Distributed NAS Authentication to Reduce AMF Processing Load

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, the legacy authentication procedures for user equipment (UE) establishing direct connections with multiple network functions (NFs) in the core network lack effective mechanisms for authenticating and securing these connections, leading to inefficiencies and increased processing loads on the access and mobility management function (AMF).

Innovation Solution

Implementing a distributed non-access stratum (NAS) architecture that allows direct connections between UEs and NFs, with authentication anchor functions (AAs) performing either a single centralized authentication for all connections or independent authentication for each NF, ensuring secure and efficient communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy authentication procedures are used for direct NAS connections, then authentication can be performed, but the processing burden on the AMF increases significantly

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprocessing burden on AMF
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication function from the AMF by introducing a separate authentication management entity. This allows the AMF to forward authentication requests without performing the actual authentication processing, thereby reducing the processing burden on the AMF while maintaining authentication capability through the segmented authentication function.

Inventive Principle:
Principle #1Segmentation

2Productivity

If direct NAS connections are established between UEs and multiple NFs, then communication efficiency improves, but security mechanisms are lacking

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces an authentication management entity as an intermediary that provides security mechanisms for direct NAS connections. This intermediary performs authentication and authorization functions, enabling secure direct connections between UEs and multiple NFs without requiring the AMF to be involved in every authentication process, thus maintaining security while improving communication efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If centralized authentication is performed for all NF connections, then authentication consistency is maintained, but authentication overhead increases

Engineering Contradiction:
Improveauthentication consistencyVSAvoidauthentication overhead
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The patent implements local quality by allowing the authentication management entity to perform authentication locally for each NF connection based on specific authorization rules. This enables authentication consistency to be maintained where needed while avoiding redundant authentication overhead by performing authentication only when and where necessary, rather than centrally for all connections uniformly.

Inventive Principle:
Principle #3Local quality

4Adaptability or versatility

If multiple independent authentication procedures are performed for different NFs, then NF-specific authentication is achieved, but system complexity increases

Engineering Contradiction:
ImproveNF-specific authenticationVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a multi-functional authentication management entity that can handle authentication for multiple different NFs through a unified framework. This single entity provides NF-specific authentication capabilities by applying different authorization rules for different NFs, thereby achieving adaptability without proportionally increasing system complexity through multiple separate authentication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250247696A1Authentication for distributed non-access stratum
Publication Date: 2025.07.31 APPLE INC
  • US20250247696A1 patent drawing
  • US20250247696A1 patent drawing
  • US20250247696A1 patent drawing

AI summary

The present application relates to devices and components including apparatus, systems, and methods to perform authentication procedures for direct non-access stratum (NAS) connections in a network.