School of Specs 24.501v20.0.0

3GPP 24.501 v20.0.0 — the document's own text

6.3.1.1 General

Taught in 6. Getting on the network, and getting a connection through it (CT1 — the group that writes what your phone says, in depth), 4. Inside TS 24.501, the document at the centre (CT1 — the group that writes what your phone says, overview).

The purpose of the PDU session authentication and authorization procedure is to enable the DN:

  • to authenticate the upper layers of the UE, when establishing the PDU session;
  • to authorize the upper layers of the UE, when establishing the PDU session;
  • both of the above; or
  • to re-authenticate the upper layers of the UE after establishment of the PDU session.

The PDU session authentication and authorization procedure can be performed only during or after the UE-requested PDU session procedure establishing a non-emergency PDU session. The PDU session authentication and authorization procedure shall not be performed during or after the UE-requested PDU session establishment procedure establishing an emergency PDU session.

The upper layers store the association between a DNN and corresponding credentials, if any, for the PDU session authentication and authorization.

If the UE is registered for onboarding services in SNPN the SMF may initiate the PDU session authentication and authorization procedure based on local policy with a DCS as specified in 3GPP TS 33.501 [24] clause I.9.2.4.1 or a DNAAA server as specified in 3GPP TS 33.501 [24] clause I.9.2.4.2.

If the UE is registered for onboarding services in SNPN and the network initiates the PDU session authentication and authorization procedure, the UE shall use the default UE credentials for secondary authentication for the PDU session authentication and authorization procedure.

The network authenticates the UE using the Extensible Authentication Protocol (EAP) as specified in IETF RFC 3748 [34].

EAP has defined four types of EAP messages:

  • an EAP-request message;
  • an EAP-response message;
  • an EAP-success message; and
  • an EAP-failure message.

The EAP-request message is transported from the network to the UE using the PDU SESSION AUTHENTICATION COMMAND message of the PDU EAP message reliable transport procedure.

The EAP-response message to the EAP-request message is transported from the UE to the network using the PDU SESSION AUTHENTICATION COMPLETE message of the PDU EAP message reliable transport procedure.

If the PDU session authentication and authorization procedure is performed during the UE-requested PDU session establishment procedure:

  • and the DN authentication of the UE completes successfully, the EAP-success message is transported from the network to the UE as part of the UE-requested PDU session establishment procedure in the PDU SESSION ESTABLISHMENT ACCEPT message.
  • and the DN authentication of the UE completes unsuccessfully, the EAP-failure message is transported from the network to the UE as part of the UE-requested PDU session establishment procedure in the PDU SESSION ESTABLISHMENT REJECT message.

If the PDU session authentication and authorization procedure is performed after the UE-requested PDU session establishment procedure:

  • and the DN authentication of the UE completes successfully, the EAP-success message is transported from the network to the UE using the PDU SESSION AUTHENTICATION RESULT message of the PDU EAP result message transport procedure.
  • and the DN authentication of the UE completes unsuccessfully, the EAP-failure message is transported from the network to the UE using the PDU SESSION RELEASE COMMAND message of the network-requested PDU session release procedure.

There can be several rounds of exchange of an EAP-request message and a related EAP-response message for the DN to complete the authentication and authorization of the request for a PDU session (see example in figure 6.3.1.1).

The SMF shall set the authenticator retransmission timer specified in IETF RFC 3748 [34] clause 4.3 to infinite value.

NOTE: The PDU session authentication and authorization procedure provides a reliable transport of EAP messages and therefore retransmissions at the EAP layer of the SMF do not occur.

Figure 6.3.1.1: PDU session authentication and authorization procedure
Figure 6.3.1.1: PDU session authentication and authorization procedure