Access control for electronic devices tethered using network slicing supported within a cellular network
The host UE device with an access control module manages multiple simultaneous upstream links to authenticate and authorize tethered UE devices for accessing different network slices, addressing the limitations of conventional tethering technologies and enhancing data communication efficiency.
Patent Information
- Application Number
- JP2024523731
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-10-21
- Filing Date
- 2022-10-21
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2042-10-21
AI Technical Summary
Conventional tethering technologies do not implement network slice access control to authenticate/authorize tethered UE devices to use different network slices provided by cellular networks, limiting their ability to utilize multiple network slices tailored to specific use cases.
A host UE device establishes multiple simultaneous upstream links with the cellular network and includes an access control module to authenticate/authorize client UE devices for accessing and managing different network slices, using network slice information to manage and control access to network slices for tethered client UE devices.
Enables tethered UE devices to benefit from network, computational, and storage resources allocated to specific network slices, allowing them to utilize multiple network slices tailored to their requirements, enhancing data communication efficiency and flexibility.
Smart Images

Figure 0007724376000001 
Figure 0007724376000002 
Figure 0007724376000003
Abstract
Description
[Background technology]
[0001] background Tethering is a technique for providing network communications to a second device (or devices) through a first device. For example, the first and second devices may be configured with hardware and software that allows the second device to establish a wired or wireless network (tether) connection with the first device. The second device sends network requests to the first device via the tether connection. The first device relays network requests received from the second device to the appropriate destination network using a communication channel established by the first device with a network, such as a cellular network. When the first device receives data associated with the second device, the first device forwards this data to the second device via the tether connection. Thus, tethering allows the second device to access network services using the network connection of the first device. Summary of the Invention
[0002] Overview of the embodiment According to some embodiments, a method includes establishing, by a first user equipment (UE), a tethered connection with a second UE; identifying a first network slice from a plurality of network slices provided by a network; obtaining authentication information associated with the second UE; and controlling access to the first network slice by the second UE based on the authentication information.
[0003] In various embodiments, the method may further include one or more of the following aspects: identifying the first network slice includes at least one of receiving a request from a second UE associated with the first network slice or selecting the first network slice from a plurality of network slices; obtaining authentication information includes sending an authentication request to the second UE and receiving an authentication response from the second UE in response to sending the authentication request; the method further includes establishing a secure connection with the second UE, wherein the authentication request is sent to the second UE via the secure connection and the authentication response is received via the secure connection; further, the method includes determining that the first network slice is available to the first UE and sending an authentication request to the second UE in response to the first network slice being available to the first UE. Obtaining the authentication information also includes receiving an authentication request associated with the first network slice from the network, forwarding the authentication request to the second UE, receiving an authentication response from the second UE in response to forwarding the authentication request, and transmitting the authentication response to the network. The method further includes establishing a secure connection with the second UE, where the authentication request is forwarded to the second UE via the secure connection, and the authentication response is received via the secure connection. Obtaining the authentication information also includes receiving an authentication request associated with the first network slice from the network, generating an authentication response based on the authentication information associated with the second UE in response to receiving the authentication request, and transmitting the authentication response to the network. Controlling access to the first network slice is based on the authentication response. The method also includes determining that the first network slice is unavailable to the first UE and requesting the first network slice from the network, where receiving the authentication request from the network is responsive to requesting the first network slice from the network.Controlling access to the first network slice includes granting access permission to the second UE to the first network slice based on the authentication information and wirelessly communicating data of the second UE via the first network slice using a first upstream link. Controlling access to the first network slice further includes denying access to the second UE to the first network slice based on the authentication information and wirelessly communicating data of the second UE via the second network slice using a second upstream link. The method further includes maintaining the first upstream link simultaneously with the second upstream link.
[0004] According to some embodiments, a method includes: establishing, by a first user equipment (UE), a tethered connection with a second UE; receiving from the second UE a request to access a network slice provided by the network; determining that the network slice is not available to the first UE; sending the request for the network slice to the network; receiving from the network an authentication request associated with the network slice; and authenticating the second UE with respect to the network slice in response to receiving the authentication request.
[0005] In various embodiments, the method may further include one or more of the following aspects: authenticating the second UE includes establishing a secure connection with the second UE; authenticating the second UE further includes forwarding an authentication request to the second UE, receiving an authentication response to the authentication request from the second UE, and forwarding the authentication response to the network; authenticating the second UE also includes forwarding the authentication request to the second UE, receiving an authentication response to the authentication request from the second UE, and forwarding the authentication response to the network; authenticating the second UE further includes, in response to forwarding the authentication response to the network, determining that the second UE is authorized to access the network slice and wirelessly communicating data of the second UE via the network slice using the upstream link; authenticating the second UE also includes, in response to forwarding the authentication response to the network, determining that the second UE is not authorized to access the network slice and denying the second UE access to the network slice.
