Terminal Reference Authentication Code for 5G AMF SMF Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The interface between the Access and Mobility Management Function (AMF) and the Session Management Function (SMF) in 5G wireless communications systems is insecure, leading to potential tampering of service request messages, which compromises network security.

Innovation Solution

A communication method where a terminal device generates a reference message authentication code based on both AMF and SMF message authentication codes, which is then used to perform integrity checks by both functions, ensuring the security of service request messages across the interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a service request message is transmitted between AMF and SMF without additional security mechanisms, then the communication process is simple and fast, but the interface is insecure and messages can be tampered with

Engineering Contradiction:
Improvesecurity of service request messageVSAvoidcomplexity of integrity check mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The terminal device performs preliminary actions by generating both the first message authentication code (using AMF key) and the second message authentication code (using SMF key) before sending the service request message. The reference message authentication code is also generated in advance by combining these two codes. This preliminary generation of authentication codes ensures that when the message reaches AMF and SMF, both entities can immediately verify the message integrity without additional computational overhead, thus enhancing security while maintaining operational simplicity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The reference message authentication code acts as an intermediary element that bridges the security requirements of both AMF and SMF. Instead of requiring complex mutual authentication protocols between AMF and SMF, the terminal device creates this reference code that contains embedded authentication information from both perspectives. This intermediary code is included in the service request message, allowing both AMF and SMF to independently verify message integrity through their respective keys, thus simplifying the overall security mechanism while ensuring reliable protection

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If both AMF and SMF perform integrity checks on service request messages, then message integrity is ensured, but the processing time and computational overhead increase

Engineering Contradiction:
Improveintegrity of service request messageVSAvoidtime for integrity verification
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The terminal device performs all necessary authentication code generation in advance, before the service request message is transmitted. By pre-generating the first message authentication code, the second message authentication code, and their combination (the reference message authentication code), the system eliminates the need for time-consuming computational operations at the AMF and SMF sides. The verification process at both entities becomes a simple comparison operation, significantly reducing processing time while maintaining dual-integrity-check security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The reference message authentication code serves as a copied or derived version of the authentication information that contains embedded verification data for both AMF and SMF. Instead of requiring both entities to perform complex joint verification computations, the reference code is a pre-computed copy that encapsulates the essential authentication information. Both AMF and SMF can independently verify the message by comparing their computed authentication codes against this reference code, reducing verification time to a simple comparison operation rather than complex computation

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3664404B1Efficient communication method between a terminal and ams plus smf
Publication Date: 2022.12.28 HUAWEI TECH CO LTD
  • EP3664404B1 patent drawingFigure 1~2
  • EP3664404B1 patent drawingFigure 3
  • EP3664404B1 patent drawingFigure 4

AI summary

This specification discloses a communication method. The method includes: obtaining, by a terminal device, a reference message authentication code based on a first message authentication code and a second message authentication code, where the first message authentication code is used by an access and mobility management function AMF to check a service request message, and the second message authentication code is used by a session management function SMF to check the service request message; and sending, by the terminal device, first information and the service request message to the AMF, where the first information is used to instruct the AMF to send the service request message to the SMF, the service request message includes second information, and the second information includes the reference message authentication code. This specification further provides a device. According to embodiments of this application, the SMF can perform a security check on the service request message, to ensure security of a communications network.