Implementing transmission isolation of network slices using slice-aware authentication data

CN122122950APending Publication Date: 2026-05-29ALCATEL LUCENT SHANGHAI BELL CO LTD +1

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ALCATEL LUCENT SHANGHAI BELL CO LTD
Filing Date
2023-08-29
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

In existing technologies, network slice isolation is not effectively designed, which means that when one slice has a problem, it affects the tunnels of all other slices, violating the principle of slice isolation and causing a waste of network bandwidth.

Method used

By generating slice-specific or slice-group-specific FQDNs in the SAN field extension of the endpoint entity certificate and using these identities in the identifier payload of IKE messages, the uniqueness of each tunnel is ensured, thereby enabling data to be sent on slice-specific connections.

Benefits of technology

It achieves secure isolation of network slices, avoiding the impact of one slice failure on other slice tunnels and preventing network bandwidth waste.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122122950A_ABST
    Figure CN122122950A_ABST
Patent Text Reader

Abstract

An apparatus comprising at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus at least to determine at least one slice-specific identifier; create a slice-specific connection with a network node using a certificate associated with the at least one slice-specific identifier; and send data on the slice-specific connection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The exemplary and non-limiting example embodiments generally relate to communications, and more specifically to implementing transport isolation of network slices using slice-aware authentication data. Background Technology

[0002] It is known to create logical or physical partitions for applications in a communication network. Summary of the Invention

[0003] According to one aspect, an apparatus includes: at least one processor; and at least one memory storing instructions that, when executed by the at least one processor, cause the apparatus to at least: determine at least one slice-specific identifier; create a slice-specific connection with a network node using a certificate associated with the at least one slice-specific identifier; and transmit data over the slice-specific connection.

[0004] According to one aspect, an apparatus includes: at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: receive an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; determine a network slice based on the first slice-specific identifier within the IPS connection request; and determine whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0005] According to one aspect, an apparatus includes: at least one processor; and at least one memory storing instructions, which, when executed by the at least one processor, cause the apparatus to at least: determine a network slice; determine a first slice-specific identifier corresponding to the network slice; send an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and send data on a slice-specific connection associated with the network slice.

[0006] According to one aspect, a method includes: determining at least one slice-specific identifier; using a certificate associated with the at least one slice-specific identifier to create a slice-specific connection with a network node; and sending data over the slice-specific connection.

[0007] According to one aspect, a method includes: receiving an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; determining a network slice based on the first slice-specific identifier within the IPS connection request; and determining whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0008] According to one aspect, a method includes: determining a network slice; determining a first slice-specific identifier corresponding to the network slice; sending an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and sending data on a slice-specific connection associated with the network slice.

[0009] According to one aspect, an apparatus includes: components for determining at least one slice-specific identifier; components for creating a slice-specific connection with a network node using a certificate associated with the at least one slice-specific identifier; and components for transmitting data on the slice-specific connection.

[0010] According to one aspect, an apparatus includes: components for receiving an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; components for determining a network slice based on the first slice-specific identifier within the IPS connection request; and components for determining whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0011] According to one aspect, an apparatus includes: components for determining a network slice; components for determining a first slice-specific identifier corresponding to the network slice; components for sending an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and components for sending data on a slice-specific connection associated with the network slice.

[0012] According to one aspect, a non-transient program storage device is provided and described, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program that is machine-executable for performing operations including: determining at least one slice-specific identifier; using a certificate associated with the at least one slice-specific identifier to create a slice-specific connection with a network node; and transmitting data on the slice-specific connection.

[0013] According to one aspect, a non-transient program storage device is provided and described, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program that is machine-executable for performing operations including: receiving an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; determining a network slice based on the first slice-specific identifier within the IPS connection request; and determining whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0014] According to one aspect, a non-transient program storage device is provided and described, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program that is machine-executable for performing operations including: determining a network slice; determining a first slice-specific identifier corresponding to the network slice; sending an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and sending data on a slice-specific connection associated with the network slice. Attached Figure Description

[0015] The foregoing aspects and other features are explained in the following description taken in conjunction with the accompanying drawings.

[0016] Figure 1 This demonstrates certificate-based authentication in IPsec that utilizes the identifier payload.

[0017] Figure 2A This illustrates the first step in restarting a service using a slice tunnel that affects other slices by utilizing an ICN payload with a public identity.

[0018] Figure 2B This illustrates the second step of a service restart that affects other slices by utilizing ICN payloads with public identities to restart a slice tunnel.

[0019] Figure 2C This illustrates the third step in restarting a service using a slice tunnel that affects other slices by utilizing ICN payloads with public identities.

[0020] Figure 2D This illustrates the fourth step of a service restart of a slice tunnel that affects other slices by utilizing ICN payloads with public identities.

[0021] Figure 3Table 1 shows different examples of the options described in this article.

[0022] Figure 4 This demonstrates that by sending a CMP initialization request to the CMP / CA server, a slice-specific FQDN can be included in the SAN field extension created by the endpoint entity certificate.

[0023] Figure 5 Table 2 shows the different values ​​of the identity used in Figure 6 at gNB / eNB, SecGW, and adjacent gNB / eNB.

[0024] Figure 6A This demonstrates the first step in restarting a slice tunnel service without affecting other slices using a uniquely identified ICN payload.

[0025] Figure 6B This demonstrates the second step of service restarting a slice tunnel without affecting the use of a uniquely identified ICN payload by other slices.

[0026] Figure 6C The third step of service restart for a slice tunnel is shown without affecting the use of a uniquely identified ICN payload by other slices.

[0027] Figure 6D The fourth step of service restart for a slice tunnel is shown without affecting the use of a uniquely identified ICN payload by other slices.

[0028] Figure 7 This is a block diagram of one possible, non-limiting system in which exemplary embodiments can be practiced.

[0029] Figure 8 It is an example device configured to implement the examples described herein.

[0030] Figure 9 A schematic diagram is shown of an example of a non-volatile memory medium used to store instructions implementing the examples described herein.

[0031] Figure 10 This is an example method based on the examples described in this article.

[0032] Figure 11 This is an example method based on the examples described in this article.

[0033] Figure 12 This is an example method based on the examples described in this article. Detailed Implementation

[0034] Network slicing is a feature and business driver of 5G, enabling enterprises and operators to address the specific requirements of different market segments. As new factors such as business models, interfaces, and signaling flows are introduced, the threat surface increases with network slicing, especially when network slice isolation is not well designed and effectively implemented.

[0035] Isolation is the principle and security requirement of network slicing. Network slices can be completely or partially, logically and / or physically isolated from one or more other network slices(s). Different types of isolation can be implemented in network slicing; for example, network slices can be physically separated by being implemented in different racks, different locations, or different hardware, and / or logically separated in the case of virtualized cloud infrastructure via VM isolation or cluster isolation.

[0036] As described in RFC 7296, Section 3.5, the uniqueness of an IPsec tunnel (in this case, a tunnel carrying slice-specific information) can be supported via IP address or FQDN. However, generating and providing these identities within the End Entity certificate, as well as the indications of these identities used in IPsec via identifying the payload, may not be scalable or efficient for runtime slice creation and the isolation of these identities from other slices.