[0006] In some embodiments, a device includes a radio frequency (RF) antenna interface, at least one processor coupled to the RF antenna interface, and a memory storing executable instructions configured to operate the at least one processor to perform any of the methods described above and herein.
[0007] The present disclosure may be better understood, and its numerous features and advantages made apparent to those skilled in the art by referencing the accompanying drawings, in which: The use of the same reference symbols in different drawings indicates similar or identical items. [Brief explanation of the drawings]
[0008] [Figure 1]FIG. 1 illustrates an example wireless communication system employing a host user equipment (UE) that implements an access control mechanism for tethered client UE devices to access network slices implemented by the host UE, in accordance with some embodiments. [Figure 2] FIG. 1 illustrates an example configuration of a UE that implements network slicing for a tethered client UE device, in accordance with some embodiments. [Figure 3] FIG. 10 illustrates example operations for implementing an access control mechanism for a tethered UE device to access a network slice, in accordance with some embodiments. [Figure 4] FIG. 10 illustrates example operations for implementing an access control mechanism for a tethered UE device to access a network slice, in accordance with some embodiments. [Figure 5] FIG. 10 illustrates example operations for implementing an access control mechanism for a tethered UE device to access a network slice, in accordance with some embodiments. [Figure 6] 6 is a ladder signaling diagram illustrating an exemplary operation of the method of FIGS. 3-5, according to some embodiments. [Figure 7] 6 is a ladder signaling diagram illustrating an exemplary operation of the method of FIGS. 3-5, according to some embodiments. [Figure 8] 6 is a ladder signaling diagram illustrating an exemplary operation of the method of FIGS. 3-5, according to some embodiments. DETAILED DESCRIPTION OF THE INVENTION
[0009] Detailed Description Tethering allows a device that may not have the hardware or software resources to establish a connection with a given network to access the network through another device that does. For example, a second user equipment (UE) device, such as a tablet or notebook computer, may not have the hardware / software to connect to a cellular network. However, the second UE device can establish a wired or wireless tethered connection (downstream link) with a first UE device, such as a smartphone, that can establish a connection (upstream link) with the cellular network. The tethered connection allows the second UE device to access the services of the cellular network through the network connection of the first UE device.
[0010] As data and bandwidth allocations to end users increase, tethering has become a more viable and useful option for accessing the Internet over cellular networks. However, tethering technologies are typically not configured to implement recent advances in cellular networks. One such advance is network slicing, which defines different types of services and provides an end-to-end logical network (network slice) for these services across multiple portions of a cellular network. Network slicing allows network services to be customized based on the requirements of various use cases. Services offered by a Third Generation Partnership Project (3GPP®) Fifth Generation New Radio (5G NR) cellular network may be implemented using network slices that are instantiated and managed by a network management system of the 5G NR cellular network. In at least some embodiments, a network slice defines a type of service within a cellular network and may be considered an end-to-end logical network across multiple portions of the cellular network. Each network slice provides a quality of service tailored to the use case associated with the network slice, such as low latency, guaranteed bandwidth, and support for internet-of-things (IoT) devices with long battery life. Also, a network slice can have dedicated resources within a single network operator's network or across multiple network operator's networks. An end-to-end network slice may consist of a radio access network (RAN) slice and / or a core slice.
[0011] Different tethered UE devices or different applications on the same tethered UE device may need to use or can benefit from using different network slices. However, conventional tethering technologies typically establish a single upstream link with a cellular network and cannot utilize different network slices provided by the cellular network for tethered UE devices. Also, only authenticated / authorized UE devices, such as a host UE device (or an application on the host UE device), can typically use a network slice or dynamically request, release, or update a network slice. Conventional tethering technologies generally do not implement network slice access control to authenticate / authorize a tethered UE device (or an application on the tethered UE device) to perform these operations with respect to the network slice provided by the cellular network. Therefore, conventional tethering technologies typically do not allow a tethered UE device to utilize different network slices provided by the cellular network.
