UE Authentication via AKMA Challenge Vector

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies lack an effective method to authenticate user equipment (UE) for applications, ensuring that the UE is the device it claims to be, while maintaining backward compatibility with existing Authentication and Key Management for Applications (AKMA) procedures.

Innovation Solution

The method involves using a challenge computed based on the AKMA root key (KAKMA) to authenticate the UE. An authentication vector (AV) is generated and compared between the UE and the AKMA anchor function (AAnF) or application function (AF), with the key for the AF being provisioned only after successful authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing AKMA procedures are used without authentication challenge, then backward compatibility is maintained, but UE identity assurance is insufficient

Engineering Contradiction:
ImproveUE identity assuranceVSAvoidauthentication procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by performing authentication challenge before key derivation and application session establishment. The AF sends an authentication challenge to the UE before deriving the application-specific key, ensuring the UE is authenticated before any sensitive operations occur. This prevents key compromise and ensures identity assurance throughout the session.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication challenge as an intermediary mechanism between the AF and UE. This challenge acts as a mediator that verifies UE identity without requiring direct sharing of secret keys. The challenge-response mechanism allows the AF to verify UE authenticity while maintaining secure key management and application session establishment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication challenge is added to AKMA procedure, then UE authentication reliability is improved, but procedure complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication procedure simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies universality by designing the authentication challenge mechanism to work within the existing AKMA framework without requiring separate authentication systems. The challenge can be implemented using existing cryptographic primitives and integrates with the current key derivation process, allowing the same infrastructure to serve both authentication and key management functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements feedback by having the UE respond to the authentication challenge with a challenge response value. The AF uses this feedback to verify UE identity by comparing the response with expected values derived from the challenge and stored keys. This feedback mechanism provides clear authentication confirmation while maintaining procedural simplicity through automated verification.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250175791A1User equipment authentication for applications
Publication Date: 2025.05.29 LENOVO (SINGAPORE) PTE LTD
  • US20250175791A1 patent drawing
  • US20250175791A1 patent drawing
  • US20250175791A1 patent drawing

AI summary

Various aspects of the present disclosure relate to authenticating user equipment (UE) for applications. A first communication device (e.g., a network entity, a server device) authenticates a second communication device (e.g., a UE) for authentication and key management for applications (AKMA) with a challenge, such as an authentication vector (AV), computed based on the AKMA anchor key (KAKMA) corresponding to the second communication device. Comparison of the challenge result (RES) received from the second communication device and an expected challenge result (XRES) is performed by an AKMA anchor function (AAnF) or by an application function (AF), and the AKMA application key (KAF) for the AF is only provisioned after the comparison indicates a successful communication device authentication (e.g., the RES and the XRES are the same).