Relay UE Authentication for Remote UE PDU Session Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G mobile communication networks, terminals connected through L3 relays cannot perform secondary authentication/authorization due to the inability to transmit and receive NAS messages, hindering the establishment of PDU sessions.

Innovation Solution

The method involves an SMF node receiving a report from a relay UE, requesting authentication from a UDM or AMF node, and transmitting authentication requests to an authentication server, while the relay UE receives and reports authentication results from the SMF.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If L3 relay connection is used to enable terminal connectivity, then coverage and connectivity are improved, but NAS message transmission capability deteriorates

Engineering Contradiction:
Improveterminal connectivityVSAvoidNAS message transmission failure
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The relay UE acts as an intermediary to forward authentication messages between the network and remote UE. The SMF sends authentication requests to the relay UE, which then forwards them to the remote UE, enabling indirect communication when direct NAS message transmission is not possible

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is segmented into separate message exchanges between different nodes (SMF, relay UE, remote UE, authentication server). Instead of requiring direct end-to-end NAS message transmission, the authentication is broken down into relayable message segments that can be forwarded through the relay UE

Inventive Principle:
Principle #1Segmentation

2Reliability

If direct NAS message exchange is required for authentication, then authentication security is improved, but relay connection compatibility deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidrelay connection compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The relay UE serves as a trusted intermediary that forwards authentication messages without compromising security. The SMF and authentication server communicate authentication credentials through the relay UE, maintaining security while enabling relay connection compatibility

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication mechanism is designed to work universally both in direct connection scenarios and relay connection scenarios. The same authentication protocol can be executed whether messages are transmitted directly or through a relay UE, making the system multi-functional

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secondary authentication with DN-AAA server is implemented, then network security is improved, but message transmission capability deteriorates when using L3 relay

Engineering Contradiction:
Improvenetwork securityVSAvoidmessage transmission capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The relay UE acts as a mediator to enable secondary authentication messages to be transmitted between the SMF and remote UE. The relay UE forwards authentication requests and responses, making secondary authentication operational in relay scenarios

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network performs preliminary actions by sending authentication requests through the relay UE before establishing the PDU session. The SMF initiates the authentication process in advance, obtaining authentication results before allowing session establishment

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4021047B1Authentication for relay
Publication Date: 2026.03.25 LG ELECTRONICS INC
  • EP4021047B1 patent drawingFigure 1
  • EP4021047B1 patent drawingFigure 2
  • EP4021047B1 patent drawingFigure 3

AI summary

One disclosure of the present specification provides a method for an SMF node to perform authentication. The method may include the steps of: receiving, from a relay UE, a Remote UE report message related to a Remote UE connected to the relay UE; transmitting a request message to a UDM node or an AMF node on the basis of the Remote UE report message including an SUCI of the remote unit; receiving a response message, including an SUPI of the Remote UE, from the UDM node or the AMF node; and transmitting an authentication request message, requesting authentication for the Remote UE, to an authentication server.