[0012] This disclosure describes embodiments of systems and methods for implementing access control mechanisms associated with different network slices for tethered connections. In at least some embodiments, a host UE device establishes a connection with a cellular network. As part of the connection process, the cellular network transmits network slice information to the host UE device. This network slice information identifies available network slices provided by the cellular network. In other embodiments, the network slice information is obtained by the host UE device while in idle mode during a radio / cell search or at any other time before connecting to the cellular network. One or more client UE devices establish tethered connections with the host UE device. The tethered connections may be wired or wireless connections. In at least some embodiments, the host UE device uses the network slice information to establish multiple simultaneous upstream links with the cellular network and use the upstream links to access multiple network slices for the tethered client UE devices.
[0013] In at least some embodiments, the host UE device includes an access control module for authenticating / authorizing client UE devices and controlling their access to network slices. As described in further detail below, when a client UE device (or an application running on the client UE device) requests, releases, or updates one or more network slices, the access control module performs one or more authentication operations to determine whether the client UE device (or application) is authorized to perform the operations. The access control module also determines whether the client UE device (or application) is authorized to access the requested network slice or the network slice selected by the host UE device for the client UE device.
[0014] In at least some embodiments, the access control module is further configured to cooperate with other modules on the host UE device to control access of one or more network slices by the client UE device. For example, when the access control module receives a new slice request from the client UE device, the access control module interacts with the network slicing policy management module to determine whether the request is permitted. If the request is permitted, the access control module communicates with the upstream network management module to determine whether a network slice is already available. If a network slice is already available, the upstream network management module requests a new slice via the connectivity service and the telephony service. During this process, there may be authentication interactions between the network, the telephony / connection service (via the modem), and the client UE device (via the access control module). When the new network slice is ready, the upstream network management module (or the access control module) calls the connectivity service (e.g., communicating with the wireless access module / modem) and the network management service (e.g., communicating with the kernel and transmission control protocol (TCP) / internet protocol (IP) stack) as necessary to update one or both of the network routes and IP rules. The policy management module and the access control module may be updated based on the new network slice. Examples of other modules with which the access control module may interact on the host UE device include a downstream network management module, a tethering state management module, etc.
[0015] As such, the techniques described herein provide a network slice authentication and access control mechanism at a host UE device that implements network slicing for tethered client UE devices in a cellular network, where data associated with the tethered client UE devices can benefit from network, computational, and storage resources allocated to and configured in the network slice that carries the data.
[0016] For ease of explanation, the following techniques are described in the exemplary context of one or more UE devices and a radio access network (RAN) implementing one or more radio access technologies (RATs), including at least a fifth-generation (5G) New Radio (NR) standard (e.g., 3rd Generation Partnership Project (3GPP) Release 15, 3GPP Release 16, etc.) (hereinafter “5G NR” or “5G NR standard”). However, it should be understood that the present disclosure is not limited to networks employing a 5G NR RAT configuration; rather, the techniques described herein may apply to any combination of various RATs employed by UE devices and RANs. It should also be understood that the present disclosure is not limited to any particular network configuration or architecture described herein for implementing network slicing (or equivalent techniques) using tethered connections; instead, the techniques described herein may apply to any configuration of a RAN in which a host UE device can establish multiple simultaneous upstream links and implement different network slices for tethered client UE devices. Additionally, the present disclosure is not limited to the examples and situations described herein; rather, the techniques described herein may be applied to any network environment in which a host UE device implements network slicing for tethered client UE devices.
[0017] FIG. 1 illustrates an exemplary mobile cellular network 100 employing a set of tethered UE devices 102, 104 implementing network slicing in accordance with some embodiments. It should be understood that the present disclosure is not limited to the cellular network 100 and that the techniques described herein apply to other types of wireless communication systems. As shown in the figure, the cellular network 100 (also referred to as network 100) includes multiple UE devices 102, 104, one or more RANs 106, and a core network 108. FIG. 1 further illustrates that one or more external networks 110, such as the Internet or a public switched telephone network (PSTN), are coupled to the cellular network 100 via the core network 108. It should be understood that the cellular network 100 may include additional components not shown in FIG. 1 .
[0018] The UE devices 102, 104 may include any of a variety of electronic devices capable of wired and / or wireless communication, such as a smartphone, a tablet computer, a notebook computer, a desktop computer, a smartwatch or other wearable computing device, an automobile or other vehicle employing wireless communication services (e.g., for navigation, entertainment service provision, in-vehicle mobile hotspot, etc.), a gaming device, a media device, an IoT device (e.g., a sensor node, a controller / actuator node, or a combination thereof), and another device capable of wired and / or wireless communication. In at least one embodiment, the RAN 106 is accessible, for example, using a 5G NR RAT and is connected to one or more other RANs (not shown) via at least a core network 108. A RAN 106 implementing a 5G NR RAT may be referred to as a 5G NR RAN or NR RAT. One example of a core network 108 in a 5G NR cellular network is a Fifth-Generation Core (5GC) network.
