Home Network UDM Triggers UE Re-authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication procedures in 5G networks are inefficient and not fully defined, particularly in triggering primary re-authentication of User Equipment (UE) in response to specific conditions, which can compromise security and privacy.
Innovation Solution
A Unified Data Management (UDM) element within the home network is configured to trigger primary re-authentication of UE in response to trigger conditions such as counter wrap-around or re-authentication requests, by sending notification messages to the Access and Mobility Management Function (AMF) and Authentication Server Function (AUSF) to initiate re-authentication, allowing for controlled and efficient re-authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If primary authentication procedures are performed frequently to ensure security, then security and privacy are improved, but network overhead and authentication latency increase
Solution Approach 1:
The home network performs re-authentication proactively before the UE actually needs authentication, by detecting counter wrap-around conditions in advance and triggering re-authentication notifications to the AMF and AUSF, thus avoiding authentication failures when the UE attempts to access the network
2Reliability
If re-authentication is triggered proactively by the home network, then authentication failures due to counter wrap-around are reduced, but network signaling overhead increases
Solution Approach 1:
The AMF sends counter wrap-around notifications to the UDM, which then triggers re-authentication based on this feedback information, allowing the system to respond dynamically to actual counter states rather than using fixed periodic re-authentication intervals
Data Source
AI summary
Systems, methods, and software of performing primary re-authentication of User Equipment (UE) (106). In one embodiment, a Unified Data Management (UDM) (218) triggers primary re-authentication of a UE in response to a trigger condition, and sends a re-authentication notification message toward an Access and Mobility Management Function (AMF) (212) to perform primary re-authentication of the UE.