[0037] Figure 1 It provides an introduction to certificate-based authentication in IPsec, where the identifier payload carrying FQDN information is used as authentication data in the endpoint entity certificate.

[0038] Figure 1 This illustrates certificate-based authentication in IPsec that utilizes the identifier payload. Specifically, Figure 1The signaling exchange between gNB 70 or eNB 70 and security gateway 80 or peer eNB 70-2 or gNB 70-2 is illustrated. At 110, gNB 70 or eNB 70 sends an IKE_INIT_SA request to security gateway 80 or peer eNB 70-2 or gNB 70-2. At 120, security gateway 80 or peer eNB 70-2 or gNB 70-2 sends an IKE_INIT_SA response to gNB 70 or eNB 70. At 130, gNB 70 or eNB 70 sends an IKE_AUTH request to security gateway 80 or peer eNB 70-2 or gNB 70-2, the IKE_AUTH request including an IDi for gNB.operator.com and a certificate with the subject name gNB.operator.com. At point 140, the security gateway 80 or its peer eNB 70-2 or gNB 70-2 verifies that the IKE ID (IDi) is part of the certificate. At point 150, the security gateway 80 or its peer eNB 70-2 or gNB 70-2 sends an IKE_AUTH response to the gNB 70 or eNB 70, which includes, for example, an IDr for SGW.operator.com and a certificate with a subject name such as SGW.operator.com. At point 160, the gNB 70 or eNB 70 verifies that the IKE ID (IDr) is part of the certificate.

[0039] Using the same certificate identity in the terminal entity certificate and the identifier payload of the IKE profile caused an impact on the tunnels (which support different slices), although they were intact due to a failure in one of the tunnels hosted in the network element (which supports lower priority slice data) and recovered from the problem.

[0040] The example described herein implements network slice isolation using slice-aware authentication data in the endpoint entity certificate and indications via slice-aware authentication data identified by the payload used in IPsec. This ensures that, due to the presence of the INITIAL_CONTACT notification (ICN) payload, one IPsec tunnel recovering from a failure (carrying lower-priority slice data) will not affect other high-priority IPsec tunnels (which remain intact and carry the most important slice data), as their use is intended to avoid wasting network bandwidth by peers, as described in Section 2.4 of RFC 7296.

[0041] According to RFC 7296 Section 2.4, it is crucial to detect endpoint failures using the presence of the INITIAL_CONTACT notification (ICN) payload whenever an endpoint recovers and reappears, thereby avoiding wasted network bandwidth. However, while there are issues even within a single IPsec tunnel, the use of common identifier types between endpoints can even disrupt what would otherwise be a complete and stable tunnel. Figure 2A , Figure 2B , Figure 2C and Figure 2D It provides further insights into the technical problems to be solved. Specifically, Figure 2A , Figure 2B , Figure 2C and Figure 2D This illustrates a service restart of a slice tunnel that affects the use of ICN payloads with public identities by other slices.

[0042] In step 1 ( Figure 2A In this configuration, different tunnels (202, 204, 206) are established between gNB / eNB 70 and SecGW 80 for different slices, and different tunnels (212, 214, 216) are established between gNB / eNB 70 and adjacent gNB / eNBs supporting MORAN use cases (including adjacent gNB / eNB70-2). Here, a single gNB identifier (220, 222) is used, such as gNB.operator.com for gNB identifier 220 or gNBx.operator.com for gNB identifier 222. Furthermore, a single identifier (221) is used for security gateway 80, namely SGW.operator.com for security gateway identifier 221.

[0043] In step 2 ( Figure 2B In the case of a problem in slice 20 of operator 1—eMBB tunnel 206 or 5G user plane (UP) / control plane (CP) tunnel 214, the tunnel (206, 214) is disconnected and attempts to start up, and at the same time gNB / eNB70 is unaware of the fault condition in the peer (SecGW 80 and adjacent gNB / eNB 70-2).

[0044] In step 3 ( Figure 2CIn the context of the peer (which means slice 20 of operator 1 – eMBB tunnel 206 or 5GUP / CP tunnel 214), whenever the peer reinitializes its state and establishes a new tunnel (230, 232) with an ICN payload (240, 242), the gNB / eNB 70 deletes the outdated tunnel (206, 214) due to the presence of the ICN payload (240, 242) to avoid wasting network bandwidth because existing services are still being sent on the outdated tunnel (206, 214).

[0045] In step 4 ( Figure 2D In the gNB / eNB70, all active tunnels (202, 204) created from different slices and from the MORAN use case perspective (212, 216) are removed – this is due to the use of common identity types between IPsec tunnel endpoints.

[0046] The technical problem to be solved here is that whenever a tunnel has a problem, restoring that tunnel using ICN should not affect all other active tunnels due to the public identity usage of the gNB / eNB terminal entity certificate within the identifier payload of the IKE message.

[0047] In other words, a problem with slice 1 affects all other slice tunnels. This violates the principle of slice isolation.

[0048] Therefore, slice isolation is implemented using slice-aware authentication data, which should be generated and exist in the SAN field extension of the endpoint entity certificate and used in the identifier payload of the IKE message.

[0049] The following options / methods solve this problem: Method 1: Slice-specific certificate-based solution.

[0050] Method 2: Slice-specific information in the EP_Transport endpoint definition of 3GPP TS 28.541 Method 1a: Single certificate per slice. This solution ensures that each slice obtains its own FQDN and its own endpoint entity certificate. Security at the slice level is negotiated independently. Advantages and disadvantages: A clean but cumbersome and expensive solution because each node needs to support multiple endpoint entity certificates.

[0051] Method 1b: Add a single certificate for all slices but with different FQDNs in the SAN field extension. This requires updating the certificate profile defined in TS33.310, which adds multiple slice-specific FQDNs in the SAN field extension of the endpoint entity certificate. Advantages and disadvantages: A single-certificate solution; however, whenever a new slice is added, a new slice-specific FQDN is generated and an endpoint entity certificate is obtained accordingly. This solution is feasible because adding new slices is not a very frequent activity.

[0052] Method 2: The EP transport endpoint definition can include slice-specific information, which can be used to generate terminal entity certificates in the SAN field extension and IKE profile identification payload, making it easy to support transport isolation of slices.

[0053] Secure isolation of network slices can be achieved using the same usage in the slice-aware authentication data in the endpoint entity certificate and the identity payload of the IKE message between public endpoints. The problem described in Section 5 can be addressed by generating the identity type to be used in the SAN field extension of the endpoint entity certificate using any of the options mentioned in Section 6. Figure 3 Table 1 shows example details of all the proposed options (i.e., different examples of the proposed options are shown).

[0054] Perform the following operations for the options / methods mentioned in this article to generate a slice-specific or slice-group-specific FQDN in the terminal entity certificate and use it from the perspective of the IKE protocol.

[0055] Method 1: Step 1: Using the PLMN ID, SNSSAI information, and FQDN, generate a unique slice-specific FQDN and send it as part of the CMP Initialization Request message to the CMP / CA server to include it in the Certificate Extension - SAN Field Extension of the End Entity Certificate.

