Distributed NAS Authentication to Reduce AMF Processing Load
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G networks, the legacy authentication procedures for user equipment (UE) establishing direct connections with multiple network functions (NFs) in the core network lack effective mechanisms for authenticating and securing these connections, leading to inefficiencies and increased processing loads on the access and mobility management function (AMF).
Innovation Solution
Implementing a distributed non-access stratum (NAS) architecture that allows direct connections between UEs and NFs, with authentication anchor functions (AAs) performing either a single centralized authentication for all connections or independent authentication for each NF, ensuring secure and efficient communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If legacy authentication procedures are used for direct NAS connections, then authentication can be performed, but the processing burden on the AMF increases significantly
Solution Approach 1:
The patent segments the authentication function from the AMF by introducing a separate authentication management entity. This allows the AMF to forward authentication requests without performing the actual authentication processing, thereby reducing the processing burden on the AMF while maintaining authentication capability through the segmented authentication function.
2Productivity
If direct NAS connections are established between UEs and multiple NFs, then communication efficiency improves, but security mechanisms are lacking
Solution Approach 1:
The patent introduces an authentication management entity as an intermediary that provides security mechanisms for direct NAS connections. This intermediary performs authentication and authorization functions, enabling secure direct connections between UEs and multiple NFs without requiring the AMF to be involved in every authentication process, thus maintaining security while improving communication efficiency.
3Stability of the object's composition
If centralized authentication is performed for all NF connections, then authentication consistency is maintained, but authentication overhead increases
Solution Approach 1:
The patent implements local quality by allowing the authentication management entity to perform authentication locally for each NF connection based on specific authorization rules. This enables authentication consistency to be maintained where needed while avoiding redundant authentication overhead by performing authentication only when and where necessary, rather than centrally for all connections uniformly.
4Adaptability or versatility
If multiple independent authentication procedures are performed for different NFs, then NF-specific authentication is achieved, but system complexity increases
Solution Approach 1:
The patent implements universality by creating a multi-functional authentication management entity that can handle authentication for multiple different NFs through a unified framework. This single entity provides NF-specific authentication capabilities by applying different authorization rules for different NFs, thereby achieving adaptability without proportionally increasing system complexity through multiple separate authentication systems.
Data Source
AI summary
The present application relates to devices and components including apparatus, systems, and methods to perform authentication procedures for direct non-access stratum (NAS) connections in a network.


