Standalone SEAF Bidding Down Attack Detection in 5G
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing 5G security architecture faces challenges in securing wireless communication systems, particularly in maintaining backwards compatibility while preparing for additional security features in Phase 2, and protecting against bidding down attacks.
Innovation Solution
Implementing a standalone Security Anchor Function (SEAF) in network equipment that receives indications from User Equipment (UE) about its support for standalone SEAF during registration and mobility, determining potential bidding down attacks by matching these indications, and managing keys accordingly to ensure secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a standalone SEAF is implemented to provide additional security features in Phase 2, then security reliability is improved, but device complexity increases
Solution Approach 1:
The patent segments the security architecture by introducing a standalone SEAF as a separate network function from the AMF. This segmentation allows the SEAF to handle security-specific operations independently, improving security reliability while maintaining manageable system complexity through functional separation.
Solution Approach 2:
The standalone SEAF is designed with multi-functionality to handle both Phase 1 and Phase 2 security requirements. It can serve as a security anchor for traditional AMF operations while also supporting advanced security features like key management for interworking with independent SEAFs, providing universal security services across different deployment scenarios.
2Ease of operation
If backwards compatibility is maintained for Phase 1 systems, then ease of operation is improved, but security precision deteriorates due to vulnerability to bidding down attacks
Solution Approach 1:
The standalone SEAF acts as an intermediary between the AMF and the UE for security operations. It mediates key management and security context handling, enabling Phase 1 systems to operate with backwards compatibility while the SEAF enforces enhanced security measures to prevent bidding down attacks, thus resolving the conflict between compatibility and security precision.
Solution Approach 2:
The system performs preliminary actions by having the SEAF pre-establish security contexts and manage key derivation before actual communication occurs. This preliminary security setup ensures that even when maintaining Phase 1 compatibility, the system is pre-configured to detect and prevent bidding down attacks, improving security precision without compromising ease of operation.
3Ease of manufacture
If key management is simplified for Phase 1 deployments, then ease of manufacture is improved, but adaptability to Phase 2 features deteriorates
Solution Approach 1:
The key management system is designed dynamically to adapt between Phase 1 and Phase 2 operations. The standalone SEAF can operate in a simplified mode for Phase 1 deployments, easing manufacturing and deployment, while automatically adapting to provide enhanced key management capabilities when Phase 2 features are activated, thus maintaining both ease of manufacture and adaptability.
Solution Approach 2:
The architecture allows for disposable or temporary key contexts to be used in Phase 1 deployments, simplifying key management for initial deployments. The standalone SEAF can generate and manage these simpler key contexts when needed, while retaining the capability to implement more robust, long-term key management structures when Phase 2 features are deployed, balancing ease of manufacture with adaptability.
Data Source
AI summary
Methods and network equipment for implementing security mechanism for interworking with independent security anchor function (SEAF) in 5G networks. A method performed by the standalone SEAF comprises receive a first request for a key to secure communication between the UE and a first access and mobility function (AMF) which a user equipment (UE) requests registration, wherein the request includes a first indication that indicates UE supports a standalone SEAF or not; receive, from a second AMF with which the UE requests registration for performing inter-AMF mobility to the second AMF, a second request for a key to secure communication between the UE and the second AMF, wherein the request includes a second indication that indicates the UE supports a standalone SEAF or not; and determine whether or not a bidding down attack has occurred depending at least in part on whether the first indication matches the second indication.


