IP Library › Granted Patent US 12,732,885
Granted Patent B2
US 12,732,885 · App. 18/557,177 · Granted Sep 8, 2026

Method and apparatus for reassignment of access and mobility management function in communication system

Inventors: Taehyung Lim (Suwon-si, KR); Jungje Son (Suwon-si, KR); Duckey Lee (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
H04W36/385H04W12/033H04W36/0038H04W60/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,732,885
App. No.
18/557,177
Granted
Sep 8, 2026
Kind
B2
Abstract

A method for carrying out AMF reassignment in a communication system may comprise the steps of: transmitting, to an NSSF, a first request message including at least one of a first parameter for requesting a public key of an AMF that is to be reassigned and a second parameter for requesting a token related to the AMF that is to be reassigned; receiving, from the NSSF, a first response message including at least one of information indicating a target AMF set, and a public key of the target AMF set or the token; generating, on the basis of first security context for user equipment, an SC container including second security context for a target AMF; encrypting the SC container by using the public key; and transmitting, to the target AMF via a radio access network related to the user equipment, at least one of the encrypted SC container, additional information related to encryption of the SC container, and the token.

Claims (134)

1 . A method by an access and mobility management function (AMF) for AMF reallocation in a communication system, the method comprising:

receiving a registration request message from a user equipment (UE);

obtaining a first security context for the UE from a previous AMF;

transmitting, to a network slice selection function (NSSF), a first request message including at least one of a first parameter requesting a public key of an AMF to be reallocated or a second parameter requesting a token related to the AMF to be reallocated;

receiving, from the NSSF, a first response message including information indicating a target AMF set and at least one of a public key of the target AMF set or the token;

generating a security context container including a second security context for a target AMF based on the first security context;

encrypting the security context container using the public key;

transmitting the encrypted security context container and at least one of additional information related to encryption of the security context container and the token to the target AMF through a radio access network related to the UE;

receiving a first registration request message from a first UE;

obtaining a third security context for the first UE from a first previous AMF;

transmitting, to the NSSF, a third request message including a third parameter requesting a public key of an AMF to be reallocated;

receiving, from the NSSF, a third response message including information indicating a first target AMF set;

transmitting, to a network repository function (NRF), a fourth request message including a fourth parameter requesting a token related to the AMF to be reallocated;

receiving, from the NRF, a fourth response message including a token related to the first target AMF set;

generating a first security context container including a fourth security context for a first target AMF based on the third security context;

encrypting the first security context container using the public key; and

transmitting the encrypted first security context container and at least one of additional information related to encryption of the first security context container and the token to the first target AMF through a first radio access network related to the first UE.

2 . The method of claim 1 , wherein the token includes, as information verifiable by the target AMF, at least one of:

an issuer item for identifying the NSSF;

a subject item for identifying an initial AMF or an AMF set where the initial AMF belongs;

an audience item for identifying the target AMF or the target AMF set where the target AMF belongs;

a service name item indicating that the token is for AMF reallocation;

a time information item indicating a time when the token is valid; or

at least one of an electronic signature and/or a message authentication code (MAC) generated for at least one of the items.

3 . The method of claim 1 , further comprising:

transmitting a second request message for requesting subscriber information about the UE to a unified data management (UDM) for data storage and management; and

receiving a second response message including the subscriber information.

4 . The method of claim 1 , wherein the token includes, as information verifiable by the first target AMF, at least one of:

an issuer item for identifying the NSSF;

a subject item for identifying an initial AMF or an AMF set where the initial AMF belongs;

an audience item for identifying the first target AMF or a first target AMF set where the target AMF belongs;

a service name item indicating that the token is for AMF reallocation;

a time information item indicating a time when the token is valid; or

at least one of an electronic signature and/or a message authentication code (MAC) generated for at least one of the items.

5 . The method of claim 1 , further comprising:

receiving a second registration request message from a second UE;

obtaining a fifth security context for the second UE from a second previous AMF;

transmitting, to the NSSF, a fifth request message for network slice selection;

receiving, from the NSSF, a fifth response message including information indicating a second target AMF set;

transmitting, to the NRF, a sixth request message including at least one of a fifth parameter requesting a public key of the second target AMF set or a sixth parameter requesting a token related to the second target AMF set;

receiving, from the NRF, a sixth response message including at least one of the public key of the second target AMF set or the token;

generating a second security context container including a sixth security context for a second target AMF based on the fifth security context;

encrypting the second security context container using the public key; and

transmitting the encrypted second security context container and at least one of additional information related to encryption of the second security context container and the token to the second target AMF through a second radio access network related to the second UE.