[0056] Step 2: The IKE profile can be configured with one of the specific identities generated in Step 1, which can be used for, for example... Figure 1 The IKE AUTH message (130, 150) shown here identifies the payload to ensure the transmission isolation of network slices.

[0057] Method 2: Step 1: An existing unique identifier or a new unique identifier that can be added to the EP transport definition can be used to generate a slice-specific FQDN and can be used in the CMP initialization request message of the CMP / CA server to include the SAN field extension of the terminal entity certificate in the Entity extension-SAN field extension.

[0058] Step 2: As Figure 1 As shown, the same unique identifier generated in step 1 can be used in the identifier payload of the IKE AUTH message (130, 150) to ensure the transmission isolation of network slices.

[0059] like Figure 4 As shown, slice-specific FQDN 412 (xyz.11.nokia.com, abc.21.nokia.com) can be included in the SAN field extension 410 created by the terminal entity certificate 408 by sending a CMP initialization request 404 to the CMP / CA server 402.

[0060] The CMP initialization 404 request contains the slice-specific FQDN in the SAN extended fields, and the FA device certificate 406 is sent as a proof of ownership (POP). The OP device certificate 414 is the operator device certificate with all slice-specific FQDN details in the SAN extended fields (410, 412). The CA root certificate 416 is shown, and other root CAs (CA1 and CA2) may also exist.

[0061] Table 2 ( Figure 5 (As shown in the figure) Different values ​​of the identity used in Figure 6 are shown at gNB / eNB 70, SecGW 80 and adjacent gNB / eNB 70-2.

[0062] Figure 6 shows about Figure 2A , Figure 2B , Figure 2C and Figure 2D The technical issues discussed can be resolved using different identities generated by any of the options mentioned in Table 1 and the examples shown in Table 2. Specifically, Figure 6 illustrates a service restart of a slice tunnel with an ICN payload that has a unique identity that does not affect other slices.

[0063] exist Figure 6A , Figure 6B and Figure 6C In the middle, steps 1, 2 and 3 are related to Figure 2A , Figure 2B and Figure 2C Steps 1, 2, and 3 remain the same. In step 4 ( Figure 6D In the gNB / eNB 70, all active tunnels (202, 204, 212, 216) created from different slices and from the perspective of MORAN use cases are not deleted – this is due to the use of unique identity among IPsec tunnel endpoints (601, 602, 603, 604, 605, 606, 607, 608, 609, 610, 611, 612).

[0064] Therefore, restarting the service of one slice tunnel does not affect any other tunnels, because each tunnel is identified using a unique identity that exists in the SAN field extension 410 of the terminal entity certificate 408, and that unique identity is part of the identification payload of the IKE message (e.g., message 130 or 150).

[0065] In the example embodiment described herein, the receiving node (e.g., SEG 80 or network node 70-2) determines the network slice based on the slice-specific identifier in the identifier payload, since multiple slice-specific identifiers may exist in the certificate's SAN. SEG 80 or gNB 70-2 can then accept the IKE request if it matches the slice-specific identifier in the identifier payload with one of the slice-specific identifiers in the certificate's SAN; otherwise, it rejects it. Specifically, gNB1 70 selects slice 1 and the corresponding slice-specific fqdn1 and establishes a connection with that fqdn1. In this request, gNB1 70 also sends a certificate containing a list of fqdns (fqdn1, fqdn2, ..., fqdnN), where N is the number of fqdns in the list. gNB2 / Node2 (80, 70-2) determines the slice based on fqdn1. When determining whether to accept or reject the request, the gNB2 / Node (80, 70-2) will also match the fqdn received in the request with the certificate.

[0066] 1. The method described herein can be standardized in 3GPP to standardize: a. slice-specific FQDN generation for gNB, and b. the use of multiple slice-specific FQDNs in the SAN field extension of the terminal entity certificate.

[0067] 2. The method described herein may be related to 3GPP TS 28.541 for generating slice-specific certificates that include slices or groups of slices.

[0068] This can be achieved by checking whether slice-specific information is used in the SAN field of the endpoint entity certificate and the identifier payload of the IKE AUTH message in the CMP IR / IP and KUR / KUP messages.

[0069] If restarting any slice-specific tunnel does not affect other IPsec tunnels (carrying different slice information) between the same endpoints using that new identity type, then this means that each tunnel is uniquely identified.

[0070] Figure 7 A block diagram illustrating a possible, non-limiting example of a cellular network 1 connected to a user equipment (UE) 10 is shown. Figure 7The cellular network shows several network elements: base station 70; and core network 90.

[0071] exist Figure 7 In this embodiment, User Equipment (UE) 10 wirelessly communicates with base station 70 of cellular network 1 via radio link 11. UE 10 is a wireless communication device configured to access the cellular network, such as a mobile device. UE 10 is shown having one or more antennas 28. The ellipsis 2 indicates that multiple UEs 10 may exist that wirelessly communicate with base station 70 via radio link. UE 10 includes one or more processors 13, one or more memories 15, and other circuitry 16. The other circuitry 16 includes one or more receivers (Rx) 17 and one or more transmitters (Tx) 18. Procedure 12 is used to cause UE 10 to perform the operations described herein. For UE 10, the other circuitry 16 may include circuitry such as user interface elements (not shown) for a display-like device.

[0072] Base station 70, as a network element of cellular network 1, provides UE 10 with access to cellular network 1 and data network 91 via core network 90 (e.g., via the user plane function (UPF) of core network 90). Base station 70 is shown having one or more antennas 58. Typically, base station 70 is referred to herein as RAN node 70. An example of RAN node 70 is a gNB. However, there are many other examples of RAN nodes that include eNB (LTE base station) or Transmitter Receiver Point (TRP). Base station 70 includes one or more processors 73, one or more memories 75, and other circuitry 76. The other circuitry 76 includes one or more receivers (Rx) 77 and one or more transmitters (Tx) 78. Procedure 72 is used to cause base station 70 to perform the operations described herein.

[0073] It should be noted that base station 70 can alternatively be implemented via other wireless technologies such as Wi-Fi (a wireless network protocol used by devices to communicate without a direct cable connection). In the case of Wi-Fi, link 11 can be characterized as a wireless link.

[0074] Two or more base stations 70 communicate using, for example, (three or more) links 79. The (three or more) links 79 may be wired or wireless or both, and may implement, for example, an Xn interface for fifth generation (5G), an X2 interface for LTE, or other suitable interfaces for other standards.

[0075] Cellular network 1 may include a core network 90, as one or more elements shown in the third example, which may include core network functions and provides connectivity to data network 91 (such as telephone networks and / or data communication networks (e.g., the Internet)) via one or more links 81. Core network 90 includes one or more processors 93, one or more memories 95, and other circuitry 96. The other circuitry 96 includes one or more receivers (Rx) 97 and one or more transmitters (Tx) 98. Program 92 is used to cause core network 90 to perform the operations described herein.

[0076] The core network 90 can be a 5GC (5G core network). The core network 90 can implement or include multiple network functions (NFs) 99, and program 92 can include one or more NFs 99. The 5G core network can use hardware such as memory and processors, as well as a virtualization layer. It can be a single standalone computing system, a distributed computing system, or a cloud computing system. The NFs 99, as network elements of the core network, can be containers or virtual machines running on the hardware of the computing systems(s) constituting the core network 90.

