School of Specs 24.501v20.0.0

3GPP 24.501 v20.0.0 — the document's own text

5.4.7.1 General

Taught in 4. Inside TS 24.501, the document at the centre (CT1 — the group that writes what your phone says, overview).

The purpose of the network slice-specific authentication and authorization procedure is to enable the authentication, authorization and accounting server (AAA-S) via the Network Slice Specific and SNPN Authentication and Authorization Function (NSSAAF) to (re-)authenticate or (re-)authorize the upper layers of the UE.

The network slice-specific authentication and authorization procedure can be invoked for a UE supporting network slice-specific authentication and authorization procedure and for a HPLMN S-NSSAI or an SNPN S-NSSAI (see clauses 5.15.10 and 5.30.2.9 in 3GPP TS 23.501 [8] and clause 4.2.9.2 of 3GPP TS 23.502 [9]).

The network (re-)authenticates the UE using the EAP as specified in IETF RFC 3748 [34].

EAP has defined four types of EAP messages:

  • an EAP-request message;
  • an EAP-response message;
  • an EAP-success message; and
  • an EAP-failure message.

The EAP-request message is transported from the network to the UE using the NETWORK SLICE-SPECIFIC AUTHENTICATION COMMAND message of the network slice-specific EAP message reliable transport procedure.

The EAP-response message to the EAP-request message is transported from the UE to the network using the NETWORK SLICE-SPECIFIC AUTHENTICATION COMPLETE message of the network slice-specific EAP message reliable transport procedure.

If the (re-)authentication of the UE completes successfully or unsuccessfully, the EAP-success message or the EAP-failure message, respectively, is transported from the network to the UE using the NETWORK SLICE-SPECIFIC AUTHENTICATION RESULT message of the network slice-specific result message transport procedure.

There can be several rounds of exchange of an EAP-request message and a related EAP-response message for the AAA-S via the NSSAAF to complete the (re-)authentication and (re-)authorization of the request for an S-NSSAI (see example in figure 5.4.7.1.1).

The AMF shall set the authenticator retransmission timer specified in clause 4.3 of IETF RFC 3748 [34] to infinite value.

NOTE: The network slice-specific authentication and authorization procedure provides a reliable transport of EAP messages and therefore retransmissions at the EAP layer of the AMF do not occur.

Figure 5.4.7.1.1: Network slice-specific authentication and authorization procedure
Figure 5.4.7.1.1: Network slice-specific authentication and authorization procedure