[0019] Each RAN 106 includes one or more base stations 112 operable to communicate wirelessly with UE devices 102, 104 within signal range, with each base station 112 or combination of base stations 112 defining a single “cell” of coverage for the RAN 106. In at least some embodiments, the base stations 112 are implemented as macrocells, microcells, small cells, picocells, etc., or any combination thereof. Consistent with the terminology adopted by the 5G NR standard, base stations 112 implementing the 5G NR RAT are referred to herein as “5G NodeBs 112” or “gNBs 112.” As is well known in the art, the base stations 112 operate as an “air interface” and establish radio frequency (RF) wireless communications links with the UE devices 102, 104, which may be implemented as any suitable type of wireless communications link. These wireless communication links then serve as data and voice conduits between the UE devices 102, 104 and a core network 108 coupled to one or more of the external networks 110 to provide various services to the UE devices 102, 104. Examples of these services include voice services over circuit-switched or packet-switched networks, messaging services such as simple messaging service (SMS) or multimedia messaging service (MMS), multimedia content delivery, presence services, etc. In at least some embodiments, multiple wireless communication links are aggregated into carrier aggregation to provide higher data rates to the UE devices 102, 104. Multiple wireless communication links from multiple base stations 112 may be configured for coordinated multipoint (CoMP) communication with the UE devices 102, 104. Additionally, in at least some embodiments, multiple wireless communication links are configured for single-RAT or multi-RAT dual connectivity (MR-DC).
[0020] 1 further illustrates an example configuration of a cellular network 100 that implements network slicing for a tethered connection between UE devices 102, 104. In at least some embodiments, one or more client UE devices 104 (shown as 104-1 and 104-2) establish a tethered connection 114 (shown as 114-1 and 114-2) with a host UE device 102. The tethered connection 114 (also referred to as a downstream link 114) may be established using wired or wireless technology. For example, a wired connection between the host UE device 102 and the client UE device 104 may be made using a universal serial bus (USB) connection, an Ethernet connection, etc. For example, a wireless connection may be made using Wi-Fi (i.e., one or more of the IEEE 802.11 wireless standards), Bluetooth, Zigbee, near-field communication (NFC), etc.
[0021] The tethered connections 114 enable the client UE devices 104 to access the core network 108 and the external network 110 via communication links 116 (also referred to as upstream links 116) established between the host UE device 102 and the core network 108 via the RAN 106. For example, the client UE devices 104 send network requests to the host UE device 102 via each tethered connection 114. The host UE device 102 relays network requests received from the client UE devices 104 to the appropriate destination via the RAN 106 and the core network 108 using the upstream links 116 established by the host UE device 102. The host UE device 102 also receives data associated with one or more of the client UE devices 104, e.g., from the external network 110, via the upstream links 116. The host UE device 102 transmits the received data to the appropriate client UE device 104 via the tethered connections 114. The data, in at least some embodiments, includes a single data packet, multiple data packets, a data stream, a data burst, or the like.
[0022] In conventional tether configurations, the host UE device is typically not configured to maintain network slice mapping for data traffic over the tethered connection. In these configurations, the host UE typically establishes a single, common upstream link with the 5G NR core network for all connected client UE devices. Therefore, only the default network slice currently used by the host UE device can be used for client UE devices. Also, because the default network slice is used for client UE devices in conventional tether configurations, the host UE device typically does not implement a network slice access control mechanism to authenticate / authorize client UE devices to use, request, release, or update a different (non-default) network slice.
[0023] However, as described in further detail below, the host UE device 102, in at least some embodiments, can establish multiple simultaneous upstream links 116 (shown as 116-1 through 116-3) and use the upstream links 116 to access multiple network slices 118 (shown as network slices 118-1 through 118-3) for the tethered client UE device 104. In at least some embodiments, one or more of the upstream links 116 are physical upstream links. In other embodiments, one or more of the simultaneous upstream links 116 are logical upstream links carried via the physical upstream links. In addition to establishing multiple simultaneous upstream links 116 to access multiple network slices, the host UE device 102 is configured to authorize / authenticate the client UE device 104 to request, use, release, and update one or more network slices 118.