[0077] Core network functions for 5G may include access and mobility management functions provided by network functions such as Access and Mobility Management Functions (AMF)(s) and session management functions provided by network functions such as Session Management Functions (SMF). Core network functions for access and mobility management in LTE networks may be provided by MME (Mobility Management Entity) and / or SGW (Serving Gateway) functions that route data to the data network. Figure 7 As shown in the examples, many other items are possible: AMF; SMF; MME; SGW; Gateway Mobile Location Center (GMLC); Location Management Function (LMF); Unified Data Management (UDM); Unified Data Repository (UDR); Network Repository Function (NRF); and / or Evolved Serving Mobile Location Center (E-SMLC). These are merely exemplary core network functionalities that can be provided by core network 90, and note that both 5G and LTE core network functionalities can be provided by core network 90. ​​Radio Access Network (RAN) node 70 is coupled to core network 90 via backhaul link 31. RAN node 70 and core network 90 may include an NG interface for 5G, or an S1 interface for LTE, or other suitable interfaces for other radio access technologies communicating via backhaul link 31.

[0078] In data network 91, there is a computer-readable medium 94. The computer-readable medium 94 contains instructions that, when downloaded and installed into the memory 15, 75, or 95 of the corresponding UE 10, base station 70, and / or (multiple) core network elements 90 and executed by (multiple) processors 13, 73, or 93, cause the corresponding device to perform the corresponding actions described herein. The computer-readable medium 94 may be implemented in other forms, such as via a compressed disk or memory stick.

[0079] Programs 12, 72, and 92 contain instructions stored by one or more corresponding memories 15, 75, or 95. When executed by one or more corresponding processors 13, 73, or 93, these instructions cause the corresponding means 10, 70, or 90 to perform the operations described herein. Computer-readable memories 15, 75, or 95 can be of any type suitable to the local technical environment and can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, firmware, magnetic storage devices and systems, optical storage devices and systems, fixed memory, and removable memory. Computer-readable memories 15, 75, and 95 can be means for performing storage functions. By way of non-limiting example, processors 13, 73, and 93 can be of any type suitable to the local technical environment and can include one or more of general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), and processors based on multi-core processor architectures. Processors 13, 73, and 93 can be means for causing their respective means to perform functions such as those described herein.

[0080] Receivers 17, 77, and 97, and transmitters 18, 78, and 98 can implement wired or wireless interfaces. Receivers and transmitters can be grouped together as transceivers.

[0081] Figure 8An example device 800, which can be implemented in hardware, is configured to implement the examples described herein. Device 800 includes at least one processor 802 (e.g., an FPGA and / or CPU), one or more memories 804 including computer program code 805, and computer program code 805 having instructions for performing the methods described herein. The at least one memory 804 and computer program code 805 are configured, together with at least one processor 802, to cause device 800 to implement circuits, processes, components, modules, or functions (implemented using control module 806) for implementing the examples described herein, including implementing transport isolation of network slices using slice-aware authentication data. Memory 804 may be non-transient memory, transient memory, volatile memory (e.g., RAM), or non-volatile memory (e.g., ROM). The N / W slice isolation 830 of the control module implements the aspects described herein related to implementing transport isolation of network slices using slice-aware authentication data.

[0082] Device 800 includes a display and / or I / O interface 808, which includes user interface (UI) circuitry and components that can be used to display aspects or states of the methods described herein (e.g., while a method is being performed or at a subsequent time), or to receive input from a user, such as using a keypad, camera, touchscreen, touch area, microphone, biometrics, one or more sensors, etc. Device 800 includes one or more communications, such as (multiple) network (N / W) interfaces (I / F) 810. The (multiple) communication I / Fs 810 can be wired and / or wireless, and communicate via the Internet / (multiple) other networks via any communication technology, including via one or more links 824. The (multiple) links 824 can be from... Figure 7 Links (multiple) 11 and / or 79 and / or 31 and / or 81. From Figure 7 The multiple links 11 and / or 79 and / or 31 and / or 81 can also be implemented using multiple transceivers 816 and multiple corresponding wireless links 826. The multiple communication I / Fs 810 may include one or more transmitters or one or more receivers.

[0083] Transceiver 816 includes one or more transmitters 818 and one or more receivers 820. Transceiver 816 and / or (multiple) communication I / F 810 may include standard-known components such as amplifiers, filters, frequency converters, (de)modulators and encoder / decoder circuitry, and one or more antennas, such as antenna 814 for communication via wireless link 826.

[0084] The control module 806 of device 800 includes one or both of portions 806-1 and / or 806-2, which can be implemented in various ways. Control module 806 can be implemented in hardware as control module 806-1, such as being implemented as part of one or more processors 802. Control module 806-1 can also be implemented as an integrated circuit or by other hardware such as a programmable gate array. In another example, control module 806 can be implemented as control module 806-2, which is implemented as computer program code (with corresponding instructions) 805 and executed by one or more processors 802. For example, one or more memories 804 store instructions that, when executed by one or more processors 802, cause device 800 to perform one or more operations as described herein. Furthermore, one or more processors 802 encoded as instructions, programs, or code, one or more memories 804, and example algorithms (e.g., as flowcharts and / or signaling diagrams) are components for causing the operations described herein to be performed.

[0085] The apparatus 800 for implementing the function of control 806 may be UE 10, base station 70 (e.g., gNB 70), or core network 90 including any network function 99, which may be implemented using network entities. Therefore, processor 802 may correspond to processor(s) 13, 73, and / or 93; memory 804 may correspond to one or more memories 15, 75, and / or 95; computer program code 805 may correspond to program 12, 72, or 92; multiple communication I / Fs 810 and / or transceivers 816 may correspond to other circuits 16, 76, or 96; and antenna 814 may correspond to antenna 28 or antenna 58.

[0086] Alternatively, device 800 and its components may not correspond to any of UE 10, base station 70, or core network and its corresponding components, as device 800 may be part of an Ad Hoc / Optimized Network (SON) node or other nodes (such as nodes in the cloud). Device 800 may also correspond to security gateway 80, peering eNB / gNB 70-2, or operator certification authority 402 (e.g., CMP / CA server). Device 800 can also be distributed throughout the network (e.g., 91), including within and between device 800 and any network elements (such as core network 90 and / or base station 70 and / or UE 10).

[0087] Interface 812 enables data communication and signaling between various components of device 800, such as... Figure 8As shown. For example, interface 812 may be one or more buses, such as address, data, or control buses, and may include any interconnection mechanism, such as a series of lines on a motherboard or integrated circuit, fiber optic cables, or other optical communication devices. Computer program code (e.g., instructions) 805 including control 806 may include object-oriented software configured to pass data or messages between objects within computer program code 805. Device 800 need not include every feature mentioned, or may include other features. Various components of device 800 may reside at least partially in a common housing 828, or a subset of various components of device 800 may reside at least partially in different housings, which may include housing 828.

