Standalone SEAF Bidding Down Attack Detection in 5G

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing 5G security architecture faces challenges in securing wireless communication systems, particularly in maintaining backwards compatibility while preparing for additional security features in Phase 2, and protecting against bidding down attacks.

Innovation Solution

Implementing a standalone Security Anchor Function (SEAF) in network equipment that receives indications from User Equipment (UE) about its support for standalone SEAF during registration and mobility, determining potential bidding down attacks by matching these indications, and managing keys accordingly to ensure secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a standalone SEAF is implemented to provide additional security features in Phase 2, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security architecture by introducing a standalone SEAF as a separate network function from the AMF. This segmentation allows the SEAF to handle security-specific operations independently, improving security reliability while maintaining manageable system complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The standalone SEAF is designed with multi-functionality to handle both Phase 1 and Phase 2 security requirements. It can serve as a security anchor for traditional AMF operations while also supporting advanced security features like key management for interworking with independent SEAFs, providing universal security services across different deployment scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If backwards compatibility is maintained for Phase 1 systems, then ease of operation is improved, but security precision deteriorates due to vulnerability to bidding down attacks

Engineering Contradiction:
Improvebackwards compatibilityVSAvoidsecurity precision
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The standalone SEAF acts as an intermediary between the AMF and the UE for security operations. It mediates key management and security context handling, enabling Phase 1 systems to operate with backwards compatibility while the SEAF enforces enhanced security measures to prevent bidding down attacks, thus resolving the conflict between compatibility and security precision.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by having the SEAF pre-establish security contexts and manage key derivation before actual communication occurs. This preliminary security setup ensures that even when maintaining Phase 1 compatibility, the system is pre-configured to detect and prevent bidding down attacks, improving security precision without compromising ease of operation.

Inventive Principle:
Principle #10Preliminary action

3Ease of manufacture

If key management is simplified for Phase 1 deployments, then ease of manufacture is improved, but adaptability to Phase 2 features deteriorates

Engineering Contradiction:
Improveease of deploymentVSAvoidadaptability to Phase 2 features
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The key management system is designed dynamically to adapt between Phase 1 and Phase 2 operations. The standalone SEAF can operate in a simplified mode for Phase 1 deployments, easing manufacturing and deployment, while automatically adapting to provide enhanced key management capabilities when Phase 2 features are activated, thus maintaining both ease of manufacture and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The architecture allows for disposable or temporary key contexts to be used in Phase 1 deployments, simplifying key management for initial deployments. The standalone SEAF can generate and manage these simpler key contexts when needed, while retaining the capability to implement more robust, long-term key management structures when Phase 2 features are deployed, balancing ease of manufacture with adaptability.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS11849325B2Security mechanism for interworking with independent SEAF in 5G networks
Publication Date: 2023.12.19 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11849325B2 patent drawing
  • US11849325B2 patent drawing
  • US11849325B2 patent drawing

AI summary

Methods and network equipment for implementing security mechanism for interworking with independent security anchor function (SEAF) in 5G networks. A method performed by the standalone SEAF comprises receive a first request for a key to secure communication between the UE and a first access and mobility function (AMF) which a user equipment (UE) requests registration, wherein the request includes a first indication that indicates UE supports a standalone SEAF or not; receive, from a second AMF with which the UE requests registration for performing inter-AMF mobility to the second AMF, a second request for a key to secure communication between the UE and the second AMF, wherein the request includes a second indication that indicates the UE supports a standalone SEAF or not; and determine whether or not a bidding down attack has occurred depending at least in part on whether the first indication matches the second indication.