[0024] In at least some embodiments, the host UE device 102 obtains network slice information 120 associated with a network slice 118 of the core network 108. FIG. 1 shows that the core network 108 includes multiple network slices 118. Throughout this description, network slice 118-1 is referred to as the default network slice, and network slices 118-2 and 118-3 are referred to as non-default network slices. Examples of network slices 118 include network slices configured for 5G NR enhanced mobile broadband (eMBB), 5G ultra-reliable low latency communications (URLLC), 5G NR massive machine type communications (mMTC), massive internet-of-things (MIoT), etc. The cellular network 100 may include any number and combination of network slices 118, including numbers and combinations not shown in FIG. 1.
[0025] The network slice information 120, in at least some embodiments, includes a list or other data structure representing available network slices 118, as well as information such as identifiers for each available network slice 118, device and application / service requirements, capabilities, service level agreements (SLAs), configured resources, etc. In at least some embodiments, the network slice information 120 is obtained by the host UE device 102 from a user, a network operator, a base station 112, one or more core network components 122, an external network 110, etc. In one example, the network slice information 120 is obtained by the host UE device 102 as part of an attachment process with the cellular network 100. In another example, the network slice information 120 is obtained by the host UE device 102 while in idle mode during a radio / cell search or at any other time prior to attaching to the cellular network 100.
[0026] The host UE device 102, in at least some embodiments, selects the default network slice 118-1 based on, for example, the context 124 (also referred to as context information 124) of the host UE device 102 and / or one or more network slice policies 126 described below. In other embodiments, the RAN 106, or a component 122 of the core network 108 that manages the network slice 118, selects the default network slice 118-1 for the host UE device 102. For example, the host UE device 102 can send a network slice access request to one or more network components 122, such as a network slice management component, along with the context 124 of the host UE device 102. The network slice management component selects the default network slice 118-1 for the host UE device 102 using the context 124 of the host UE device 102.
[0027] In at least some embodiments, the UE device context 124 indicates various parameters / attributes of the UE device. Examples of context information include tether connection parameters such as link type (e.g., wired or wireless, USB, Wi-Fi, Bluetooth, etc.), link frequency, channel, etc., type of client UE device (e.g., smartphone, tablet computing device, laptop, vehicle, IoT device, gaming device, etc.), media access control (MAC) address of the UE device 102, 104, source Internet Protocol (IP) address of data associated with the UE device 102, 104, destination IP address of data associated with the UE device 102, 104, communication port associated with the data on the UE device 102, 104, application and / or service on the UE device 102, 104 requesting the data, latency requirements of the UE device 102, 104, movement state of the UE device 102, 104 (e.g., in a vehicle, stationary, pedestrian-carrying, moving above or below a speed threshold, etc.), type and / or size of data being sent and / or requested by the UE device 102, 104, etc.
[0028] The host UE device 102, in at least some embodiments, activates the selected default network slice 118-1 by transmitting an access request to the RAN 106 and / or one or more core network components 122 to access the selected default network slice 118-1. After the host UE device 102 is authenticated by the one or more network components 122 and granted access to the default network slice 118-1, the host UE device 102 accesses the default network slice 118-1 and associated services using the default upstream link 116-1. Data associated with the default network slice 118-1 is wirelessly communicated (e.g., transmitted and / or received) by the host UE device 102 via the default upstream link 116-1. The wireless communication of data may, in at least some embodiments, include one or both of transmitting data or receiving data. The host UE device 102 may establish the upstream link 116-1 with the cellular network 100 before or after selecting the default network slice 118-1. The host UE device 102 may implement various mechanisms and techniques for establishing the upstream link 116 and accessing the network slice 118, such as the mechanisms and techniques described in 3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2 (Release 15).
[0029] In addition to selecting and accessing the default network slice 118-1, the host UE device 102, in at least some embodiments, also selects and accesses one or more network slices 118 for the client UE devices 104 based on, for example, a network slice request 128 received from the client UE devices 104, one or more network slice policies (or rules) 126, a combination thereof, etc. For example, the host UE device 102, in at least some embodiments, receives a request from the client UE device 104 (or an application running on the client UE device 104) for one or more new (non-default) network slices 118, such as an eMBB network slice. The request can be for one or more specific network slices 118 or types of network slices 118. In at least some embodiments, the host UE device 102 can broadcast / transmit available network slices 118 provided by the cellular network to one or more of the client UE devices 104 via the tethered connection 114, a network or application layer protocol, etc. A user, application, or service of the client UE device 104 can select one or more of the available network slices 118.