[0088] Figure 9 A schematic diagram is shown of a non-volatile memory medium 900a (e.g., a computer / optical disc (CD) or digital multifunction optical disc (DVD)) and 900b (e.g., a Universal Serial Bus (USB) Memory Stick) and 900c (e.g., cloud storage for downloading instructions and / or parameters 902 or receiving email instructions and / or parameters 902), which, when executed by a processor, allows the processor to perform one or more steps of the methods described herein.

[0089] Figure 10 This is an example method 1000 based on the example embodiments described herein. At 1010, the method includes determining at least one slice-specific identifier. At 1020, the method includes creating a slice-specific connection with a network node using a certificate associated with the at least one slice-specific identifier. At 1030, the method includes sending data over the slice-specific connection. Method 1000 can be performed by network node 70, network node 70-2, security gateway 80, user equipment 10, or device 800.

[0090] Figure 11 This is an example method 1100 based on the example embodiments described herein. At 1110, the method includes receiving an Internet Protocol Secure (IPS) connection request with a certificate. At 1120, the method includes wherein the IPS connection request includes a first slice-specific identifier. At 1130, the method includes wherein the certificate includes at least one second slice-specific identifier. At 1140, the method includes determining a network slice based on the first slice-specific identifier within the IPS connection request. At 1150, the method includes determining whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier. Method 1000 can be performed by network node 70, network node 70-2, security gateway 80, user equipment 10, or device 800.

[0091] Figure 12 This is an example method 1200 based on an example embodiment described herein. At 1210, the method includes determining a network slice. At 1220, the method includes determining a first slice-specific identifier corresponding to the network slice. At 1230, the method includes sending an Internet Protocol Secure (IPS) connection request with a certificate. At 1240, the method includes wherein the IPS connection request includes the first slice-specific identifier. At 1250, the method includes wherein the certificate includes at least one second slice-specific identifier. At 1260, the method includes sending data on a slice-specific connection associated with the network slice. Method 1000 can be performed by network node 70, network node 70-2, security gateway 80, user equipment 10, or device 800.

[0092] This article provides and describes the following examples.

[0093] Example 1. An apparatus comprising: at least one processor; and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least: determine at least one slice-specific identifier; create a slice-specific connection with a network node using a certificate associated with the at least one slice-specific identifier; and transmit data on the slice-specific connection.

[0094] Example 2. The apparatus according to Example 1, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: send an initialization request to include at least one slice-specific identifier within a field extension of a certificate.

[0095] Example 3. The apparatus according to Example 2, wherein an initialization request is sent to a certificate management protocol server or a certificate authorization server.

[0096] Example 4. An apparatus according to any one of Examples 2 to 3, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: send a request within an initialization request to include a plurality of slice-specific identifiers within a field extension of a certificate.

[0097] Example 5. The apparatus according to Example 4, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: determine at least one slice-specific identifier among a plurality of slice-specific identifiers when a new network slice is added.

[0098] Example 6. An apparatus according to any one of Examples 2 to 5, wherein the initialization request includes a certificate management protocol initialization request.

[0099] Example 7. An apparatus according to any one of Examples 1 to 6, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: receive a certificate having at least one slice-specific identifier.

[0100] Example 8. The apparatus according to Example 7, wherein the certificate is received from a certificate management protocol server or a certificate authorization server.

[0101] Example 9. An apparatus according to any one of Examples 1 to 8, wherein at least one slice-specific identifier includes a fully qualified domain name.

[0102] Example 10. An apparatus according to any one of Examples 1 to 9, wherein the certificate includes at least one slice-specific identifier.

[0103] Example 11. An apparatus according to any one of Examples 1 to 10, wherein the field extension of the certificate includes a subject alternate name field extension, the subject alternate name field extension including at least one slice-specific identifier.

[0104] Example 12. An apparatus according to any one of Examples 1 to 11, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: determine at least one slice-specific identifier using a public land mobile network identifier and a single network slice selection auxiliary information.

[0105] Example 13. An apparatus according to any one of Examples 1 to 12, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: use an endpoint transfer definition identifier to determine at least one slice-specific identifier.

[0106] Example 14. The apparatus according to Example 13, wherein the endpoint transmission definition identifier is already existing.

[0107] Example 15. An apparatus according to any one of Examples 13 to 14, wherein the endpoint transmission definition identifier is newly added.

[0108] Example 16. An apparatus according to any one of Examples 1 to 15, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: send an Internet Key Exchange Authentication message, wherein at least one slice-specific identifier is used in the identification payload of the Internet Key Exchange Authentication message.

[0109] Example 17. An apparatus according to any one of Examples 1 to 16, wherein the Internet key exchange identifier is part of the certificate.

[0110] Example 18. An apparatus according to any one of Examples 1 to 17, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: configure an Internet key exchange profile using at least one slice-specific identifier.

[0111] Example 19. An apparatus according to any one of Examples 1 to 18, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: determine, based on at least one slice-specific identifier, not to delete active tunnels created from a slice other than those created from a slice used for the initial contact notification payload, wherein the slice used for the initial contact notification payload is associated with at least one slice-specific identifier.

[0112] Example 20. An apparatus according to any one of Examples 1 to 19, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: determine, based on at least one slice-specific identifier, not to delete active tunnels created from at least one multi-operator radio access network use case.

[0113] Example 21. An apparatus according to any one of Examples 1 to 20, wherein the network node includes an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

[0114] Example 22. An apparatus according to any one of Examples 1 to 21, wherein the apparatus includes another network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

[0115] Example 23. An apparatus according to any one of Examples 1 to 22, wherein at least one slice-specific identifier includes a tunnel endpoint.

[0116] Example 24. An apparatus according to any one of Examples 1 to 23, wherein the certificate includes a terminal entity certificate.

[0117] Example 25. An apparatus according to any one of Examples 1 to 24, wherein at least one slice-specific identifier and a slice-specific connection are specific to a network slice.

[0118] Example 26. An apparatus according to any one of Examples 1 to 25, wherein the certificate is specific to a network slice.

[0119] Example 27. An apparatus according to any one of Examples 1 to 26, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: determine at least one slice-specific identifier from a plurality of slice-specific identifiers within a certificate.

[0120] Example 28. An apparatus comprising: at least one processor; and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least: receive an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; determine a network slice based on the first slice-specific identifier within the IPS connection request; and determine whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0121] Example 29. An apparatus according to Example 28, wherein the instructions, when executed by at least one processor, cause the apparatus to at least: determine to accept the Internet Protocol Secure Connection Request in response to a first slice-specific identifier in the Internet Protocol Secure Connection Request matching at least one of at least one second slice-specific identifier in the certificate; and determine to reject the Internet Protocol Secure Connection Request in response to a first slice-specific identifier in the Internet Protocol Secure Connection Request not matching at least one of at least one second slice-specific identifier in the certificate.

[0122] Example 30. An apparatus according to any one of Examples 28 to 29, wherein the Internet Protocol Secure Connection Request includes an Internet Key Exchange Request.

[0123] Example 31. An apparatus according to any one of Examples 28 to 30, wherein a first slice-specific identifier includes a fully qualified domain name, and at least one second slice-specific identifier includes a fully qualified domain name.

[0124] Example 32. An apparatus according to any one of Examples 28 to 31, wherein at least one second slice-specific identifier is within a field extension of the certificate.

