AMF Re-allocation via RAN Intermediary for Slice Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for Access and Mobility Function (AMF) reallocation in cellular communications systems fail to maintain network slice isolation and secure UE registration due to shared security contexts and unprotected messages, leading to registration failures.
Innovation Solution
The method involves forwarding the UE security context to another Network Function (NF) via a protected Service-Based Interface (SBI), using an anonymization proxy to ensure network slice isolation and secure re-routing without impacting the UE or network security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the target AMF sends unprotected NAS messages to the UE during AMF reallocation, then the UE security context can be established, but the UE will discard these messages due to existing NAS security with the initial AMF
Solution Approach 1:
The patent introduces the RAN as an intermediary to transport the UE security context from the initial AMF to the target AMF. This mediator enables the target AMF to obtain the security context without direct contact with the initial AMF, allowing protected NAS message transmission while maintaining network slice isolation.
Solution Approach 2:
The patent applies preliminary action by having the initial AMF forward the UE security context to the target AMF through the RAN before the target AMF sends any NAS messages to the UE. This ensures the target AMF is pre-configured with the necessary security context to protect messages from the outset.
2Reliability
If the initial AMF and target AMF have direct contact for security context transfer, then the target AMF can obtain UE security context, but network slice isolation is compromised
Solution Approach 1:
The RAN serves as an intermediary that enables indirect communication between the initial AMF and target AMF. The initial AMF sends the UE security context to the RAN, which then forwards it to the target AMF, eliminating direct contact between AMFs while ensuring secure context transfer.
Solution Approach 2:
The patent changes the communication dimension by routing the security context transfer through the RAN dimension rather than direct AMF-to-AMF contact. This dimensional change allows the target AMF to obtain the security context while maintaining network slice isolation through indirect communication paths.
3Reliability
If the target AMF requests UE security context from the initial AMF directly, then the security context can be obtained, but the AMF set balance is disrupted
Solution Approach 1:
The RAN acts as a mediator that enables the target AMF to obtain the UE security context without directly contacting the initial AMF. This indirect path maintains the balance of the AMF set by preventing direct dependencies between specific AMFs while ensuring security context availability.
Solution Approach 2:
The RAN performs multiple functions: it serves as the access network for UE connection, the routing path for NAS messages, and the transport medium for security context transfer. This multi-functionality allows the target AMF to obtain security context through a universal path that doesn't disrupt AMF set balance.
Data Source
AI summary
Systems and methods are disclosed herein for Access and Mobility Function (AMF) re-allocation. In one embodiment, a method for AMF re-allocation includes, at an initial AMF, receiving a registration request for a User Equipment (UE) from a Radio Access Network (RAN), deciding to initiate an AMF re-allocation procedure, sending the registration request to the RAN for delivery to a target AMF for the AMF re-allocation procedure, and sending a UE security context of the UE to another Network Function (NF). The method further includes, at the target AMF, receiving a message from the RAN wherein the message includes the registration request from the UE, obtaining the UE security context of the UE from the other NF, and performing protected NAS signaling related to a registration procedure for the UE using the UE security context of the UE.