[0030] In other embodiments, the host UE device 102 may automatically select one or more network slices 118 (or slice types) for the client UE device 104 without receiving a request from the client UE device 104. In these embodiments, the host UE device 102 implements one or more network slice policies (or rules) 126 to determine which of the network slices 118 to select and use for a given client UE device 104. The host UE device 102 may use the network slice policies 118 to determine whether a network slice 118 requested by the client UE device 104 can be used for the client UE device 104. The host UE device 102, in at least some embodiments, obtains the network slice policies 126 from a user, a network operator, one or more of the client UE devices 104, a base station 112, a component 122 of the core network 108, an external network 110, etc. In one example, the client UE device 104 transmits the one or more network slice policies 126 to the host UE device 102 using the tethered connection 114. In at least some embodiments, the network slice policy 126 includes, for example, identifiers 130 of the network slices 118 and criteria 132 for each network slice 118 that control the selection and utilization of the network slices 118 for the client UE device 104. The host UE device 102 may store and access the network slice policy 126 locally and / or remotely.
[0031] In at least some embodiments, the network slice policy 126 is a global network slice policy 126-1 that applies to one or more client UE devices 104. In other embodiments, the one or more network slice policies 126 are UE-specific network slice policies 126-2 that are defined or configured for a particular client UE device 104. If the client UE device 104 is associated with the UE-specific network slice policy 126-2, the host UE device 102 may select the network slice 118 for the client UE device 104 using the UE-specific network slice policy 126-2 instead of the global network slice policy 126-1. In at least some embodiments, the selection criteria 132 of the network slice policy 126 may be defined from the perspective of one or both of the UE devices 102, 104 and the network slice 118. For example, the global network slice policy 126-1 may indicate that the associated network slice 118 may be selected for the client UE device 104 only if the context 124 of the client UE device 104 satisfies the selection criteria 132. In another example, the UE-specific network slice policy 126-2 may include selection criteria 132 that indicate a particular slice context 134 (e.g., parameters, attributes, capabilities, etc.) for a network slice 118 to be selected for a given client UE device 104. In at least some embodiments, the host UE device 102 may select the default network slice 118-1 using the network slice policy 126. Also, in at least some embodiments, a user or an application running on either the host UE device 102 or the client UE device 104 can update the network slice policy 126 defined for the client UE device 104.
[0032] In addition to the selection criteria 132, the network slice policy 126, in at least some embodiments, also includes resource allocation information for the tethered connection 114. For example, the network slice policy 126 may indicate specific resources for allocation to any client UE device 104, or, for a given tethering situation, to one or more specific client UE devices 104. For example, the network slice policy 126 may indicate that, for a tethering situation in which one or more client UE devices 104 are connected to the host UE device 102 using a Wi-Fi link, resources such as specific channels, frequencies, buffer sizes, etc., should be allocated to one or more client UE devices 104. In at least some embodiments, the resource allocation information may be included in a different policy separate from the network slice policy 126.
[0033] The network slice policy 126, in at least some embodiments, may include additional information related to management of the network slice policy 126. For example, the network slice policy 126 may indicate whether the client UE device 104 is or is not authorized to update the selection rules or criteria of the network slice policy 126, whether the client UE device 104 should or should not be authorized to update the selection rules or criteria, whether the client UE device 104 is or is not authorized to request the current network slice 118 or to request a new network slice 118, whether the client UE device 104 should or should not be authorized to request / release the network slice 118, whether a user of the host UE device 102 or the client UE device 104 can or cannot be shown details or only an overview of the network slice policy 126, etc. In other embodiments, the additional information may be maintained or accessed separately from the network slice policy 126.
[0034] The host UE device 102, in at least some embodiments, determines one or more network slices 118 for the client UE device 104 in response to the client UE device 104 establishing a tethered connection (downstream link) 114 with the host UE device 102 or when receiving a request from the client UE device 104 to access the cellular network 100. As part of the network slice 118 selection process or prior to the selection process, the host UE device 102 obtains the client UE device 104's current context 124 with respect to the network slice 118 to be selected. For example, the host UE device 102 may analyze the network slice policy 126 and identify the type of context information 124 to determine which of the network slices 118 may be selected for the client UE device 104. For example, the host UE device 102, after analyzing the network slice policy 126 of the third network slice 118-3, determines that context information 124, such as a device type, a tether connection type, a frequency of the tether connection, and a data type, is needed to determine whether the third network slice 118-3 can be selected for the client UE device 104. The host UE device 102 then communicates with the client UE device 104 to obtain this context information 124. However, in at least some embodiments, this and other context information 124 has already been provided to the host UE device 102 as part of establishing the tether connection 114. As such, the context 124 of the client UE device 104 can be automatically provided to the host UE device 102 by the client UE device 104 and / or the host UE device 102 can query the client UE device 104 for the context information 124.