[0125] Example 33. An apparatus according to any one of Examples 28 to 32, wherein the field extension of the certificate includes a subject alternate name field extension, and at least one second slice-specific identifier is within the subject alternate name field extension of the certificate.

[0126] Example 34. The apparatus according to Example 33, wherein at least one second slice-specific identifier within the subject alternate name field extension of the certificate includes a plurality of slice-specific identifiers.

[0127] Example 35. An apparatus according to any one of Examples 28 to 34, wherein at least one second slice-specific identifier includes a plurality of slice-specific identifiers.

[0128] Example 36. An apparatus according to any one of Examples 28 to 35, wherein the Internet Protocol Secure connection request is received from a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

[0129] Example 37. An apparatus according to any one of Examples 28 to 36, wherein the apparatus includes a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

[0130] Example 38. An apparatus according to any one of Examples 28 to 37, wherein a first slice-specific identifier includes a tunnel endpoint, and at least one second slice-specific identifier includes a tunnel endpoint.

[0131] Example 39. An apparatus according to any one of Examples 28 to 38, wherein a first slice-specific identifier is within the identifier payload of an Internet Protocol Secure Connection Request.

[0132] Example 40. An apparatus comprising: at least one processor; and at least one memory storing instructions, the instructions, when executed by the at least one processor, causing the apparatus to at least: determine a network slice; determine a first slice-specific identifier corresponding to the network slice; send an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and send data on a slice-specific connection associated with the network slice.

[0133] Example 41. The apparatus according to Example 40, wherein the Internet Protocol Secure Connection Request includes an Internet Key Exchange Request.

[0134] Example 42. An apparatus according to any one of Examples 40 to 41, wherein a first slice-specific identifier includes a fully qualified domain name, and at least one second slice-specific identifier includes a fully qualified domain name.

[0135] Example 43. An apparatus according to any one of Examples 40 to 42, wherein at least one second slice-specific identifier is within a field extension of the certificate.

[0136] Example 44. An apparatus according to any one of Examples 40 to 43, wherein the field extension of the certificate includes a subject alternate name field extension, and at least one second slice-specific identifier is within the subject alternate name field extension of the certificate.

[0137] Example 45. The apparatus according to Example 44, wherein at least one second slice-specific identifier within the subject alternate name field extension of the certificate includes a plurality of slice-specific identifiers.

[0138] Example 46. An apparatus according to any one of Examples 40 to 45, wherein at least one second slice-specific identifier includes a plurality of slice-specific identifiers.

[0139] Example 47. An apparatus according to any one of Examples 40 to 46, wherein an Internet Protocol secure connection request is sent to a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

[0140] Example 48. An apparatus according to any one of Examples 40 to 47, wherein the apparatus includes a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

[0141] Example 49. An apparatus according to any one of Examples 40 to 48, wherein a first slice-specific identifier includes a tunnel endpoint, and at least one second slice-specific identifier includes a tunnel endpoint.

[0142] Example 50. An apparatus according to any one of Examples 40 to 49, wherein a first slice-specific identifier is within the identifier payload of an Internet Protocol Secure Connection Request.

[0143] Example 51. A method comprising: determining at least one slice-specific identifier; using a certificate associated with the at least one slice-specific identifier to create a slice-specific connection with a network node; and sending data on the slice-specific connection.

[0144] Example 52. A method comprising: receiving an Internet Protocol Secure (IPS) connection request having a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; determining a network slice based on the first slice-specific identifier within the IPS connection request; and determining whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0145] Example 53. A method comprising: determining a network slice; determining a first slice-specific identifier corresponding to the network slice; sending an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and sending data on a slice-specific connection associated with the network slice.

[0146] Example 54. An apparatus comprising: components for determining at least one slice-specific identifier; components for creating a slice-specific connection with a network node using a certificate associated with the at least one slice-specific identifier; and components for transmitting data on the slice-specific connection.

[0147] Example 55. An apparatus comprising: components for receiving an Internet Protocol Secure (IPS) connection request having a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; components for determining a network slice based on the first slice-specific identifier within the IPS connection request; and components for determining whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0148] Example 56. An apparatus comprising: components for determining a network slice; components for determining a first slice-specific identifier corresponding to the network slice; components for sending an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and components for sending data on a slice-specific connection associated with the network slice.

[0149] Example 57. A non-transient program storage device, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program, the instruction program being machine-executable for performing operations including: determining at least one slice-specific identifier; using a certificate associated with the at least one slice-specific identifier to create a slice-specific connection with a network node; and transmitting data on the slice-specific connection.

[0150] Example 58. A non-transient program storage device, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program, the instruction program being machine-executable for performing operations including: receiving an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes a first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; determining a network slice based on the first slice-specific identifier within the IPS connection request; and determining whether to accept or reject the IPS connection request based on the first slice-specific identifier and at least one second slice-specific identifier.

[0151] Example 59. A non-transient program storage device, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program, the instruction program being machine-executable for performing operations including: determining a network slice; determining a first slice-specific identifier corresponding to the network slice; sending an Internet Protocol Secure (IPS) connection request with a certificate; wherein the IPS connection request includes the first slice-specific identifier; wherein the certificate includes at least one second slice-specific identifier; and sending data on a slice-specific connection associated with the network slice.

[0152] References to 'computer', 'processor', etc., should be understood to encompass not only computers with different architectures (such as single / multiprocessor architectures and sequential or parallel architectures), but also special-purpose circuits (such as field-programmable gate arrays (FPGAs), special-purpose circuits (ASICs)), signal processing devices, and other processing circuits. References to computer programs, instructions, code, etc., should be understood to encompass software or firmware for programmable processors, such as, for example, the programmable content of hardware devices, whether instructions for processors or configuration settings for fixed-function devices, gate arrays, or programmable logic devices, etc.

[0153] The memory described herein can be implemented using any suitable data storage technology, such as semiconductor-based memory devices, flash memory, magnetic memory devices and systems, optical memory devices and systems, non-transient memory, transient memory, fixed memory, and removable memory. The memory may include a database for storing data.

[0154] As used herein, the term "circuit" may refer to: (a) a hardware circuit implementation, such as an analog and / or digital circuit; and (b) a combination of circuitry and software (and / or firmware), such as (if applicable): (i) a combination of (multiple) processors or (ii) a portion of (multiple) processors / software, including (multiple) digital signal processors, software, and memory, which work together to enable a device to perform various functions; and (c) a circuit, such as (multiple) microprocessors or a portion of (multiple) microprocessors, which requires software or firmware to operate, even if the software or firmware is not physically present. As another example, as used herein, the term "circuit" will also cover embodiments of a processor (or multiple processors) or a portion of a processor and its accompanying software and / or firmware. For example, and if applicable to a particular element, the term "circuit" will also cover a baseband integrated circuit or application processor integrated circuit for a mobile phone, or a similar integrated circuit in a server, cellular network device, or another network device.

[0155] It should be understood that the foregoing description is illustrative only. Those skilled in the art can devise various alternatives and modifications. For example, features recited in the various dependent claims can be combined with each other in any suitable combination. Furthermore, features from the different example embodiments described above can be selectively combined to form new example embodiments. Therefore, this specification is intended to cover all such alternatives, modifications, and variations falling within the scope of the appended claims.

