A vendor-specific EAP method (EAP-5G) is used to encapsulate NAS messages between the 5G-RG and the W-AGF serving the 5G-RG. The EAP-5G packets utilize the "Expanded" EAP type and the existing 3GPP Vendor-Id registered with IANA under the SMI Private Enterprise Code registry (i.e. 10415). The EAP-5G method is utilized only for encapsulating the NAS messages. The EAP-5G method is not utilized to authenticate the 5G-RG in wireline access network.
The 5G-RG and the W-AGF serving the 5G-RG shall exchange EAP-5G messages via W-CP EAP connection. The W-AGF on reception of a W-CP EAP connection establishment shall start an EAP-5G session by sending an EAP-Request/5G-Start message.
The 5G-RG acknowledges start of the EAP-5G session by sending an EAP-Response/5G-NAS message which shall include:
a NAS-PDU field containing a NAS message, for example, a REGISTRATION REQUEST message; and
an AN-parameters field containing access network parameters, such as GUAMI, selected PLMN ID, requested NSSAI and establishment cause (see TS 23.502).
The W-AGF, on reception of NAS messages from the 5G-RG within an EAP-Response/5G-NAS message, shall forward the NAS message to the AMF.
The W-AGF, on reception of NAS messages from the AMF, shall include the NAS message within an EAP-Request/5G-NAS message. The W-AGF shall transmit the EAP-Request/5G-NAS message to the 5G-RG.
The EAP-Request/5G-NAS message shall include a NAS-PDU field that contains a NAS message.
Further NAS messages between the 5G-RG and the AMF, via the W-AGF, shall be inserted in NAS-PDU field of an EAP-Response/5G-NAS (5G-RG to W-AGF direction) and EAP-Request/5G-NAS (W-AGF to 5G-RG direction) message.
Upon completion of successful authentication and on reception of the W-AGF key from the AMF, the W-AGF serving the 5G-RG shall complete the EAP-5G session by sending an EAP-Success message.
On reception of the EAP-Success message from the W-AGF, the 5G-RG proceeds as specified in subclause 8.2.1.
An example of an EAP-5G session after successful authentication is shown in figure 7A.3-1.
Upon receiving indication from the upper layer that no 5G-NAS messages need to be transmitted between the 5G-RG and W-AGF, the 5G-RG shall terminate the EAP-5G session by sending an EAP-Response/5G-Stop message to the W-AGF.
On reception of EAP-Response/5G-Stop message, the W-AGF shall complete the EAP-5G session by sending an EAP-Failure message to the 5G-RG.