AMF Re-allocation NAS Security Context Alignment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G NR registration procedure with AMF re-allocation has security flaws that can lead to registration failures due to mismatched NAS security contexts between the initial and target AMFs, causing integrity check failures during handovers.
Innovation Solution
The method involves the initial AMF rerouting the registration request using SUCI or SUPI, generating a security mode command message with redirection criteria or a NULL integrity negotiation algorithm, allowing the UE to accept non-integrity protected messages, and then authenticating the UE with the target AMF to establish a new security association.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If AMF re-allocation is implemented during handovers, then mobility management capability is improved, but security context mismatch occurs between initial and target AMFs causing integrity check failures
Solution Approach 1:
The initial AMF performs preliminary actions by setting redirection criteria and negotiating integrity protection algorithms before the actual handover occurs. This includes configuring the UE to accept non-integrity protected messages temporarily and establishing the security mode command message with the target AMF identifier, ensuring that security contexts are aligned before the handover completes.
Solution Approach 2:
The security mode command message acts as an intermediary mechanism between the initial AMF and target AMF. It carries redirection criteria and integrity negotiation algorithms that mediate the security context transfer, allowing the UE to properly configure its security parameters to match the target AMF's expectations during the handover process.
2Reliability
If redirection criteria are set to allow non-integrity protected messages, then registration success during handover is improved, but security protection is temporarily reduced
Solution Approach 1:
The system performs preliminary security configuration by setting redirection criteria before handover occurs. The initial AMF configures the UE to temporarily accept non-integrity protected messages as a preliminary step, which is then corrected by the security mode command message that establishes proper integrity protection with the target AMF.
Solution Approach 2:
The system applies beforehand cushioning by preparing the UE with redirection criteria that allow temporary acceptance of non-integrity protected messages. This cushioning prevents immediate registration failure during handover, and the security mode command message then restores full security protection, cushioning against the temporary security reduction.
Data Source
AI summary
A system and method of registration with AMF re-allocation. The system and method includes receiving, by an initial AMF from a wireless communication device via a RAN, a registration request comprising a first device identifier associated with the wireless communication device. The system and method includes determining, by the initial AMF, an identifier type associated with the first device identifier. The system and method includes generating, by the initial AMF, a reroute message comprising a second device identifier. The system and method includes originating, by the initial AMF to the wireless communication device, a security mode command message comprising a redirection criteria or an integrity negotiation algorithm, the security mode command message causes the wireless communication device to set the redirection criteria allowing the wireless communication device to accept a request message that is not integrity protected and return a security mode complete message to the initial AMF.