[0035] The host UE device 102, in at least some embodiments, compares the context 124 of the client UE device 104 with the selection criteria 132 of the network slice policy 126 to determine whether the context 124 satisfies the selection criteria 132 of one or more network slices 118. If the context 124 of the client UE device 104 satisfies the selection criteria 132 of the network slice 118, the host UE device 102 selects the network slice 118. If the context 124 of the client UE device 104 does not satisfy the selection criteria 132 of a non-default network slice 118, the host UE device 102, in at least some embodiments, selects the default network slice 118-1 for the client UE device 104. In at least some embodiments, instead of (or in addition to) analyzing the context 124 of the client UE device 104 with respect to the network slice policy 126, the host UE device 102 analyzes the context 134 of the network slice 118 (also referred to as context information 134) with respect to the network slice policy 126. For example, the network slice policy 126 may include selection criteria 132 based on context information 134 of the network slice 118. For example, the selection criteria 132 may indicate particular attributes and / or parameters, such as latency, bandwidth, offered services, SLA, etc., for which the network slice 118 is selected for a given client UE device 104.
[0036] If the host UE device 102 selects the default network slice 118-1, the client UE device 104 transmits a first data stream to the host UE device 102 using the first tether connection 114-1. The host UE device 102 receives the first data stream and transmits the first data stream via the default network slice 118-1 using the default upstream link 116-1. A second data stream is received by the host UE device 102 via the default network slice 118-1. The host UE device 102 determines that the second data stream is intended for the client UE device 104 and transmits the second data stream to the client UE device 104 using the first tether connection 114-1.
[0037] If the client UE device 104 requests or the host UE device 102 selects one or more non-default network slices 118-2 or 118-3, the client UE device 104, in at least some embodiments, may need to be authenticated by one or both of the network 100 and the host UE device 102 before using / accessing, releasing, or updating the requested / selected network slice 118. Accordingly, in at least some embodiments, the host UE device 102 includes an access control module 136 for performing authentication / authorization operations and controlling access to the network slice 118 by the client UE device 104. The access control module 136, in at least some embodiments, establishes a connection 138 (depicted as connections 138-1 and 138-2) with a network slicing-aware application 140 (depicted as network slicing-aware application 140-1 and network slicing-aware application 140-2) on the client UE device 104 associated with the selected / requested network slice 118. Connection 138, in at least some embodiments, is a secure connection implementing one or more security protocols, such as the Transport Layer Security (TLS) protocol or other applicable protocols. In some embodiments, connection 138 is a secure connection 138, while in other embodiments, connection 138 may not be a secure connection.
[0038] The network slicing-aware application 140 is configured to interact with the access control module 136 of the host UE device 102 to authenticate / authorize the client UE device 104 and to manage access of network slices at the client UE device 104. For example, the network slicing-aware application 140 requests access to, update, or release one or more network slices 118 associated with the client UE device 104. In other embodiments, the network slicing-aware application 140 is configured to interact with the access control module 136 of the host UE device 102 to authenticate / authorize the client UE device 104, while one or more other applications at the client UE device 104 are configured to request access to update or release one or more network slices 118 associated with the client UE device 104. The network slicing-aware application 140, in at least some embodiments, is a standalone application at the client UE device 104 or is part of another application at the client UE device 104 that can use the network slices 118.
[0039] In at least some embodiments, the secure connection 138 is established between the access control module 136 and the network slicing-aware application 140 when the tether connection 114 is established. In other embodiments, the secure connection 138 is established after the tether connection 114 is established. The secure connection 138 can be part of the tether connection 114 or separate from the tether connection 114. In at least some embodiments, the client UE device 104 uses the secure connection 138 to send network slicing requests 128 to the host UE device 102, receive responses to received authentication requests from the host UE device 102, send authentication messages to the host UE device 102, receive authentication messages from the host UE device 102, combinations thereof, etc. In at least some embodiments, the host UE device 102 uses the secure connection 138 to receive network slicing requests 128 from the client UE device 104, send authentication messages to the client UE device 104, receive authentication messages from the client UE device 104, combinations thereof, etc.