[0156] The following acronyms and abbreviations, which can be found in the instruction manual and / or accompanying drawings, are given below (abbreviations and acronyms may be appended to each other or with other characters such as dashes, hyphens, forward slashes or numbers, and may be case-insensitive): 3GPP Third Generation Partnership Project 4G fourth generation 5G (Fifth Generation) 5GC 5G Core Network AMF Access and Mobility Management Functions ASIC (Application-Specific Integrated Circuit) AUTH certification BTS base station transceiver station CA (Certificate Authority) CD / Computer CD CMP Certificate Management Agreement CMP IP CMP Initialization Response CMP IR CMP Initialization Request CP control plane CPU (Central Processing Unit) DSP Digital Signal Processor DVD (Digital Universal Disc) eMBB Enhanced Mobile Broadband eNB evolved base stations (e.g., LTE base stations) EP endpoint EPC Evolved Packet Core Network E-SMLC Evolved Service Mobility Center FA manufacturers (such as) Figure 4 FA equipment certificate in China FPGA (Field Programmable Gate Array) fqdn, FQDN Fully Qualified Domain Name GMLC Gateway Mobile Location Center gNB (Next Generation Base Station) is a base station used for 5G / NR, providing NR user plane and control plane protocol termination to the UE and connecting to the 5GC node via the NG interface. GW gateway ICN Initial Contact Notice ID identifier or identity IDi logo initiator IDr identifies the responder I / F interface IKE Internet Key Exchange INIT initialization I / O Input / Output IP Internet Protocol IPsec Internet Protocol Security KPIs (Key Performance Indicators) KUR Key Update Request KUP Key Update Response LMF location management function LTE Long Term Evolution (4G) MAC Media Access Control MME (Mobility Management Entity) MORAN (Multi-Operator RAN) NF Network Functions NG New Generation NG-RAN (Next Generation Radio Access Network) NR New Radio NRF Network Repository Functionality N / W network OP operators (e.g., Figure 4 (OP device certificate) OPR operator PKI Public Key Infrastructure PLMN Public Land Mobile Network POP Holding Certificate RAM (Random Access Memory) RAN (Radio Access Network) RFC Request for Comments ROM (Read-Only Memory) Rx receiver or receiver S1 is the interface connecting the eNB and EPC. SA Security Association SAN theme alternative name Sec security SecGW security gateway SEG Security Gateway SGW Service Gateway SMF Session Management Function SNSSAI Single Network Slice Selection Auxiliary Information SON self-organizing / self-optimizing network TRP Transmitter / Receiver Point TS Technical Specifications Tx sender or sender UDM Unified Data Management UDR Unified Data Repository UE (User Equipment) (such as wireless equipment, typically mobile equipment) UI (User Interface) UP User Interface UPF User Face Functions USB Universal Serial Bus v version VM virtual machine Wi-Fi is a wireless network protocol used by Wi-Fi devices to communicate without a direct cable connection. Network interfaces between X2 RAN nodes and between the RAN and the core network. Xn Network interface between NG-RAN nodes.

Claims

1. An apparatus comprising: At least one processor; as well as At least one memory stores instructions that, when executed by the at least one processor, cause the device to at least: Identify at least one slice-specific identifier; A slice-specific connection to a network node is created using a certificate associated with the at least one slice-specific identifier; and Data is sent over the slice-specific connection.

2. The apparatus of claim 1, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: Send an initialization request to include the at least one slice-specific identifier within the field extension of the certificate.

3. The apparatus according to claim 2, wherein the initialization request is sent to a certificate management protocol server or a certificate authorization server.

4. The apparatus according to any one of claims 2 to 3, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: Within the initialization request, a request is sent to include multiple slice-specific identifiers within the field extensions of the certificate.

5. The apparatus of claim 4, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: When a new network slice is added, at least one slice-specific identifier among the plurality of slice-specific identifiers is determined.

6. The apparatus according to any one of claims 2 to 5, wherein the initialization request includes a certificate management protocol initialization request.

7. The apparatus according to any one of claims 1 to 6, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: Receive the certificate having the at least one slice-specific identifier.

8. The apparatus of claim 7, wherein the certificate is received from a certificate management protocol server or a certificate authorization server.

9. The apparatus according to any one of claims 1 to 8, wherein the at least one slice-specific identifier comprises a fully qualified domain name.

10. The apparatus according to any one of claims 1 to 9, wherein the certificate includes the at least one slice-specific identifier.

11. The apparatus according to any one of claims 1 to 10, wherein the field extension of the certificate includes a subject alternate name field extension, the subject alternate name field extension including the at least one slice-specific identifier.

12. The apparatus according to any one of claims 1 to 11, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: The at least one slice-specific identifier is determined using a public land mobile network identifier and a single network slice selection auxiliary information.

13. The apparatus according to any one of claims 1 to 12, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: The endpoint transport definition identifier is used to determine the at least one slice-specific identifier.

14. The apparatus of claim 13, wherein the endpoint transmission definition identifier is already existing.

15. The apparatus according to any one of claims 13 to 14, wherein the endpoint transmission definition identifier is newly added.

16. The apparatus according to any one of claims 1 to 15, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: Send an Internet Key Exchange Authentication Message, wherein at least one slice-specific identifier is used in the identification payload of the Internet Key Exchange Authentication Message.

17. The apparatus according to any one of claims 1 to 16, wherein the Internet key exchange identifier is part of the certificate.

18. The apparatus according to any one of claims 1 to 17, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: Use the at least one slice-specific identifier to configure the Internet key exchange profile.

19. The apparatus according to any one of claims 1 to 18, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: Based on the at least one slice-specific identifier, it is determined that active tunnels created from slices other than those created from slices used for the initial contact notification payload will not be deleted, wherein the slice used for the initial contact notification payload is associated with the at least one slice-specific identifier.

20. The apparatus according to any one of claims 1 to 19, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: Based on the at least one slice-specific identifier, determine whether to delete active tunnels created from at least one multi-operator radio access network use case.

21. The apparatus according to any one of claims 1 to 20, wherein the network node includes an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

22. The apparatus according to any one of claims 1 to 21, wherein the apparatus comprises another network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

23. The apparatus according to any one of claims 1 to 22, wherein at least one slice-specific identifier includes a tunnel endpoint.

24. The apparatus according to any one of claims 1 to 23, wherein the certificate includes a terminal entity certificate.

25. The apparatus according to any one of claims 1 to 24, wherein the at least one slice-specific identifier and the slice-specific connection are specific to a network slice.

26. The apparatus according to any one of claims 1 to 25, wherein the certificate is specific to a network slice.

27. The apparatus according to any one of claims 1 to 26, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: At least one slice-specific identifier is determined from a plurality of slice-specific identifiers within the certificate.

