IP Library › Granted Patent US 12,549,946
Granted Patent B2
US 12,549,946 · App. 18/304,615 · Granted Feb 10, 2026

Authentication proxy for AKMA authentication service

Inventors: Saurabh Khare (Bangalore, IN); Suresh P Nair (Estero, FL); Ranganathan Mavureddi Dhanasekaran (Munich, DE)
Assignee: Nokia Technologies Oy
H04W12/069H04L63/0884H04W12/041H04W12/0433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,946
App. No.
18/304,615
Granted
Feb 10, 2026
Kind
B2
Abstract

Systems, methods, and software of performing an Authentication and Key Management for Applications (AKMA) authentication service. An AKMA authentication proxy resides between User Equipment (UE) and a plurality of Application Functions (AFs). The AKMA authentication proxy receive an application session establishment request message from the UE requesting an application session with a first application function, sends a key request message toward an AKMA anchor function (AAnF) requesting AKMA application keys for a plurality of application functions, receives a key response message sent from the AAnF that includes the AKMA application keys, identifies a first AKMA application key for the first application function from the AKMA application keys derived by the AAnF, and forwards the application session establishment request message to the first application function with the first AKMA application key.

Claims (67)

1 . An Authentication and Key Management for Applications (AKMA) authentication proxy ( 602 ), comprising:

at least one processor ( 930 ); and

at least one memory ( 932 ) storing computer program code;

wherein the at least one processor is configured to execute the computer program code to cause the AKMA authentication proxy at least to:

receive an application session establishment request message ( 1201 ) from User Equipment (UE) ( 106 ) requesting an application session with a first application function ( 222 );

send a key request message ( 1202 ) toward an AKMA anchor function ( 536 ) requesting AKMA application keys ( 708 ) for a plurality of application functions ( 222 );

receive a key response message ( 1203 ) sent from the AKMA anchor function that includes the AKMA application keys;

identify a first AKMA application key for the first application function from the AKMA application keys derived by the AKMA anchor function; and

forward the application session establishment request message to the first application function with the first AKMA application key.

2 . The AKMA authentication proxy of claim 1 , wherein:

the AKMA application keys are derived by the AKMA anchor function based on application function identities ( 802 ) of the application functions provided in the key request message, and an AKMA anchor key ( 704 ).

3 . The AKMA authentication proxy of claim 1 , wherein the at least one processor further causes the AKMA authentication proxy at least to:

receive a subsequent application session establishment request message ( 1208 ) from the UE requesting an application session with a second application function;

identify a second AKMA application key for the second application function from the AKMA application keys previously derived by the AKMA anchor function; and

forward the subsequent application session establishment request message to the second application function with the second AKMA application key.

4 . The AKMA authentication proxy of claim 1 , wherein the at least one processor further causes the AKMA authentication proxy at least to:

identify a set of the application functions that are authorized for the UE; and

send the key request message toward the AKMA anchor function requesting the AKMA application keys for the set of the application functions that are authorized for the UE.

5 . The AKMA authentication proxy of claim 1 , wherein the at least one processor further causes the AKMA authentication proxy at least to:

send an initial key request message ( 1212 ) toward the AKMA anchor function requesting the first AKMA application key for the first application function;

receive an initial key response message ( 1213 ) sent from the AKMA anchor function that includes the first AKMA application key for the first application function, and includes a UE identity of the UE; and

identify a set of the application functions that are authorized for the UE based on the UE identity

wherein sending the key request message ( 1202 ) toward the AKMA anchor function requesting the AKMA application keys for the plurality of application functions comprises sending a subsequent key request message toward the AKMA anchor function requesting the AKMA application keys for the authorized application functions.

6 . A method of performing an Authentication and Key Management for Applications (AKMA) authentication service, the method comprising:

receiving ( 1302 ), in an AKMA authentication proxy, an application session establishment request message from User Equipment (UE) requesting an application session with a first application function;

sending ( 1304 ) a key request message from the AKMA authentication proxy toward an AKMA anchor function requesting AKMA application keys for a plurality of application functions;

receiving ( 1306 ), at the AKMA authentication proxy, a key response message sent from the AKMA anchor function that includes the AKMA application keys;

identifying ( 1308 ), at the AKMA authentication proxy, a first AKMA application key for the first application function from the AKMA application keys derived by the AKMA anchor function; and

forwarding ( 1310 ) the application session establishment request message from the AKMA authentication proxy to the first application function with the first AKMA application key.

7 . The method of claim 6 , further comprising:

deriving ( 1404 ), at the AKMA anchor function, the AKMA application keys based on application function identities of the application functions provided in the key request message, and an AKMA anchor key.

8 . The method of claim 6 , further comprising:

receiving ( 1504 ), at the UE, an application session establishment response message from the first application function; and

deriving ( 1506 ), at the UE, the first AKMA application key for the first application function based on an application function identity of the first application function, and an AKMA anchor key.

9 . The method of claim 6 , further comprising:

receiving ( 1710 ), at the AKMA authentication proxy, a subsequent application session establishment request message from the UE requesting an application session with a second application function;

identifying ( 1712 ), at the AKMA authentication proxy, a second AKMA application key for the second application function from the AKMA application keys previously derived by the AKMA anchor function; and

forwarding ( 1714 ) the subsequent application session establishment request message from the AKMA authentication proxy to the second application function with the second AKMA application key.

10 . The method of claim 9 , further comprising:

receiving ( 1504 ), at the UE, a subsequent application session establishment response message from the second application function; and

deriving ( 1506 ), at the UE, the second AKMA application key for the second application function based on an application function identity of the second application function, and an AKMA anchor key.

