Session Key Identifier Binding for AF-Specific UE Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing AKMA mechanism in 3GPP TS 33.535 is vulnerable to privacy breaches, as the A-KID used for session establishment does not contain the UE's identity in plaintext, allowing unauthorized entities to intercept and misuse the A-KID for obtaining the UE's GPSI.
Innovation Solution
Introduce a privacy-conserving parameter, A-KID-PRIV, constructed from A-TID-PRIV, which includes a temporary identity of the UE and AF, ensuring that the same encrypted identifier cannot be used by different AFs to obtain an AKMA key from the 5G system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the A-KID is used for session establishment without combining A-TID and A-TAI, then the session establishment process is simple, but the UE privacy is compromised as unauthorized AFs can access UE information
Solution Approach 1:
The patent combines A-TID (AKMA temporary UE ID) and A-TAI (AKMA temporary AF ID) into a new identifier A-KID-PRIV = A-TID-PRIV@HNI, where A-TID-PRIV is derived from both A-TID and A-TAI. This merging ensures that the identifier cannot be reused across different AFs, preventing unauthorized access to UE information while maintaining a streamlined session establishment process.
Solution Approach 2:
The patent introduces AF-specific quality into the identifier by incorporating A-TAI (which identifies the specific AF) into the derivation of A-TID-PRIV. This makes the identifier locally unique to each AF-UE pair, ensuring that an identifier valid for one AF cannot be used by another AF to access the same UE, thus protecting UE privacy at the local AF level.
2Adaptability or versatility
If the same A-TID is used by multiple AFs, then the UE identifier can be reused across different applications, but unauthorized AFs can obtain UE identity and AKMA keys
Solution Approach 1:
The patent merges A-TID and A-TAI into a combined identifier A-TID-PRIV, ensuring that while A-TID can be reused across different AFs for versatility, the combination with AF-specific A-TAI creates a unique identifier for each AF-UE pair, thereby maintaining authorization security and preventing unauthorized access.
Solution Approach 2:
The patent segments the identifier into two distinct components: A-TID (which can be reused across AFs) and A-TAI (which is AF-specific). By segmenting the identifier in this way, the system allows versatile reuse of A-TID while using A-TAI to segment and isolate access permissions for each AF, ensuring that reuse does not compromise security.
3Ease of operation
If A-KID contains UE identity in plaintext, then the UE identity can be easily identified by AFs, but the UE privacy is exposed to unauthorized access
Solution Approach 1:
The patent extracts the plaintext UE identity from the identifier and replaces it with a privacy-preserving derived identifier A-TID-PRIV. The original SUPI (Subscription Permanent Identifier) is not included in the transmitted identifier, but the derived A-TID-PRIV maintains the ability to identify the UE session while protecting the actual UE identity from exposure to AFs.
Solution Approach 2:
The patent introduces A-TID-PRIV as an intermediary identifier that mediates between the need for UE identification and privacy protection. Instead of directly exposing SUPI or using plaintext UE identity, the system uses this intermediate derived identifier that allows AFs to identify and establish sessions with UEs without directly accessing or exposing the actual UE identity information.
Data Source
AI summary
Method comprising:monitoring whether a network receives an authorization request for establishing a session of an AF with a UE, wherein the authorization request comprises a permanent identifier of the AF, a received temporary identifier of the AF, and a temporary identifier of a UE;if the authorization request is received:forming a key identifier based on the temporary identifier of the UE;retrieving, based on the key identifier, a stored key and a first permanent identifier of the UE;calculating a calculated temporary identifier of the AF based on the permanent identifier of the AF and the stored key;checking whether the calculated temporary identifier of the AF is identical with the received temporary identifier of the AF;inhibiting authorizing the AF for the establishing the session with the UE if the calculated temporary identifier of the AF is not identical with the received temporary identifier of the AF.