6 . The method of claim 5 , wherein the token includes, as information verifiable by the second target AMF, at least one of:

an issuer item for identifying the NSSF;

a subject item for identifying an initial AMF or an AMF set where the initial AMF belongs;

an audience item for identifying the second target AMF or the second target AMF set where the second target AMF belongs;

a service name item indicating that the token is for AMF reallocation;

a time information item indicating a time when the token is valid; or

at least one of an electronic signature and/or a message authentication code (MAC) generated for at least one of the items.

7 . The method of claim 1 , further comprising:

receiving a third registration request message from a third UE;

obtaining a seventh security context for the third UE from a third previous AMF;

transmitting, to the NSSF, a seventh request message for network slice selection;

receiving, from the NSSF, a seventh response message including information indicating a third target AMF set and at least one of a public key of the third target AMF set or a token related to the third target AMF set;

generating a third security context container including a eighth security context for a third target AMF based on the seventh security context;

encrypting the third security context container using the public key; and

transmitting the encrypted third security context container and at least one of additional information related to encryption of the third security context container and the token to the third target AMF through a third radio access network related to the third UE.

8 . The method of claim 7 , wherein the token includes, as information verifiable by the third target AMF, at least one of:

an issuer item for identifying the NSSF;

a subject item for identifying an initial AMF or an AMF set where the initial AMF belongs;

an audience item for identifying the third target AMF or the third target AMF set where the third target AMF belongs;

a service name item indicating that the token is for AMF reallocation;

a time information item indicating a time when the token is valid; or

at least one of an electronic signature and/or a message authentication code (MAC) generated for at least one of the items.

9 . The method of claim 1 , further comprising:

receiving a fourth registration request message from a fourth UE;

obtaining a ninth security context for the fourth UE from a fourth previous AMF;

transmitting, to the NSSF, a ninth request message for network slice selection;

receiving, from the NSSF, a ninth response message including a target AMF set ID;

transmitting the target AMF set ID to a fourth radio access network related to the fourth UE;

receiving a target AMF ID for identifying a fourth target AMF from the fourth radio access network;

transmitting, to the NSSF, the target AMF ID, a seventh parameter requesting a public key of the target AMF, and a ninth parameter requesting a token related to the fourth target AMF;

receiving a public key of the fourth target AMF and the token from the NSSF;

generating a fourth security context container including a tenth security context for the fourth target AMF based on the ninth security context;

encrypting the fourth security context container using the public key; and

transmitting the encrypted fourth security context container and at least one of additional information related to encryption of the fourth security context container and the token to the fourth target AMF through the fourth radio access network related to the fourth UE.

10 . The method of claim 9 , wherein the token includes, as information verifiable by the fourth target AMF, at least one of:

an issuer item for identifying the NSSF;

a subject item for identifying an initial AMF or an AMF set where the initial AMF belongs;

an audience item for identifying the fourth target AMF or a fourth target AMF set where the fourth target AMF belongs;

a service name item indicating that the token is for AMF reallocation;

a time information item indicating a time when the token is valid; or

at least one of an electronic signature and/or a message authentication code (MAC) generated for at least one of the items.

11 . An access and mobility management function (AMF) entity for performing AMF reallocation in a communication system, the AMF entity comprising:

a transceiver configured to communicate with another network entity; and

a controller operatively coupled with the transceiver, wherein the controller is configured to:

receive a registration request message from a user equipment (UE),

obtain a first security context for the UE from a previous AMF,

transmit, to a network slice selection function (NSSF), a first request message including at least one of a first parameter requesting a public key of an AMF to be reallocated or a second parameter requesting a token related to the AMF to be reallocated,

receive, from the NSSF, a first response message including information indicating a target AMF set and at least one of a public key of the target AMF set or the token,

generate a security context container including a second security context for a target AMF based on the first security context,

encrypt the security context container using the public key,

transmit the encrypted security context container and at least one of additional information related to encryption of the security context container and the token to the target AMF through a radio access network related to the UE,

receive a first registration request message from a first UE,

obtain a third security context for the first UE from a first previous AMF,

transmit, to the NSSF, a third request message including a third parameter requesting a public key of an AMF to be reallocated,

receive, from the NSSF, a third response message including information indicating a first target AMF set,

transmit, to a network repository function (NRF), a fourth request message including a fourth parameter requesting a token related to the AMF to be reallocated,

receive, from the NRF, a fourth response message including a token related to the first target AMF set,

generate a first security context container including a fourth security context for a first target AMF based on the third security context,

encrypt the first security context container using the public key, and

transmit the encrypted first security context container and at least one of additional information related to encryption of the first security context container and the token to the first target AMF through a first radio access network related to the first UE.

