AMF Node Managing UE Context During Network Slice Re-authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The AMF faces challenges in managing the UE context during re-authentication and re-authorization procedures for network slice identifiers, specifically regarding whether to continue or remove allowed S-NSSAIs from the Allowed NSSAI set and store them in the Pending NSSAI set.
Innovation Solution
The AMF includes a processor configured to manage UE contexts with sets of allowed and pending network slice identifiers, where it removes a network slice identifier from the allowed set and stores it in the pending set during re-authentication and re-authorization, or continues to store it in the allowed set based on specific conditions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the AMF removes the network slice identifier from the allowed set during re-authentication, then security is improved, but service continuity deteriorates
Solution Approach 1:
The patent segments the network slice identifier management into two distinct sets: Allowed NSSAI for currently authorized slices and Pending NSSAI for slices undergoing re-authentication. This segmentation allows the AMF to maintain service continuity for authorized slices while securely managing re-authentication for pending slices, resolving the contradiction between security and service continuity.
Solution Approach 2:
The patent introduces a Pending NSSAI set that proactively captures network slice identifiers before re-authentication is completed. By preliminarily separating these identifiers into a pending state, the system prepares for secure re-authentication without interrupting ongoing services, thus maintaining both security and service continuity.
2Duration of action of stationary object
If the AMF continues to store the network slice identifier in the allowed set during re-authentication, then service continuity is maintained, but security deteriorates
Solution Approach 1:
The patent divides the authorization state into two segments: Allowed NSSAI for actively authorized slices and Pending NSSAI for slices requiring re-authentication. This segmentation enables the AMF to continue serving authorized slices while securely managing re-authentication processes, preventing security deterioration.
Solution Approach 2:
The Pending NSSAI set acts as an intermediary state between the Allowed NSSAI and the re-authentication process. It mediates the transition by holding identifiers that are no longer fully authorized but haven't been rejected yet, allowing service continuity while preparing for security updates.
3Reliability
If the AMF manages UE context with separate allowed and pending sets, then authorization status is improved, but device complexity increases
Solution Approach 1:
The patent segments the UE context into distinct Allowed NSSAI and Pending NSSAI sets, providing clear authorization status tracking. This segmentation improves authorization management by explicitly separating authorized from pending states, making the complexity manageable through structured organization.
Solution Approach 2:
The patent introduces dynamic state management where the Pending NSSAI can transition to Allowed or be removed based on re-authentication outcomes. This dynamic approach allows flexible authorization status management, improving reliability while the structured transitions help manage complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An AMF node (2) manages a UE context regarding a UE (1). The UE context includes a) a set of allowed network slice identifiers indicating one or more network slice identifiers currently allowed to the UE (1), and b) a set of pending network slice identifiers indicating one or more network slice identifiers for which a Network Slice-Specific Authentication and Authorization (NSSAA) procedure is pending. If the AMF (2) triggers initiation of a re-authentication and re-authorization procedure for a first network slice identifier currently allowed to the UE (1), it removes the first network slice identifier from the allowed set and store the same in the pending set. This, for example, allows the AMF to manage the UE context appropriately.