AMF Redirection via SUCI Registration in 5G Network Slices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G wireless communication systems, when a user equipment (UE) needs to switch from one network slice to another, the current methods for AMF redirection are inefficient, particularly in fully isolated network slices, as they rely on non-access stratum security context transfer over the RAN, which breaks isolation and requires additional authentication rounds, wasting radio resources and potentially routing the UE to the wrong AMF.
Innovation Solution
The system indicates to the UE to perform new registration with its Subscription Conceded Identifier (SUCI) instead of the globally unique temporary identity (GUTI), even when GUTI is valid, allowing the new AMF to run a full authentication procedure directly without relying on the previous AMF, and includes mechanisms for defining compatible network slices to ensure correct routing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If non-access stratum security context transfer over RAN is used for AMF redirection, then the UE can be redirected to another AMF, but this breaks network slice isolation and requires additional authentication rounds
Solution Approach 1:
The patent extracts the security context transfer mechanism from the non-access stratum (NAS) layer and implements it at the access stratum (AS) layer through RRC signaling. This allows the AMF redirection to occur without relying on NAS security context transfer, thereby preserving network slice isolation while enabling efficient redirection. The security context is transferred through the RRC connection reconfiguration message rather than through NAS messages.
Solution Approach 2:
The patent introduces the RRC layer as an intermediary between the UE and the core network for security context transfer during AMF redirection. Instead of directly transferring security contexts through NAS messages (which breaks isolation), the RRC layer acts as a mediator that can transfer necessary information while maintaining the isolation boundaries of different network slices. This intermediary approach allows redirection without compromising security architecture.
2Ease of operation
If non-access stratum security context transfer is used, then AMF redirection can be performed, but additional authentication rounds are required which waste radio resources
Solution Approach 1:
The patent performs security context transfer in advance through RRC signaling before the actual AMF redirection occurs. By pre-transferring the necessary security context information (including SUCI and authentication data) through the RRC connection reconfiguration message, the system eliminates the need for additional authentication rounds during the redirection process. This preliminary action saves radio resources and reduces latency.
Solution Approach 2:
The patent skips the traditional multi-step authentication process by directly transferring the security context through RRC signaling. Instead of going through multiple authentication rounds (which would normally be required when switching AMFs), the system rushes through the redirection process by having the target AMF already possess the necessary security context via the RRC-mediated transfer, thus eliminating unnecessary authentication delays and radio resource consumption.
3Productivity
If GUTI is used for registration, then the authentication process is simplified, but the UE may be routed to the wrong AMF in isolated network slices
Solution Approach 1:
The patent applies different identification mechanisms for different network slice contexts. Instead of using a single global identifier (GUTI) for all registrations, the system uses SUCI (Subscription Concealed Identifier) specifically for isolated network slice registrations. This local quality approach ensures that the appropriate identifier type is used based on the network slice context, thereby maintaining both authentication efficiency and routing accuracy to the correct AMF.
Solution Approach 2:
The patent changes the identification parameter from GUTI to SUCI when dealing with isolated network slices. By dynamically selecting the appropriate identifier type based on the network slice configuration, the system ensures that SUCI is used for isolated slices (which provides accurate AMF routing) while GUTI can be used for non-isolated slices (which provides faster authentication). This parameter change resolves the contradiction between authentication efficiency and routing accuracy.
Data Source
AI summary
Systems, methods, apparatuses, and computer program products for selective indications towards a UE (110), for example, at de-registration (110) from an AMF with request to re-register (130) with another AMF, are provided.


