3GPP 23.501 v20.2.0 — the document's own text
5.17.2.5 Secondary DN authentication and authorization in EPS Interworking case
Taught in 19. Living next to 4G (The 5G system architecture, in depth), 7. Roaming, other accesses, the edge and the outside (The 5G system architecture, overview).
Secondary authentication/authorization by a DN-AAA server during the establishment of a PDN connection over 3GPP access to EPC, is supported based on following principles:
- It is optional for the UE to support EAP-based secondary authentication and authorization by DN-AAA over EPC,
- A SMF+PGW-C shall be used to serve DNN(s) requiring secondary authentication/authorization by a DN-AAA server,
- For secondary authentication/authorization by a DN-AAA server, the SMF+PGW-C runs the same procedures with PCF, UDM and DN-AAA and uses the same corresponding interfaces regardless of whether the UE is served by EPS or 5GS,
- The interface towards the UE is different (usage of NAS for EPS instead of NAS for 5GS) between the EPS and 5GS cases.
This is further specified in Annex H of TS 23.502 [3].
In this Release, EAP based Secondary authentication by a DN-AAA server during the establishment of a PDN connection over non-3GPP access to EPC is not supported.