School of Specs 24.501v20.0.0

3GPP 24.501 v20.0.0 — the document's own text

6.3.1A.1 General

Taught in 4. Inside TS 24.501, the document at the centre (CT1 — the group that writes what your phone says, overview).

The purpose of the service-level authentication and authorization (service-level-AA) procedure is to enable the DN using NEF services for authentication:

  • to authenticate the upper layers of the UE, when establishing the PDU session;
  • to authorize the upper layers of the UE, when establishing the PDU session;
  • both of the above; or
  • to re-authenticate the upper layers of the UE after establishment of the PDU session.

The service-level authentication and authorization procedure is used for UUAA as specified in 3GPP TS 23.256 [6AB].

NOTE 1: The authentication protocol for UUAA is out of scope of 3GPP in this release of specification.

The service-level authentication and authorization procedure can be performed only during or after the UE-requested PDU session procedure establishing a non-emergency PDU session. The service-level authentication and authorization procedure shall not be performed during or after the UE-requested PDU session establishment procedure establishing an emergency PDU session.

If the service-level authentication and authorization procedure is performed during the UE-requested PDU session establishment procedure:

  • and the service-level-AA procedure of the UE completes successfully, the service-level-AA response is transported from the network to the UE as a part of the UE-requested PDU session establishment procedure in the PDU SESSION ESTABLISHMENT ACCEPT message; or
  • and the service-level-AA procedure of the UE completes unsuccessfully, the service-level-AA response is transported from the network to the UE as a part of the UE-requested PDU session establishment procedure in the PDU SESSION ESTABLISHMENT REJECT message.

NOTE 2: If the SMF receives the HTTP code set to "4xx" or "5xx" as specified in 3GPP TS 29.500 [20AA] or the SMF detects a UUAA-SM failure as specified in 3GPP TS 29.256 [21B], then the SMF considers that the UUAA-SM procedure has completed unsuccessfully.

If the service-level authentication and authorization procedure is performed for the established PDU session with re-authentication purpose:

  • and the service-level-AA procedure of the UE completes successfully, the service-level-AA response is transported from the network to the UE as a part of the network-requested PDU session modification procedure in the PDU SESSION MODIFICATION COMMAND message; or
  • and the service-level-AA procedure of the UE completes unsuccessfully, the service-level-AA response is transported from the network to the UE as a part of the network-requested PDU session release procedure in the PDU SESSION RELEASE COMMAND message.

There can be several rounds of exchange of a service-level-AA payload for the service to complete the service-level authentication and authorization of the request for a PDU session (see example in figure 6.3.1A.1-1).

If the UE receives the service-level-AA response in the PDU SESSION ESTABLISHMENT ACCEPT message or the PDU SESSION ESTABLISHMENT REJECT message, the UE passes it to the upper layer.

Figure 6.3.1A.1-1: Service-level authentication and authorization procedure
Figure 6.3.1A.1-1: Service-level authentication and authorization procedure