AMF Re-allocation NAS Container Decryption via Context Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing AMF re-allocation procedure in wireless communication networks faces challenges when a UE shares a 5G security context with a different Last Serving AMF, as the Initiating AMF cannot decrypt the NAS Container, leading to inefficiencies in routing the registration request to a Target AMF.
Innovation Solution
The proposed solution optimizes the AMF re-allocation procedure by allowing the Last Serving AMF to decrypt the NAS Container and route the registration request to the Target AMF, using a context transfer mechanism that includes a decryption request indicator, enabling efficient slicing information retrieval and AMF rerouting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the Initiating AMF cannot decrypt the NAS Container due to security context restrictions, then security is maintained, but the AMF re-allocation procedure becomes inefficient and requires additional signaling
Solution Approach 1:
The patent introduces a decryption indicator as an intermediary mechanism that enables the Initiating AMF to request decryption assistance from the Last Serving AMF. This mediator allows the system to maintain security (by not exposing the security context broadly) while improving efficiency (by enabling selective decryption when needed for re-allocation). The decryption indicator acts as a controlled bridge between security constraints and operational needs.
2Ease of operation
If the Initiating AMF requests decryption from the Last Serving AMF, then the NAS Container can be decrypted for routing, but the complexity of the re-allocation procedure increases
Solution Approach 1:
The patent segments the re-allocation procedure into distinct phases: (1) initial registration with encrypted NAS Container, (2) decryption request phase with indicator transmission, (3) decryption execution by Last Serving AMF, and (4) routing phase using decrypted information. This segmentation allows each step to be handled independently and clearly, reducing overall procedural complexity despite adding a decryption step.
Solution Approach 2:
The patent applies preliminary action by having the UE include slicing information in the encrypted NAS Container before re-allocation is needed. This pre-prepared information is readily available for decryption and immediate use in routing decisions, eliminating the need for additional information exchange or processing during the actual re-allocation event.
3Loss of information
If additional signaling messages are exchanged for decryption requests, then the NAS Container can be decrypted, but the signaling overhead increases
Solution Approach 1:
The patent merges the decryption request functionality into existing signaling messages by incorporating a decryption indicator into the context transfer request message. Rather than creating a separate dedicated decryption request message, the indicator is combined with the existing Namf_Communication_UEContextTransfer message, thereby reducing signaling overhead while still conveying the necessary decryption instruction to the Last Serving AMF.
Data Source
AI summary
The AMF re-allocation procedure for an Initiating AMF that has reroute capability via an Access Network (AN) is optimized in scenarios where a wireless device, such as a User Equipment (UE), already shares a 5G security context with-in a Last Serving AMF that is different from the Initiating AMF, and where the Initiating AMF and the Last Serving AMF can communicate with each other via an interface.


