UE Registration via NAS Security Context Deletion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a 5G mobile communication system, user equipment (UE) fails to register due to the target Access and Mobility Management Function (AMF) not having an NAS security context, leading to authentication request messages being discarded by the UE.
Innovation Solution
The initial AMF sends indication information to the UE to delete or discard the existing NAS security context, allowing the UE to process authentication requests without security protection during AMF reallocation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the target AMF sends an authentication request message without security protection to the UE during AMF reallocation, then the UE can process the authentication request, but the UE discards the message because it expects security protection based on the existing NAS security context
Solution Approach 1:
The initial AMF performs preliminary action by deleting or deactivating the NAS security context before initiating AMF reallocation. This preliminary action ensures that when the target AMF sends authentication requests without security protection, the UE will process them correctly without discarding them due to expecting security protection.
Solution Approach 2:
The initial AMF acts as an intermediary that coordinates between the UE and target AMF during reallocation. It sends indication information to the UE about the upcoming reallocation and security context deletion, enabling the UE to properly handle authentication requests from the target AMF that lack security protection.
2Reliability
If the UE maintains the existing NAS security context during AMF reallocation, then security is preserved, but the UE fails to process authentication requests from the target AMF without security protection
Solution Approach 1:
The initial AMF performs preliminary action by deleting or deactivating the NAS security context before initiating AMF reallocation. This preliminary action ensures that when the target AMF sends authentication requests without security protection, the UE will process them correctly without discarding them due to expecting security protection.
Solution Approach 2:
The initial AMF provides feedback to the UE through indication information about the upcoming AMF reallocation and security context deletion. This feedback enables the UE to adjust its behavior and process authentication requests from the target AMF correctly, preventing rejection of legitimate authentication messages.
3Adaptability or versatility
If the initial AMF performs AMF reallocation via (R)AN, then the UE can be served by a different AMF, but the UE fails to register due to security context issues
Solution Approach 1:
The initial AMF performs preliminary action by deleting or deactivating the NAS security context before initiating AMF reallocation. This preliminary action ensures that when the target AMF sends authentication requests without security protection, the UE will process them correctly without discarding them due to expecting security protection.
Solution Approach 2:
The initial AMF acts as an intermediary that coordinates between the UE and target AMF during reallocation. It sends indication information to the UE about the upcoming reallocation and security context deletion, enabling the UE to properly handle authentication requests from the target AMF that lack security protection.
Data Source
AI summary
Embodiments of this application relate to a registration method and apparatus to ensure that user equipment does not discard and processes a received authentication request message sent by a target AMF. In the registration method, an initial AMF sends indication information to the UE, or the target AMF sends, to the UE, the authentication request message that includes indication information, where the indication information is used to indicate the UE to delete an NAS security context. The UE deletes the NAS security context, processes the received authentication request message, and sends an authentication response message to the target AMF. Alternatively, the UE directly processes a received authentication request message without security protection, and sends an authentication response message to the target AMF.


