AMF Re-allocation NAS Security Context Alignment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The 5G NR registration procedure with AMF re-allocation has security flaws that can lead to registration failures due to mismatched NAS security contexts between the initial and target AMFs, causing integrity check failures during handovers.

Innovation Solution

The method involves the initial AMF rerouting the registration request using SUCI or SUPI, generating a security mode command message with redirection criteria or a NULL integrity negotiation algorithm, allowing the UE to accept non-integrity protected messages, and then authenticating the UE with the target AMF to establish a new security association.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If AMF re-allocation is implemented during handovers, then mobility management capability is improved, but security context mismatch occurs between initial and target AMFs causing integrity check failures

Engineering Contradiction:
Improvemobility management capabilityVSAvoidintegrity check reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The initial AMF performs preliminary actions by setting redirection criteria and negotiating integrity protection algorithms before the actual handover occurs. This includes configuring the UE to accept non-integrity protected messages temporarily and establishing the security mode command message with the target AMF identifier, ensuring that security contexts are aligned before the handover completes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security mode command message acts as an intermediary mechanism between the initial AMF and target AMF. It carries redirection criteria and integrity negotiation algorithms that mediate the security context transfer, allowing the UE to properly configure its security parameters to match the target AMF's expectations during the handover process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If redirection criteria are set to allow non-integrity protected messages, then registration success during handover is improved, but security protection is temporarily reduced

Engineering Contradiction:
Improveregistration success rateVSAvoidintegrity protection level
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security configuration by setting redirection criteria before handover occurs. The initial AMF configures the UE to temporarily accept non-integrity protected messages as a preliminary step, which is then corrected by the security mode command message that establishes proper integrity protection with the target AMF.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies beforehand cushioning by preparing the UE with redirection criteria that allow temporary acceptance of non-integrity protected messages. This cushioning prevents immediate registration failure during handover, and the security mode command message then restores full security protection, cushioning against the temporary security reduction.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11503533B2Method of registration with access and mobility management function re-allocation
Publication Date: 2022.11.15 ZTE CORP
  • US11503533B2 patent drawing
  • US11503533B2 patent drawing
  • US11503533B2 patent drawing

AI summary

A system and method of registration with AMF re-allocation. The system and method includes receiving, by an initial AMF from a wireless communication device via a RAN, a registration request comprising a first device identifier associated with the wireless communication device. The system and method includes determining, by the initial AMF, an identifier type associated with the first device identifier. The system and method includes generating, by the initial AMF, a reroute message comprising a second device identifier. The system and method includes originating, by the initial AMF to the wireless communication device, a security mode command message comprising a redirection criteria or an integrity negotiation algorithm, the security mode command message causes the wireless communication device to set the redirection criteria allowing the wireless communication device to accept a request message that is not integrity protected and return a security mode complete message to the initial AMF.