School of Specs 24.501v20.0.0

3GPP 24.501 v20.0.0 — the document's own text

5.4.2.1 General

Taught in 6. Getting on the network, and getting a connection through it (CT1 — the group that writes what your phone says, in depth), 10. Who CT1 writes to, and what the letters count (CT1 — the group that writes what your phone says, in depth), 12. The neighbours — and how little the record says about them (CT1 — the group that writes what your phone says, in depth), 4. Inside TS 24.501, the document at the centre (CT1 — the group that writes what your phone says, overview).

The purpose of the NAS security mode control procedure is to take a 5G NAS security context into use, and initialise and start NAS signalling security between the UE and the AMF with the corresponding 5G NAS keys and 5G NAS security algorithms.

Furthermore, the network may also initiate the security mode control procedure in the following cases:

  • - in order to change the 5G NAS security algorithms for a current 5G NAS security context already in use;
  • in order to change the value of uplink NAS COUNT used in the latest SECURITY MODE COMPLETE message as described in 3GPP TS 33.501 [24], clause 6.9.4.4; and
  • in order to provide the Selected EPS NAS security algorithms to the UE.

For restrictions concerning the concurrent running of a security mode control procedure with other security related procedures in the AS or inside the core network see 3GPP TS 33.501 [24], clause 6.9.5.

If the security mode control procedure is initiated after successful 5G AKA based primary authentication and key agreement procedure and the security mode control procedure intends to bring into use the partial native 5G NAS security context created by the 5G AKA based primary authentication and key agreement procedure and the UE accepts received security mode command (see clause 5.4.2.3), the ME shall:

  • delete the valid KAUSF and the valid KSEAF, if any; and
  • consider the new KAUSF to be the valid KAUSF, and the new KSEAF to be the valid KSEAF, reset the SOR counter and the UE parameter update counter to zero, and store the valid KAUSF, the valid KSEAF, the SOR counter and the UE parameter update counter as specified in annex C and use the valid KAUSF in the verification of SOR transparent container and UE parameters update transparent container, if any are received.

NOTE: The AMF does not perform a security mode control procedure when the 5G AKA based primary authentication procedure successfully authenticates a 5G ProSe layer-3 remote UE accessing the network via a 5G ProSe layer-3 UE-to-network relay UE served by the AMF.