Session Management Function Key Configuration for 5G Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing session security algorithms are not applicable to the future mobile communications architecture, posing an urgent need for a security mechanism setup in this context.
Innovation Solution
A key configuration method and security policy determining method are introduced, where a session management network element receives requests for end-to-end communication, determines a security policy based on user and service requirements, and generates a protection key using a shared key between user equipment and the carrier network, which is then sent to the involved devices for secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing session security algorithms are used, then the system maintains compatibility with current architectures, but the security mechanism is not applicable to future mobile communications architecture
Solution Approach 1:
The patent changes the fundamental parameters of security algorithm selection and key management to accommodate future 5G architecture. It introduces new security algorithms and key derivation methods that are parameterized to work with the service-based architecture and network slicing requirements of 5G, making the security mechanism adaptable while maintaining reliability through standardized procedures
2Reliability
If segment-based encryption is used, then the implementation is simpler, but the security level is lower compared to end-to-end protection
Solution Approach 1:
The patent applies segmentation by dividing the end-to-end communication path into multiple segments (UE to AMF, AMF to SMF, SMF to UPF) and implementing encryption at each segment with appropriate security contexts. This segmented approach maintains manageable device complexity while achieving high security levels through layered protection, avoiding the need for a single complex end-to-end encryption system
3Reliability
If end-to-end protection keys are configured for both communication ends, then higher security is achieved, but the key management complexity increases
Solution Approach 1:
The patent introduces the SMF (Session Management Function) as an intermediary that facilitates secure key exchange between communication endpoints. The SMF acts as a trusted mediator that establishes security contexts, derives appropriate keys, and distributes them to relevant network functions and user equipment, thereby achieving end-to-end protection without requiring direct complex key management between end devices
Data Source
AI summary
This application provides a key configuration method. A session management network element receives a request for end-to-end communication and obtains a security policy, where the security policy is determined based on at least one of: a user security requirement that is of the user equipment and that is preconfigured on a home subscriber server, a service security requirement from the user equipment, a security capability requirement supported by the user equipment, a security capability requirement from a carrier network, and a security requirement of a device on the other end of the end-to-end communication. The session management network element obtains a protection key used for protecting the end-to-end communication. The session management network element sends the security policy to the devices on two ends of the end-to-end communication.


