DN-AAA Feedback for PDU Session Re-authentication in 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The re-authentication of DN-authorized PDU sessions in next-generation wireless communication systems needs enhancement to effectively manage updated DN authorization information.
Innovation Solution
The method involves a network configuration where the access and mobility management function (AMF) and session management function (SMF) are separated, with a DN-AAA server managing DN authorization data, allowing for efficient re-authentication procedures triggered by the terminal, SMF, or DN-AAA server, ensuring updated authorization information is propagated and policy/control information is dynamically managed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DN authorization data is updated in the DN-AAA server, then authorization information becomes current and secure, but re-authentication overhead and signaling complexity increase
Solution Approach 1:
The patent implements a feedback mechanism where the DN-AAA server notifies the SMF when DN authorization data is updated. The SMF then triggers re-authentication only when necessary, based on this feedback. This selective feedback approach ensures authorization accuracy while minimizing unnecessary re-authentication signaling overhead.
Solution Approach 2:
The SMF autonomously determines whether re-authentication is needed by evaluating the updated DN authorization data received from the DN-AAA server. Instead of forcing re-authentication in all cases, the SMF self-services by making intelligent decisions about when re-authentication is actually required, reducing signaling complexity while maintaining security.
2Reliability
If re-authentication is triggered frequently to ensure updated authorization, then security and authorization accuracy improve, but network signaling overhead and processing time increase
Solution Approach 1:
The DN-AAA server provides feedback to the SMF when DN authorization data is updated, enabling the system to trigger re-authentication only when actually needed. This feedback-driven approach prevents unnecessary re-authentication operations, reducing time loss while maintaining authorization accuracy.
Solution Approach 2:
The system changes the parameter of re-authentication triggering from a fixed frequent schedule to a dynamic event-driven approach based on actual authorization data changes. This parameter change optimizes the balance between authorization accuracy and processing time efficiency.
3Productivity
If the SMF autonomously determines re-authentication need, then signaling efficiency improves, but the decision-making complexity in the SMF increases
Solution Approach 1:
The patent introduces an intermediary notification mechanism from the DN-AAA server to the SMF, which provides structured authorization data change information. This intermediary feedback simplifies the SMF's decision-making by providing clear, standardized inputs, reducing the complexity of autonomous decision logic while maintaining high session management efficiency.
4Reliability
If PDU session authorization is tightly controlled with frequent re-authentication, then security is enhanced, but network resource utilization and service continuity deteriorate
Solution Approach 1:
The feedback mechanism from DN-AAA server to SMF enables security-enhanced authorization control without excessive re-authentication. The system only triggers re-authentication when actual authorization data changes occur, maintaining security while preserving network resource utilization and service continuity by avoiding unnecessary interruptions.
Solution Approach 2:
Instead of continuous or overly frequent re-authentication, the system uses periodic action triggered by specific events (authorization data changes). This event-driven periodic approach maintains security requirements while optimizing network resource utilization and service continuity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The disclosure relates to a communication method and system for converging a 5th-Generation (5G) communication system for supporting higher data rates beyond a 4th-Generation (4G) system with a technology for Internet of Things (IoT). The disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. The disclosure provides a method for supporting re-authentication of a PDU session generated through DN authentication/authorization with a DN-AAA server, and a method and an apparatus for managing a corresponding PDU session if DN authorization information is updated at the time of re-authentication.