12 . The AMF entity of claim 11 , wherein the controller is further configured to:

receive a second registration request message from a second UE,

obtain a fifth security context for the second UE from a second previous AMF,

transmit, to the NSSF, a fifth request message for network slice selection,

receive, from the NSSF, a fifth response message including information indicating a second target AMF set,

transmit, to the NRF, a sixth request message including at least one of a fifth parameter requesting a public key of the second target AMF set or a sixth parameter requesting a token related to the second target AMF set,

receive, from the NRF, a sixth response message including at least one of the public key of the second target AMF set or the token,

generate a second security context container including a sixth security context for a second target AMF based on the fifth security context,

encrypt the second security context container using the public key, and

transmit the encrypted second security context container and at least one of additional information related to encryption of the second security context container and the token to the second target AMF through a second radio access network related to the second UE.

13 . The AMF entity of claim 11 , wherein the controller is further configured to:

receive a third registration request message from a third UE,

obtain a seventh security context for the third UE from a third previous AMF,

transmit, to the NSSF, a seventh request message for network slice selection,

receive, from the NSSF, a seventh response message including information indicating a third target AMF set and at least one of a public key of the third target AMF set or a token related to the third target AMF set,

generate a third security context container including a eighth security context for a third target AMF based on the seventh security context,

encrypt the third security context container using the public key, and

transmit the encrypted third security context container and at least one of additional information related to encryption of the third security context container and the token to the third target AMF through a third radio access network related to the third UE.

14 . The AMF entity of claim 11 , wherein the controller is further configured to:

receive a fourth registration request message from a fourth UE,

obtain a ninth security context for the fourth UE from a fourth previous AMF,

transmit, to the NSSF, a ninth request message for network slice selection,

receive, from the NSSF, a ninth response message including a target AMF set ID,

transmit the target AMF set ID to a fourth radio access network related to the fourth UE,

receive a target AMF ID for identifying a fourth target AMF from the fourth radio access network,

transmit, to the NSSF, the target AMF ID, a seventh parameter requesting a public key of the target AMF, and a ninth parameter requesting a token related to the fourth target AMF,

receive a public key of the fourth target AMF and the token from the NSSF,

generate a fourth security context container including a tenth security context for the fourth target AMF based on the ninth security context,

encrypt the fourth security context container using the public key, and

transmit the encrypted fourth security context container and at least one of additional information related to encryption of the fourth security context container and the token to the fourth target AMF through the fourth radio access network related to the fourth UE.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 25, 2023
From: LIM, TAEHYUNG; SON, JUNGJE; LEE, DUCKEY
To: SAMSUNG ELECTRONICS CO., LTD
Reel/Frame 065341/0497 →
Priority Claims (3)
KR 10-2021-0054552 · Apr 27, 2021 · national
KR 10-2021-0063470 · May 17, 2021 · national
KR 10-2021-0082125 · Jun 24, 2021 · national
Continuity (1)
Related Publication 20240214902A1 · Jun 27, 2024
References Cited (16)
US 11277791B2 · Thorat · 2022 [cited by examiner]
US 20180227871A1 · Singh et al. · 2018 [cited by applicant]
US 20180317163A1 · Lee · 2018 [cited by examiner]
US 20200154350A1 · Dao et al. · 2020 [cited by applicant]
US 20210136602A1 · Pokkunuri · 2021 [cited by examiner]
US 20220248316A1 · Castellanos Zamora · 2022 [cited by examiner]
US 20240121610A1 · Rajadurai · 2024 [cited by examiner]
WO 2020254359A1 · 2020 [cited by applicant]
WO 2021032610A1 · 2021 [cited by applicant]
Supplementary European Search Report dated Jan. 4, 2024, in connection with European Patent Application No. 22796048.1, 17 pages. [cited by applicant]
Samsung, “Update to Solution #10,” 3GPP TSG-SA3 Meeting #104-e, e-meeting, Aug. 2021, S3-212926, 4 pages. [cited by applicant]
Ericsson, “AMF re-allocation: New solution with reroute of Registration Request and protected security context via RAN,” 3GPP TSG-SA3 Meeting #102Bis-e, e-meeting, S3-211093, 6 pages. [cited by applicant]
International Search Report and Written Opinion of the International Searching Authority dated Jul. 28, 2022, in connection with International Application No. PCT/KR2022/005763, 10 pages. [cited by applicant]
Lenovo et al., “NSAC in case of mobility with AMF change,” S2-2103469, 3GPP TSG-WG SA2 Meeting #144E (e-meeting), Elbonia, Apr. 2021, 18 pages. [cited by applicant]
Samsung et al., “Introduction of Leaving procedure—5GS,” S3-2103033, 3GPP TSG-WG SA2 Meeting #144E (e-meeting), Elbonia, Apr. 2021, 38 pages. [cited by applicant]
Samsung, “Use of TAI(s) for slice restriction based on analytics,” S2-2103257, SA WG2 Meeting #144E e-meeting, Elbonia, Apr. 2021, 6 pages. [cited by applicant]