Session Management Authorization Token for 5G PDU Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In next-generation wireless communication networks like 5G, the separation of mobility management and session management functions from the Mobility Management Entity (MME) poses challenges in ensuring secure and authorized session establishment for User Equipment (UE) across different network locations, particularly due to the potential for unauthorized modifications by Access and Mobility Function (AMF) entities.
Innovation Solution
The implementation of a method that involves generating and transmitting an authorization token based on session parameters and a key received from a Security Anchor Function (SEAF) or a third-party AAA server, ensuring that only authorized User Equipment (UE) can establish a Protocol Data Unit (PDU) session within a logical data network, thereby securing session management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If mobility management and session management functions are separated from the MME in next-generation networks, then network functionality and flexibility are improved, but security risks and vulnerability to unauthorized modifications increase
Solution Approach 1:
The patent introduces an authorization token as an intermediary mechanism between the AMF and SMF. The token, generated by the SEAF based on security parameters and session information, mediates the authorization process to ensure that session management operations are performed only by authorized entities, thus resolving the security risk introduced by functional separation.
2Device complexity
If session management is performed by a logically separate SMF from the AMF, then system modularity and flexibility are improved, but the risk of unauthorized modifications by AMF entities increases
Solution Approach 1:
The patent applies preliminary anti-action by generating the authorization token in advance, before the SMF performs session management operations. The token pre-encodes the authorized operations and parameters, preventing any unauthorized modifications by the AMF during the session establishment process, thus counteracting the security risk before it can manifest.
Solution Approach 2:
The authorization token serves as an intermediary that carries security credentials from the SEAF to the SMF. This intermediary mechanism ensures that even though the SMF is logically separate from the AMF, the SMF can verify authorization independently through the token, preventing unauthorized modifications while maintaining system modularity.
3Reliability
If an authorization token is generated and transmitted to verify UE authorization, then session security and integrity are improved, but signaling overhead and processing complexity increase
Solution Approach 1:
The patent extracts the security verification functionality into a separate authorization token generation process performed by the SEAF. This extraction allows the SMF to focus on session management while delegating security token generation to a dedicated security function, thereby improving session integrity without significantly increasing the processing complexity of the session management entity itself.
Data Source
AI summary
Techniques are described that provide a session management authorization token by receiving a session request message to establish a protocol data unit (PDU) session for a logical data network associated with a user equipment (UE), the session request message may include one or more session parameters; verifying that the UE is authorized to establish the PDU session for the logical data network; receiving a key associated with the PDU session; generating an authorization token based on the received key and the session parameters; and transmitting a session response message including the generated authorization token to the UE.