11 . The method of claim 6 , wherein sending the key request message from the AKMA authentication proxy toward the AKMA anchor function comprises:

sending the key request message from the AKMA authentication proxy toward the AKMA anchor function requesting the AKMA application keys for a set of the application functions that are authorized for the UE.

12 . The method of claim 6 , further comprising:

sending ( 1804 ) an initial key request message toward the AKMA anchor function requesting a first AKMA application key for the first application function;

receiving ( 1806 ) an initial key response message sent from the AKMA anchor function that includes the first AKMA application key for the first application function, and includes a UE identity of the UE; and

identifying ( 1808 ) a set of the application functions that are authorized for the UE based on the UE identity;

wherein sending the key request message from the AKMA authentication proxy toward the AKMA anchor function requesting the AKMA application keys for the plurality of application functions comprises sending ( 1810 ) a subsequent key request message toward the AKMA anchor function requesting the AKMA application keys for the authorized application functions.

13 . A non-transitory computer readable medium embodying programmed instructions executed by a processor of an Authentication and Key Management for Applications (AKMA) authentication proxy, wherein the instructions, when executed by the processor, cause the AKMA authentication proxy at least to:

receive, in the AKMA authentication proxy, an application session establishment request message from User Equipment (UE) requesting an application session with a first application function;

send a key request message from the AKMA authentication proxy toward an AKMA anchor function requesting AKMA application keys for a plurality of application functions;

receive, at the AKMA authentication proxy, a key response message sent from the AKMA anchor function that includes the AKMA application keys;

identify, at the AKMA authentication proxy, a first AKMA application key for the first application function from the AKMA application keys derived by the AKMA anchor function; and

forward the application session establishment request message from the AKMA authentication proxy to the first application function with the first AKMA application key.

14 . The computer readable medium of claim 13 , wherein:

the AKMA application keys are derived by the AKMA anchor function based on application function identities of the application functions provided in the key request message, and an AKMA anchor key.

15 . The computer readable medium of claim 13 , wherein the instructions, when executed by the processor, further cause the AKMA authentication proxy at least to:

receive, at the AKMA authentication proxy, a subsequent application session establishment request message from the UE requesting an application session with a second application function;

identify, at the AKMA authentication proxy, a second AKMA application key for the second application function from the AKMA application keys previously derived by the AKMA anchor function; and

forward the subsequent application session establishment request message from the AKMA authentication proxy to the second application function with the second AKMA application key.

16 . The computer readable medium of claim 13 , wherein sending the key request message from the AKMA authentication proxy toward the AKMA anchor function comprises:

sending the key request message from the AKMA authentication proxy toward the AKMA anchor function requesting the AKMA application keys for a set of the application functions that are authorized for the UE.

17 . The computer readable medium of claim 13 , wherein the instructions, when executed by the processor, further cause the AKMA authentication proxy at least to:

send an initial key request message toward the AKMA anchor function requesting a first AKMA application key for the first application function;

receive an initial key response message sent from the AKMA anchor function that includes the first AKMA application key for the first application function, and includes a UE identity of the UE; and

identify a set of the application functions that are authorized for the UE based on the UE identity;

wherein sending the key request message from the AKMA authentication proxy toward the AKMA anchor function requesting the AKMA application keys for the plurality of application functions comprises sending a subsequent key request message toward the AKMA anchor function requesting the AKMA application keys for the authorized application functions.

Assignments (6)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: P NAIR, SURESH
To: NOKIA OF AMERICA CORPORATION
Reel/Frame 063956/0199 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: NOKIA OF AMERICA CORPORATION
To: NOKIA TECHNOLOGIES OY
Reel/Frame 063956/0215 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: MAVUREDDI DHANASEKARAN, RANGANATHAN
To: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
Reel/Frame 063956/0798 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: KHARE, SAURABH
To: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
Reel/Frame 063956/0812 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: NOKIA SOLUTIONS AND NETWORKS GMBH & CO. KG
To: NOKIA TECHNOLOGIES OY
Reel/Frame 063956/0824 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 15, 2023
From: NOKIA SOLUTIONS AND NETWORKS INDIA PRIVATE LIMITED
To: NOKIA TECHNOLOGIES OY
Reel/Frame 063956/0839 →
Priority Claims (1)
IN 202241024385 · Apr 26, 2022 · national
Continuity (1)
Related Publication 20230345246A1 · Oct 26, 2023
References Cited (12)
US 20230086032A1 · Guo · 2023 [cited by examiner]
US 20230413045A1 · Khare · 2023 [cited by examiner]
US 20240147232A1 · Viswambharan · 2024 [cited by examiner]
US 20250056227A1 · Zhuang · 2025 [cited by examiner]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 17)”, 3GPP TS 33.501, V17.5.0, Mar. 2022, pp. 1-293. [cited by applicant]
“New SID on enhancement of AKMA”, 3GPP TSG-SA3 Meeting #106-e, S3-220262, Agenda Item: 4.18, China Mobile, Feb. 14-25, 2022, 3 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Authentication and Key Management for Applications (AKMA) based on 3GPP credentials in the 5G System (5GS) (Release 17)”, 3… [cited by applicant]
“Regulatory LI compliance of AKMA”, 3GPP SA3LI#78e-d, S3i200477, SA3-LI, Aug. 25-26, 2020, 2 pages. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA); Access to network application functions using Hypertext Transfer Protocol over T… [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 17)”, 3GPP TS 23.501, V17.4.0, Mar. 2022, pp. 1-567. [cited by applicant]
“PCR on solution 7 enhancement ”, 3GPP TSG-SA3 Meeting #110Ad-Hoc-e , S3-231813, Agenda Item: 5.6, Nokia, Apr. 17-21, 2023, 5 pages. [cited by applicant]
Extended European Search Report received for corresponding European Patent Application No. 23168845.8, dated Sep. 19, 2023, 6 pages. [cited by applicant]