UE Security Context Management for Stale K AUSF Cleanup
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G communication systems face challenges in maintaining the latest security keys (K AUSF) when user equipment (UE) registers simultaneously with both 3GPP and non-3GPP networks or after re-authentication, leading to potential security vulnerabilities and denial-of-service scenarios due to stale or unused security contexts.
Innovation Solution
A method and apparatus for managing security context in UE, which identifies registration with a new AMF, detects generation of new security contexts, and initiates de-registration with old AUSFs to clear stale contexts, ensuring only the latest K AUSF is maintained across different networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the UE registers simultaneously with both 3GPP and non-3GPP networks via different serving-networks, then the UE can access multiple networks and services, but multiple stale security contexts (K AUSF) are generated leading to security vulnerabilities and denial-of-service scenarios
Solution Approach 1:
The system performs preliminary actions by establishing a validation mechanism before security context usage. The UDM validates whether the AMF registering itself belongs to the same serving-network as updated by the AUSF, and whether the UE was recently and successfully authenticated in that network. This preliminary validation prevents stale security contexts from being used, resolving the contradiction between multi-network access and security reliability.
2Stability of the object's composition
If the UDM allows multiple AMFs to register for the same UE, then the UE can maintain connectivity across different networks, but rogue network functions may impersonate the UE using outdated security contexts
Solution Approach 1:
The system implements feedback by having the UDM continuously validate AMF registration requests against the latest authentication status stored from the AUSF. When a new AMF registers, the UDM checks whether it belongs to the same serving-network as the one that performed the latest authentication. This feedback loop ensures that only legitimate network functions can access UE security contexts, preventing rogue impersonation while maintaining stable connectivity.
3Reliability
If the system performs validation checks for every AMF registration, then security is enhanced by preventing unauthorized access, but the complexity of the registration process increases
Solution Approach 1:
The system applies universality by designing the UDM to perform multiple functions within a single validation process. The UDM simultaneously manages subscription information, validates AMF registration authenticity, checks authentication status, and maintains the latest serving-network identity all in one unified mechanism. This multi-functionality reduces the need for separate validation procedures, thereby enhancing security without proportionally increasing process complexity.
Data Source
Figure 1
Figure 2
Figure 3a
AI summary
Embodiments of present disclosure relates to an apparatus and method for managing security context related to a UE. Initially, registration of a UE with a new AMF in a communication network is identified. Further, generation of new security context by new AUSF selected by the new AMF for authentication of the UE is detected. Further, presence of one or more old security contexts related to the UE and generated by one or more old AUSFs selected by one or more old AMFs for one or more previous authentications of the UE, is detected. Upon the detection, de-registration of the UE with the one or more old AUSFs is initiated for managing security context related to the UE in the communication network. Thus, stale and inactive security context related to the UE may be deleted in the network and security of communication with the UE is enhanced.