IP Library › Granted Patent US 12,556,912
Granted Patent B2
US 12,556,912 · App. 18/343,483 · Granted Feb 17, 2026

Systems and methods for provisioning security policies for deriving session keys

Inventors: Vinod Kumar Choyi (Conshohocken, PA); Shanthala Kuravangi-Thammaiah (Keller, TX); Yousif Targali (Sammamish, WA)
Assignee: Verizon Patent and Licensing Inc.
H04W12/0433H04L63/20H04W12/041H04W12/35
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,912
App. No.
18/343,483
Granted
Feb 17, 2026
Kind
B2
Abstract

In some implementations, an key management server function (KMSF) may generate a security policy, wherein the security policy is an application function (AF)-specific security policy or a network function (NF)-specific security policy. The KMSF may transmit, to one of an AF or an NF, the security policy, wherein the AF-specific security policy is associated with a derivation of an AF-specific session key, or the NF-specific security policy is associated with a derivation of an NF-specific session key.

Claims (84)

1 . A method, comprising:

receiving, by a key management server function (KMSF) in a Fifth Generation (5G) system and from an authentication server function (AUSF), an AUSF-based key, and an AUSF-based key identifier;

deriving, by the KMSF, a KMSF-based key based on the AUSF-based key;

generating, by the KMSF, a security policy, wherein the security policy is an application function (AF)-specific security policy or a network function (NF)-specific security policy;

storing, by the KMSF, the AUSF-based key, and the AUSF-based key identifier in a hardware security module (HSM) associated with the KMSF;

storing, by the KMSF, the security policy; and

transmitting, by the KMSF and to one of an AF or an NF, the security policy, wherein the AF-specific security policy is associated with a derivation of an AF-specific session key, or the NF-specific security policy is associated with a derivation of an NF-specific session key.

2 . The method of claim 1 , wherein:

the security policy is customized based on one or more of: an AF type, an NF type, an operator domain, or a user equipment (UE) trust level;

the security policy includes information associated with one or more of: a key derivation function (KDF), types of protection, security algorithms, types of asymmetric keys, symmetric key lengths, a certificate issuance, a token issuance, or types of signing algorithms; and

the AF is internal to the 5G system or the AF is external to the 5G system.

3 . The method of claim 1 , further comprising:

receiving, by the KMSF and from the AUSF, an indication of a subscription permanent identifier (SUPI) associated with a user equipment (UE); and

storing, by the KMSF, the SUPI in the HSM associated with the KMSF.

4 . The method of claim 1 , further comprising:

receiving, by the KMSF, a unique application identifier associated with the AF;

generating, by the KMSF and based on the KMSF-based key, an NF-based key, an NF-based key identifier, an AF-based key, and an AF-based key identifier, wherein the AF-based key is generated based on the unique application identifier associated with the AF; and

transmitting, by the KMSF and to the NF, the NF-based key, the NF-based key identifier, and the NF-specific security policy, wherein the NF-specific session key is derived based on the NF-specific security policy.

5 . The method of claim 4 , further comprising:

transmitting, by the KMSF and via the AUSF, the NF-based key, the NF-based key identifier, and the NF-specific security policy; or

transmitting, by the KMSF and directly to the NF using a subscribe or notification message, the NF-based key, the NF-based key identifier, and the NF-specific security policy.

6 . The method of claim 4 , further comprising:

receiving, by the KMSF and from the AF, a request for the AF-based key; and

transmitting, by the KMSF and to the AF, the AF-based key, the AF-based key identifier, and the AF-specific security policy, wherein the AF-specific session key is derived based on the AF-specific security policy,

wherein the AF-specific session key includes multiple AF-specific session keys, and the multiple AF-specific session keys include an AF-based integrity key and an AF-based encryption key.

7 . The method of claim 1 , wherein:

the AF-specific session key provides one or more of: integrity, confidentiality, or replay protection between a user equipment (UE) and the AF; or

the NF-specific session key provides one or more of: integrity, confidentiality, or replay protection between the UE and the NF.

8 . The method of claim 1 , wherein:

the KMSF is a standalone server function; or

the KMSF is associated with an AUSF functionality, and the KMSF is a micro-service that is associated with the AUSF.

9 . A device, comprising:

one or more processors configured to:

receive a unique application identifier associated with an application function (AF);

generate a security policy, wherein the security policy is an AF-specific security policy or a network function (NF)-specific security policy;

generate an NF-based key or an AF-based key, wherein the AF-based key is generated based on the unique application identifier associated with the AF; and

transmit, to one of an AF or an NF in a Fifth Generation (5G) system, the security policy and at least one of the NF-based key or the AF-based key,

wherein an AF-specific session key is derived based on the AF-specific security policy, or

wherein an NF-specific session key is derived based on the NF-specific security policy.

10 . The device of claim 9 , wherein:

the security policy is customized based on one or more of: an AF type, an NF type, an operator domain, or a user equipment (UE) trust level;

the security policy includes information associated with one or more of: a key derivation function (KDF), types of protection, security algorithms, types of asymmetric keys, symmetric key lengths, a certificate issuance, a token issuance, or types of signing algorithms; and

the AF is internal to the 5G system or the AF is external to the 5G system.

