AMF Relay Key Request for ProSe Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile communication systems face challenges in authenticating user equipment (UE) for network access and managing security connections when UEs access a mobile communication network through direct communication between UEs, which is essential for secure and efficient network operations, especially with the increasing complexity of 5G and future 6G technologies.
Innovation Solution
A method involving the Access and Mobility Management Function (AMF) and Authentication Server Function (AUSF) that receives and processes relay key requests, authenticates remote UEs, and generates proximity-based services (ProSe) session encryption keys to establish secure connections between UEs, ensuring authorized access and secure communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If direct communication between UEs is implemented for network access, then network access flexibility and service efficiency are improved, but security risks and authentication complexity increase
Solution Approach 1:
The patent introduces the AMF as an intermediary between UEs and the authentication system. The AMF receives relay key requests from relay UEs, identifies remote UEs, and coordinates with AUSF for authentication. This mediator approach enables direct UE-to-UE communication while maintaining centralized security control, resolving the contradiction between communication efficiency and security reliability.
Solution Approach 2:
The patent implements preliminary authentication actions by establishing ProSe session encryption keys before direct communication occurs. The AMF performs authentication procedures with remote UEs in advance, and relay UEs obtain encryption keys beforehand through relay key requests. This preliminary security setup enables efficient direct communication while ensuring security requirements are met from the outset.
2Reliability
If traditional network-centric authentication is used, then security control is maintained, but communication latency and network dependency increase
Solution Approach 1:
The patent segments the authentication process into distinct phases: network-centric preliminary authentication (AMF coordinating with AUSF to verify UE identities and establish encryption keys) and UE-to-UE direct communication phase (relay UEs using obtained ProSe session encryption keys for direct communication). This segmentation allows security control to be maintained during key establishment while enabling low-latency direct communication during the execution phase, reducing overall authentication latency.
3Adaptability or versatility
If UE-to-UE direct communication is enabled, then network access flexibility is improved, but device complexity and key management burden increase
Solution Approach 1:
The patent implements self-service mechanisms where relay UEs autonomously obtain ProSe session encryption keys by sending relay key requests to the AMF, and remote UEs autonomously authenticate with the network through the AMF-AUSF coordination. The system provides self-service key management capabilities that enable flexible UE-to-UE communication while reducing the operational burden on individual devices, as the complex key management tasks are automated through standardized procedures.
Data Source
AI summary
The present disclosure relates to a 5G or 6G communication system for supporting a higher data transmission rate. A method performed by an access and mobility management function (AMF) in a wireless communication system according to an embodiment of the present disclosure comprises: receiving, from a relay user equipment (UE) for a UE-network relay communication, a relay key request message including an identifier of a remote UE for the UE-network relay communication; identifying whether the relay UE is authorized to provide a UE-network relay service; identifying an authentication server function (AUSF) related to the remote UE, based on the identifier of the remote UE; transmitting, to the AUSF, an authentication request message including the identifier of the remote UE; in case that an authentication procedure for the remote UE based on the identifier of the remote UE is successfully performed, acquiring a proximity-based services (ProSe) session encryption key established between the remote UE and the relay UE; and transmitting, to the relay UE, the ProSe session encryption key.


