solution

A method is introduced where a target AMF sends a security context request to a source AMF, receiving a parameter that identifies a Security Anchor Function (SEAF) AMF, allowing the target AMF to decide an authentication strategy based on the SEAF's situation, thereby avoiding the need for re-authentication and maintaining key security without requiring an independent SEAF function or standardized interfaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication procedure is performed during AMF change, then security is improved, but signaling overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the security anchor function from the AMF by introducing a separate SEAF entity that retains the authentication context. This allows the AMF to be changed without triggering re-authentication, as the SEAF maintains the security context independently. The authentication procedure is separated from the mobility management function, resolving the contradiction between security and authentication time.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The SEAF acts as an intermediary between the UE and the AMF for security context management. It mediates the authentication process by maintaining the security context and providing it to serving AMFs as needed, eliminating the need for re-authentication during AMF changes while preserving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If SEAF is collocated with AMF, then device complexity is reduced, but forward security is compromised

Engineering Contradiction:
Improvenetwork architecture complexityVSAvoidforward security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the SEAF and AMF into separate functional entities. The SEAF is responsible for maintaining security context and generating security parameters, while the AMF handles mobility management. This segmentation allows the SEAF to remain in a secure location (e.g., operator premises) while AMFs can be deployed flexibly at the network edge, preserving forward security without excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimensional separation between security context management (SEAF) and mobility management (AMF). This functional dimensionality allows independent optimization of each function's location and deployment, enabling AMFs to be distributed at the edge while the SEAF remains centralized in secure locations.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Adaptability or versatility

If AMF is deployed at network edge for flexibility, then adaptability is improved, but security risk increases

Engineering Contradiction:
Improvedeployment flexibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The SEAF serves as a secure intermediary that mediates between the edge-deployed AMF and the core network security functions. It maintains the security context in a secure location and provides security parameters to AMFs remotely, allowing AMFs to be deployed flexibly at the network edge without exposing security credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security context management function from the edge-deployed AMF and places it in a centrally-located SEAF. This separation allows the AMF to operate at the network edge with high adaptability while the security context remains protected in a secure location, mitigating security risks associated with edge deployment.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3520454B1Security anchor function in 5g systems
Publication Date: 2024.03.06 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3520454B1 patent drawingFigure 1
  • EP3520454B1 patent drawingFigure 2
  • EP3520454B1 patent drawingFigure 3~4

AI summary

A method for handling change of serving Access and Mobility Managing Function for a user equipment. The method comprises sending (S2) of a context request to a source Access and Mobility Managing Function. This sending is performed from a target Access and Mobility Managing Function. In the target Access and Mobility Managing Function, a context is received (S3) in reply from the source Access and Mobility Managing Function. The context comprises a parameter which identifies a Security Anchor Function Access and Mobility Managing Function. The Security Anchor Function Access and Mobility Managing Function keeps a key, which is shared with the user equipment. A method for handling a change of serving Access and Mobility Managing Function in a user equipment is also disclosed as well as Access and Mobility Managing Function and User Equipments therefore.