5G Authentication via AMF and SMF Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G mobile communications, the separation of access and mobility management functions (AMF) and session management functions (SMF) creates a need for separate entities to authenticate and manage terminal mobility and sessions effectively, differing from the integrated approach in 4G LTE communications.

Innovation Solution

An authentication method where a terminal transmits a session connection request to the SMF via the AMF and receives authentication information back, with the SMF and AMF processing these messages to ensure secure communication and efficient resource management within network slices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the access and mobility management functions (AMF) and session management functions (SMF) are separated in 5G systems, then the system can provide more specialized and efficient management for mobility and sessions, but the authentication process becomes more complex requiring multiple entities to interact

Engineering Contradiction:
Improvemanagement flexibilityVSAvoidauthentication process complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent divides the authentication process into distinct segments: the terminal initiates authentication with the SMF, which then coordinates with the AMF through defined interfaces. This segmentation allows each function (SMF for session management, AMF for mobility management) to perform its specific authentication tasks independently while maintaining overall system coherence, thus managing complexity through structured division of labor

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The SMF acts as an intermediary between the terminal and the AMF in the authentication process. The terminal sends authentication requests to the SMF, which then communicates with the AMF to verify mobility management credentials. This intermediary role streamlines the interaction by providing a clear protocol sequence and reducing direct complexity between terminal and AMF

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate entities (AMF and SMF) are used to authenticate terminal and sessions, then each entity can be optimized for its specific function, but the number of message exchanges and processing steps increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication actions where the terminal establishes its identity with the SMF before session setup begins. The SMF pre-coordinates with the AMF to prepare mobility management verification. These preliminary actions ensure that when actual session establishment occurs, the authentication framework is already in place, reducing delays during critical session setup moments

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process maintains continuity by establishing a persistent authentication context between the terminal, SMF, and AMF. Once authenticated, this context is maintained throughout the session lifecycle, allowing subsequent communications to reference established credentials rather than repeating full authentication sequences, thus reducing overall authentication time while maintaining reliability

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11659386B2Method and apparatus for authenticating terminal and network in 5G communication system
Publication Date: 2023.05.23 SAMSUNG ELECTRONICS CO LTD
  • US11659386B2 patent drawing
  • US11659386B2 patent drawing
  • US11659386B2 patent drawing

AI summary

The present disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. The present invention relates to an authentication method applied to a next generation 5G communication system and an apparatus for performing same, network slices, a method for managing the network slices, and an apparatus for performing the same.