11 . The device of claim 9 ,

wherein the one or more processors are further configured to:

receive, from an authentication server function (AUSF), an indication of a subscription permanent identifier (SUPI) associated with a user equipment (UE), an AUSF-based key, and an AUSF-based key identifier; and

store the SUPI, the AUSF-based key, and the AUSF-based key identifier in a hardware security module (HSM).

12 . The device of claim 9 ,

wherein the one or more processors are further configured to:

generate the NF-based key, an NF-based key identifier, the AF-based key, and an AF-based key identifier; and

transmit, to the NF, the NF-based key, the NF-based key identifier, and the NF-specific security policy.

13 . The device of claim 12 ,

wherein the one or more processors are further configured to:

transmit, via an authentication server function (AUSF), the NF-based key, the NF-based key identifier, and the NF-specific security policy; or

transmit, directly to the NF using a subscribe or notification message, the NF-based key, the NF-based key identifier, and the NF-specific security policy.

14 . The device of claim 12 ,

wherein the one or more processors are further configured to:

receive, from the AF, a request for the AF-based key; and

transmit, to the AF, the AF-based key, the AF-based key identifier, and the AF-specific security policy, wherein the AF-specific session key is derived based on the AF-specific security policy,

wherein the AF-specific session key includes multiple AF-specific session keys, and the multiple AF-specific session keys include an AF-based integrity key and an AF-based encryption key.

15 . The device of claim 9 , wherein:

the AF-specific session key provides one or more of: integrity, confidentiality, or replay protection between a user equipment (UE) and the AF; or

the NF-specific session key provides one or more of: integrity, confidentiality, or replay protection between the UE and the NF.

16 . The device of claim 9 ,

wherein the device is associated with a key management server function (KMSF).

17 . A non-transitory computer-readable medium storing a set of instructions, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

receive a unique application identifier associated with an application function (AF);

generate a security policy, wherein the security policy is an AF-specific security policy or a network function (NF)-specific security policy;

generate an NF-based key or an AF-based key, wherein the AF-based key is generated based on the unique application identifier associated with the AF; and

transmit, to one of an AF or an NF in a Fifth Generation (5G) system, the security policy and at least one of the NF-based key or the AF-based key,

wherein an AF-specific session key is derived based on the AF-specific security policy, or

wherein an NF-specific session key is derived based on the NF-specific security policy.

18 . The non-transitory computer-readable medium of claim 17 ,

wherein the one or more instructions, when executed by the one or more processors, further cause the device to:

generate the NF-based key, an NF-based key identifier, the AF-based key, and an AF-based key identifier; and

transmit, to the NF, the NF-based key, the NF-based key identifier, and the NF-specific security policy.

19 . The non-transitory computer-readable medium of claim 17 ,

wherein the one or more instructions, when executed by the one or more processors, further cause the device to:

receive, from the AF, a request for the AF-based key; and

transmit, to the AF, the AF-based key, an AF-based key identifier, and the AF-specific security policy, wherein the AF-specific session key is derived based on the AF-specific security policy,

wherein the AF-specific session key includes multiple AF-specific session keys, and the multiple AF-specific session keys include an AF-based integrity key and an AF-based encryption key.

20 . The non-transitory computer-readable medium of claim 17 ,

wherein the device is associated with a key management server function (KMSF).

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 30, 2023
From: CHOYI, VINOD KUMAR; KURAVANGI-THAMMAIAH, SHANTHALA; TARGALI, YOUSIF
To: VERIZON PATENT AND LICENSING INC.
Reel/Frame 064127/0848 →
Continuity (1)
Related Publication 20250008323A1 · Jan 2, 2025
References Cited (17)
US 11553381B2 · Palanigounder · 2023 [cited by examiner]
US 12143812B2 · Kunz · 2024 [cited by examiner]
US 12316757B2 · You · 2025 [cited by examiner]
US 12401998B2 · Rohini · 2025 [cited by examiner]
US 20190253889A1 · Wu · 2019 [cited by examiner]
US 20210273923A1 · Zhang · 2021 [cited by examiner]
US 20210392495A1 · Tsiatsis · 2021 [cited by examiner]
US 20220159460A1 · Ben Henda · 2022 [cited by examiner]
US 20220345888A1 · Yu · 2022 [cited by examiner]
US 20230199486A1 · Wang · 2023 [cited by examiner]
US 20230247423A1 · Kunz · 2023 [cited by examiner]
US 20230354037A1 · Rohini · 2023 [cited by examiner]
US 20240080662A1 · Suh · 2024 [cited by examiner]
US 20240121606A1 · Zhou · 2024 [cited by examiner]
US 20240413986A1 · Ambekar · 2024 [cited by examiner]
US 20250150817A1 · Guo · 2025 [cited by examiner]
US 20250193771A1 · Baskaran · 2025 [cited by examiner]