28. An apparatus comprising: At least one processor; as well as At least one memory stores instructions that, when executed by the at least one processor, cause the device to at least: Receive Internet Protocol Secure (IPS) connection requests with certificates; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate mentioned above includes at least one second slice-specific identifier; The network slice is determined based on the first slice-specific identifier within the Internet Protocol Secure Connection Request; as well as Based on the first slice-specific identifier and the at least one second slice-specific identifier, determine whether to accept or reject the Internet Protocol Secure (IPS) connection request.

29. The apparatus of claim 28, wherein the instructions, when executed by the at least one processor, cause the apparatus to at least: In response to a match between the first slice-specific identifier in the Internet Protocol Secure (IPS) connection request and at least one of the at least one second slice-specific identifiers in the certificate, it is determined that the IPS connection request is accepted; and In response to a mismatch between the first slice-specific identifier in the Internet Protocol Secure Connection Request and at least one of the at least one second slice-specific identifiers in the certificate, the Internet Protocol Secure Connection Request is rejected.

30. The apparatus according to any one of claims 28 to 29, wherein the Internet Protocol Secure Connection Request includes an Internet Key Exchange Request.

31. The apparatus according to any one of claims 28 to 30, wherein the first slice-specific identifier comprises a fully qualified domain name, and the at least one second slice-specific identifier comprises a fully qualified domain name.

32. The apparatus according to any one of claims 28 to 31, wherein the at least one second slice-specific identifier is within the field extension of the certificate.

33. The apparatus of any one of claims 28 to 32, wherein the field extension of the certificate includes a subject alternative name field extension, and the at least one second slice-specific identifier is within the subject alternative name field extension of the certificate.

34. The apparatus of claim 33, wherein the at least one second slice-specific identifier within the subject alternative name field extension of the certificate comprises a plurality of slice-specific identifiers.

35. The apparatus according to any one of claims 28 to 34, wherein the at least one second slice-specific identifier comprises a plurality of slice-specific identifiers.

36. The apparatus according to any one of claims 28 to 35, wherein the Internet Protocol secure connection request is received from a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

37. The apparatus according to any one of claims 28 to 36, wherein the apparatus comprises a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

38. The apparatus of any one of claims 28 to 37, wherein the first slice-specific identifier includes a tunnel endpoint, and the at least one second slice-specific identifier includes a tunnel endpoint.

39. The apparatus according to any one of claims 28 to 38, wherein the first slice-specific identifier is within the identifier payload of the Internet Protocol Secure Connection Request.

40. An apparatus comprising: At least one processor; as well as At least one memory stores instructions that, when executed by the at least one processor, cause the device to at least: Determine network slices; Determine a first slice-specific identifier corresponding to the network slice; Send a certificated Internet Protocol Secure (IPS) connection request; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate includes at least one second slice-specific identifier; and Data is sent on a slice-specific connection associated with the network slice.

41. The apparatus of claim 40, wherein the Internet Protocol Secure Connection Request includes an Internet Key Exchange Request.

42. The apparatus of any one of claims 40 to 41, wherein the first slice-specific identifier comprises a fully qualified domain name, and the at least one second slice-specific identifier comprises a fully qualified domain name.

43. The apparatus according to any one of claims 40 to 42, wherein the at least one second slice-specific identifier is within the field extension of the certificate.

44. The apparatus of any one of claims 40 to 43, wherein the field extension of the certificate includes a subject alternative name field extension, and the at least one second slice-specific identifier is within the subject alternative name field extension of the certificate.

45. The apparatus of claim 44, wherein the at least one second slice-specific identifier within the subject alternative name field extension of the certificate comprises a plurality of slice-specific identifiers.

46. ​​The apparatus according to any one of claims 40 to 45, wherein the at least one second slice-specific identifier comprises a plurality of slice-specific identifiers.

47. The apparatus of any one of claims 40 to 46, wherein the Internet Protocol Secure Connection Request is sent to a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

48. The apparatus according to any one of claims 40 to 47, wherein the apparatus comprises a network node, an evolved Node B, a next-generation Node B, a security gateway, or a user equipment.

49. The apparatus of any one of claims 40 to 48, wherein the first slice-specific identifier includes a tunnel endpoint, and the at least one second slice-specific identifier includes a tunnel endpoint.

50. The apparatus of any one of claims 40 to 49, wherein the first slice-specific identifier is within the identifier payload of the Internet Protocol Secure Connection Request.

51. A method comprising: Identify at least one slice-specific identifier; Use the certificate associated with the at least one slice-specific identifier to create a slice-specific connection to the network node; as well as Data is sent over the slice-specific connection.

52. A method comprising: Receive Internet Protocol Secure (IPS) connection requests with certificates; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate mentioned above includes at least one second slice-specific identifier; The network slice is determined based on the first slice-specific identifier within the Internet Protocol Secure Connection Request; as well as Based on the first slice-specific identifier and the at least one second slice-specific identifier, determine whether to accept or reject the Internet Protocol Secure (IPS) connection request.

53. A method comprising: Determine network slices; Determine a first slice-specific identifier corresponding to the network slice; Send a certificated Internet Protocol Secure (IPS) connection request; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate includes at least one second slice-specific identifier; and Data is sent on a slice-specific connection associated with the network slice.

54. An apparatus comprising: Components used to identify at least one slice-specific identifier; A component for creating a slice-specific connection to a network node using a certificate associated with the at least one slice-specific identifier; as well as Components used to send data on specific connections of the slice.

55. An apparatus comprising: A component used to receive Internet Protocol Secure (IPS) connection requests with certificates; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate mentioned above includes at least one second slice-specific identifier; Components used to determine network slices based on the first slice-specific identifier within the Internet Protocol Secure Connection Request; as well as A component for determining whether to accept or reject the Internet Protocol Secure (IPS) connection request based on the first slice-specific identifier and the at least one second slice-specific identifier.

56. An apparatus comprising: Components used to determine network slices; Components used to determine a first slice-specific identifier corresponding to the network slice; A component used to send Internet Protocol Secure (IPS) connection requests with certificates; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate mentioned above includes at least one second slice-specific identifier; as well as Components for sending data on slice-specific connections associated with the network slice.

57. A non-transient program storage device, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program, the instruction program being machine-executable for performing operations, the operations including: Identify at least one slice-specific identifier; Use the certificate associated with the at least one slice-specific identifier to create a slice-specific connection to the network node; as well as Data is sent over the slice-specific connection.

58. A non-transient program storage device, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program, the instruction program being machine-executable for performing operations, the operations including: Receive Internet Protocol Secure (IPS) connection requests with certificates; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate mentioned above includes at least one second slice-specific identifier; The network slice is determined based on the first slice-specific identifier within the Internet Protocol Secure Connection Request; as well as Based on the first slice-specific identifier and the at least one second slice-specific identifier, determine whether to accept or reject the Internet Protocol Secure (IPS) connection request.

59. A non-transient program storage device, the non-transient program storage device being machine-readable, the non-transient program storage device tangibly implementing an instruction program, the instruction program being machine-executable for performing operations, the operations including: Determine network slices; Determine a first slice-specific identifier corresponding to the network slice; Send a certificated Internet Protocol Secure (IPS) connection request; The Internet Protocol Secure Connection Request includes a first slice-specific identifier; The certificate includes at least one second slice-specific identifier; and Data is sent on a slice-specific connection associated with the network slice.