UE Security Context Handling for AMF Reallocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In wireless communication networks, especially during Access and Mobility Management Function (AMF) reallocation, the existing solutions face challenges in securely transferring security contexts between Initial and Target AMFs, leading to issues with unprotected authentication requests and potential service disruptions.

Innovation Solution

A wireless device accepts unprotected authentication requests temporarily, allowing exceptions to standard security context handling rules until AMF re-allocation is complete, enabling successful registration and security context transfer between Initial and Target AMFs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the UE strictly follows standard security context handling rules and drops unprotected authentication requests, then network security is maintained, but AMF reallocation fails causing service disruption

Engineering Contradiction:
ImproveAMF reallocation successVSAvoidunprotected authentication request handling
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The UE dynamically changes its security context handling behavior based on the registration state. During AMF reallocation (before registration completion), the UE transitions from dropping unprotected authentication requests to accepting them. After registration completion, it returns to the standard behavior of dropping such requests. This dynamic state change resolves the contradiction by adapting security rules to the specific phase of the protocol.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the parameter of authentication request handling from a static rule (always drop) to a state-dependent rule (drop except during registration). The UE introduces a new parameter or modifies existing behavior to accept unprotected authentication requests specifically when the registration is not yet complete, enabling AMF reallocation while maintaining security otherwise.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If the UE accepts unprotected authentication requests during AMF reallocation, then seamless registration is achieved, but security rules are violated

Engineering Contradiction:
Improveregistration completion speedVSAvoidsecurity context handling
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The UE dynamically adjusts its security context handling based on registration state. During the registration process (when completion is not yet achieved), the UE accepts unprotected authentication requests to enable AMF reallocation. Once registration is complete, it returns to standard security behavior. This dynamic adaptation resolves the contradiction between productivity and security reliability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The UE prepares for potential AMF reallocation by being in a state where it can accept unprotected authentication requests before registration is complete. This preliminary positioning allows the network to perform reallocation without disrupting the registration process, achieving both speed and security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the UE maintains strict security rules throughout registration, then security context integrity is preserved, but AMF reallocation cannot occur

Engineering Contradiction:
Improvesecurity context integrityVSAvoidAMF reallocation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The UE dynamically modifies its security context handling rules during the registration process. When registration is not yet complete, the UE temporarily accepts unprotected authentication requests, enabling AMF reallocation. After registration completion, it returns to strict security rules. This dynamic behavior preserves security context integrity while enabling reallocation capability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the parameter of authentication request handling from a fixed strict security mode to a state-dependent mode. The UE introduces a condition based on registration completion status, allowing unprotected requests only during registration. This parameter change enables both security integrity and reallocation adaptability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11917412B2AMF reallocation handling using UE exceptions to security context rules
Publication Date: 2024.02.27 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11917412B2 patent drawing
  • US11917412B2 patent drawing
  • US11917412B2 patent drawing

AI summary

A UE having a security context with an Initial AMF is able to accept an unprotected AUTHRQ, under certain circumstances, for a limited time. In one embodiment, a UE considers the security context to be temporary, which invokes rules or exceptions different than a permanent security context, such as the acceptance of an unprotected AUTHRQ from a Target AMF. The network may indicate to the UE the temporary status, or the UE may assume it. Alternatively, the UE may enable exceptions to the defined rules associated with the security context. In one embodiment, the UE receives a plurality of partial registration acceptance messages, each indicating a specific task or aspect of the overall registration has been completed. The UE may mark its security context temporary, or enable exceptions to the rules 10 associated with it, until a partial registration acceptance messages indicates AMF re-allocation is complete or is not required. In another embodiment, the UE accepts unprotected authentication messages from the network until the Registration procedure is completed, enabling a Target AMF to successfully send it an unprotected AUTHRQ.