AUSF RID-Based A-KID Generation for SUPI-Based AKMA Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 5G AKMA procedure, the AUSF cannot generate an A-KID when the authentication request message carries the SUPI due to the absence of the RID, leading to a failed authentication process.
Innovation Solution
The AUSF generates an A-KID based on the RID extracted from the SUCI or obtained from the UDM/AMF, ensuring the A-KID is stored and used even when the SUPI is carried in the authentication request, thereby completing the AKMA procedure successfully.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the authentication request message carries the SUPI, then the authentication vector get request message can be sent to the UDM function, but the AUSF cannot obtain the RID and cannot generate the A-KID
Solution Approach 1:
The AUSF extracts and stores the RID from the SUCI in advance before the authentication vector retrieval process. This preliminary action ensures that when the authentication request message carries SUPI, the AUSF already has the RID information needed to generate the A-KID, preventing information loss and enabling successful AKMA procedure completion.
2Loss of information
If the authentication request message carries the SUCI, then the AUSF can obtain the RID from the SUCI, but the permanent identifier SUPI cannot be used for authentication
Solution Approach 1:
The AUSF is designed to handle both SUPI and SUCI identifier types universally. When SUCI is received, the AUSF extracts the RID and stores it for later use. This enables the system to accept SUPI in authentication requests while still being able to generate A-KID using the previously extracted RID from the SUCI, thus achieving identifier type flexibility and preventing information loss.
3Reliability
If the AUSF stores the RID, then the A-KID can be generated successfully, but the system complexity increases
Solution Approach 1:
The RID extraction operation is performed once when the SUCI is initially received, and the extracted RID is stored in the AUSF. This extraction and storage mechanism simplifies subsequent A-KID generation processes, as the RID is already available without requiring complex real-time extraction operations, thus improving reliability while managing system complexity.
Data Source
AI summary
An authentication management function AUSF receives an authentication request message from an access and mobility management function AMF, where the authentication request message carries a subscription concealed identifier SUCI. The AUSF sends an authentication vector get request message to a unified data management UDM function, where the authentication vector get request message carries the SUCI. The AUSF receives an authentication vector get response message from the UDM, where the authentication vector get response message includes authentication and key management for application AKMA indication information. The AUSF generates, based on the AKMA indication information, an authentication and key management for application-key identifier based on a routing indicator RID in the SUCI.


