SMF Session Authentication via NEF for 5G Data Network Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G networks, there is a lack of authentication between terminal devices and third-party authentication entities within the data network, leading to security risks and unauthorized access, which compromises the security of the network and wastes resources.
Innovation Solution
A control-plane-based session processing method that involves a session management function (SMF) authenticating terminal devices with third-party authentication entities using a network exposure function (NEF), ensuring mutual authentication and preventing unauthorized access by utilizing reference information such as data network names, session management-network slice selection assistance information, and application identifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If no authentication is performed between terminal device and third-party authentication entity during PDU session establishment, then the network access is simple and fast, but security of the DN is compromised and unauthorized access occurs
Solution Approach 1:
The patent performs authentication between the terminal device and third-party authentication entity during PDU session establishment before data transmission begins. The SMF entity initiates authentication requests to the third-party authentication entity, and the terminal device completes authentication procedures in advance, ensuring security is established before resource allocation occurs.
Solution Approach 2:
The SMF entity acts as an intermediary between the terminal device and the third-party authentication entity. It receives PDU session establishment requests, determines authentication requirements based on reference information (DNN, S-NSSAI, application identifier), and coordinates the authentication process by sending authentication requests and receiving authentication results, thereby managing the complex authentication流程 without requiring direct complex interactions between terminal and third-party entities.
2Reliability
If authentication is performed between terminal device and third-party authentication entity, then security of the DN is improved, but network resources are consumed during authentication process
Solution Approach 1:
The patent applies authentication selectively based on local quality requirements. The SMF entity determines whether authentication is needed by evaluating reference information such as DNN (data network name), S-NSSAI (session management-network slice selection assistance information), and application identifier. Authentication is performed only for specific PDU sessions that require it, rather than universally for all sessions, thereby optimizing resource usage.
Solution Approach 2:
The system changes authentication parameters dynamically based on session characteristics. The SMF entity uses reference information (DNN, S-NSSAI, application identifier) to determine authentication requirements, and different authentication methods or levels can be applied based on the specific session context, allowing flexible resource management while maintaining security where needed.
3Reliability
If authentication is performed between terminal device and third-party authentication entity, then unauthorized access is prevented, but the PDU session establishment procedure becomes more complex
Solution Approach 1:
The terminal device autonomously determines whether authentication is required based on reference information received during PDU session establishment. The device can identify authentication requirements using DNN, S-NSSAI, or application identifier, and initiates authentication procedures without requiring manual configuration or complex external coordination, thereby simplifying the overall process while maintaining security.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
This application provides a session processing method and device. The method includes: receiving, by an SMF entity, a PDU session establishment request, where the PDU session establishment request is used to request to establish a PDU session for a terminal device; determining, by the SMF entity based on reference information, to authenticate the PDU session; and sending, by the SMF entity, an authentication request to a third-party authentication entity by using a network exposure function NEF entity. A control-plane-based PDU session authentication manner is provided, so that the terminal device and the third-party authentication entity that is in a DN may be required to perform mutual authentication, and unauthorized user access may be rejected, thereby improving security of the DN, and reducing network resources.