AMF Re-Allocation Routing for Secure NAS Message Rerouting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In certain wireless communications networks, the new access and mobility management function (AMF) may lack authentication server function selection information, leading to potential registration failures during AMF re-allocation and indirect rerouting via the radio access network (RAN), as the rerouted NAS message does not contain necessary AUSF and UDM routing information.
Innovation Solution
The proposed solution involves providing routing information, such as AUSF and UDM instance identifiers, to facilitate AMF re-allocation by transmitting rerouted NAS messages with necessary routing information via the RAN, ensuring the target AMF can fetch the correct UE security context from the AUSF and UDM.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If indirect rerouting via RAN is used for AMF re-allocation, then the initial AMF can transfer the UE to a target AMF when unable to serve the UE, but the rerouted NAS message does not contain necessary AUSF and UDM routing information, leading to registration failures
Solution Approach 1:
The patent applies preliminary action by including AUSF and UDM routing information in the rerouted NAS message before the message reaches the target AMF. This ensures that the target AMF has all necessary routing information available in advance to successfully retrieve the UE security context, preventing registration failures that would occur without pre-provisioned routing data
Solution Approach 2:
The patent uses the initial AMF as an intermediary that extracts and forwards routing information to the target AMF through the rerouted NAS message. This intermediary role ensures that the target AMF receives the necessary AUSF and UDM routing information without requiring direct communication with the initial AMF, maintaining the indirect rerouting architecture while ensuring registration success
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Apparatuses, methods, and systems are disclosed for network security based on routing information. One method (700) includes receiving (702), at a first network device, a security request message from an initial access and mobility management function (AMF), an initial security anchor function (SEAF)), or a combination thereof. The security request message includes information indicating a serving network name (SNN), whether routing information is required, a subscription permanent identifier (SUPI), or some combination thereof. The method (700) includes determining (704), at the first network device, routing information based on the security request message. The method (700) includes transmitting (706), from the first network device, a security response message to the initial AMF, the initial SEAF, or the combination thereof. The security response message includes the routing information.