UE Security Context Management for Stale K AUSF Cleanup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G communication systems face challenges in maintaining the latest security keys (K AUSF) when user equipment (UE) registers simultaneously with both 3GPP and non-3GPP networks or after re-authentication, leading to potential security vulnerabilities and denial-of-service scenarios due to stale or unused security contexts.

Innovation Solution

A method and apparatus for managing security context in UE, which identifies registration with a new AMF, detects generation of new security contexts, and initiates de-registration with old AUSFs to clear stale contexts, ensuring only the latest K AUSF is maintained across different networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the UE registers simultaneously with both 3GPP and non-3GPP networks via different serving-networks, then the UE can access multiple networks and services, but multiple stale security contexts (K AUSF) are generated leading to security vulnerabilities and denial-of-service scenarios

Engineering Contradiction:
Improvenetwork access capabilityVSAvoidsecurity context validity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by establishing a validation mechanism before security context usage. The UDM validates whether the AMF registering itself belongs to the same serving-network as updated by the AUSF, and whether the UE was recently and successfully authenticated in that network. This preliminary validation prevents stale security contexts from being used, resolving the contradiction between multi-network access and security reliability.

Inventive Principle:
Principle #10Preliminary action

2Stability of the object's composition

If the UDM allows multiple AMFs to register for the same UE, then the UE can maintain connectivity across different networks, but rogue network functions may impersonate the UE using outdated security contexts

Engineering Contradiction:
Improvenetwork connectivityVSAvoidrogue network function impersonation
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback by having the UDM continuously validate AMF registration requests against the latest authentication status stored from the AUSF. When a new AMF registers, the UDM checks whether it belongs to the same serving-network as the one that performed the latest authentication. This feedback loop ensures that only legitimate network functions can access UE security contexts, preventing rogue impersonation while maintaining stable connectivity.

Inventive Principle:
Principle #23Feedback

3Reliability

If the system performs validation checks for every AMF registration, then security is enhanced by preventing unauthorized access, but the complexity of the registration process increases

Engineering Contradiction:
Improveauthentication securityVSAvoidregistration process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies universality by designing the UDM to perform multiple functions within a single validation process. The UDM simultaneously manages subscription information, validates AMF registration authenticity, checks authentication status, and maintains the latest serving-network identity all in one unified mechanism. This multi-functionality reduces the need for separate validation procedures, thereby enhancing security without proportionally increasing process complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP4104475B1Method and apparatus for managing security context related to ue
Publication Date: 2025.08.13 SAMSUNG ELECTRONICS CO LTD
  • EP4104475B1 patent drawingFigure 1
  • EP4104475B1 patent drawingFigure 2
  • EP4104475B1 patent drawingFigure 3a

AI summary

Embodiments of present disclosure relates to an apparatus and method for managing security context related to a UE. Initially, registration of a UE with a new AMF in a communication network is identified. Further, generation of new security context by new AUSF selected by the new AMF for authentication of the UE is detected. Further, presence of one or more old security contexts related to the UE and generated by one or more old AUSFs selected by one or more old AMFs for one or more previous authentications of the UE, is detected. Upon the detection, de-registration of the UE with the one or more old AUSFs is initiated for managing security context related to the UE in the communication network. Thus, stale and inactive security context related to the UE may be deleted in the network and security of communication with the UE is enhanced.