[0040] Upon receiving a network slice request 128 from the client UE device 104 or the host UE device 102 selecting a network slice 118 for the client UE device 104, the access control module 136 determines whether the requested / selected network slice 118 is currently available at the host UE device 102. If the requested network slice 118 is available, the host UE device 102 has already been authenticated / authorized by the network 100 to use the network slice 118. This authentication / authorization, in at least some embodiments, may be carried over to the client UE device 104 such that the client UE device does not need to be authenticated / authorized by the network 100. However, the client UE device 104 may still need to be locally authenticated / authorized by the host UE device 102 to request, use, release, or update the network slice 118. In other embodiments, even if the host UE device 102 is authenticated / authorized, the client UE device 104 may need to be authenticated / authorized by the network 100, and the network authentication / authorization process described below is performed. The access control module 136, in at least some embodiments, determines whether network authentication / authorization or local authentication / authorization of the client UE device 104 should be performed based on, for example, the network slice information 120 associated with the requested / selected network slice 118, the network slice policy 126, a combination thereof, etc. Also, if multiple network slices 118 are requested / selected, the client UE device 104 may need to be authenticated with respect to one or more of the requested / selected network slices 118 but may not need to be authenticated with respect to one or more of the remaining requested / selected network slices 118.
[0041] If local authentication / authorization of the client UE device 104 is not required for the requested / selected network slice 118, the access control module 136, in at least some embodiments, configures one or both of the host UE device 102 and the client UE device 104 with network routes / rules to enable the client UE device 104 to use the requested network slice 118 available at the host UE device 102. For example, the access control module 136 sets one or both of the network routes and IP rules via a network management service that communicates with the kernel or TCP / IP stack of the host UE device 102. The network slicing-aware application 140 (or associated module) of the client UE device 104 sets one or both of the routes and IP rules via an associated system service.
[0042] The access control module 136, in at least some embodiments, notifies the client UE device 104 (or application) that the requested network slice 118 is available and may be used by the client UE device 104 (or application). The host UE device 102 establishes (if not already established) an upstream link 116-2 with the cellular network 100 for the client UE device 104 to wirelessly communicate data over the requested / selected network slice 118-2. In other embodiments, the upstream link 116-2 may be established before requesting / selecting the network slice 118-2. In at least some embodiments, if multiple non-default network slices 118-2 and 118-3 are requested / selected, the host UE device 102 establishes separate upstream links 116-2 and 116-3 for each of the multiple network slices 118-2 and 118-3 for wirelessly communicating data over the requested / selected network slice 118. The host UE device 102 begins transmitting and receiving data for the client UE device 104 via the requested / selected non-default network slice 118-2 or 118-3 using the associated upstream link 116-2 or 116-3.
[0043] If the access control module 136 determines that local authentication of the client UE device 104 is required for the requested network slice 118, the access control module 136 authenticates the client UE device 104 using one or more authentication protocols, such as the Extensible Authentication Protocol (EAP). For example, the access control module 136 sends a request to authenticate 142 (also referred to as an authentication request 142) to a network slicing-aware application 140 (or other component) of the client UE device 104 over the secure connection 138. The authentication request 142 may include, for example, the client UE device 104's (or application's) identification information, a message-digest 5 (MD5) challenge, or a request for other authentication information. In response to the valid authenticating request 142, the network slicing-aware application 140 sends a response packet 144 (also referred to as an authentication response 144) to the access control module 136 over the secure connection 138. The process of the access control module 136 sending a request packet to the network slicing-aware application 140 and the network slicing-aware application 140 sending a response packet to the access control module 136 is repeated until the access control module 136 has enough information to determine whether authentication of the client UE device 104 (or application) was successful or failed.
[0044] If the access control module 136 is unable to authenticate the client UE device 104 (or application), the access control module 136 does not grant the client UE device 104 (or application) access to the requested / selected network slice 118 and notifies the client UE device 104 (or application) accordingly. However, if authentication of the client UE device 104 (or application) is successful, the access control module 136 configures one or both of the host UE device 102 and the client UE device 104 with one or more of the network routes or network rules for the client UE device 104 to use the requested network slice 118 available at the host UE device 102. The access control module 136, in at least some embodiments, then notifies the client UE device 104 (or application) that the requested non-default network slice 118-2 or 118-3 is available and may be used by the client UE device 104 (or application). The host UE device 102 establishes (if not already established) the upstream link 116-2 or 116-3 of the requested / selected non-default network slice 118. The host UE device 102 begins transmitting and receiving data for the client UE device 104 via the requested / selected non-default network slice 118 using the associated upstream link 116-2 or 116-3.
[0045] In some examples, the requested / selected network slice 118 may not be available to the host UE device 102. For example, the host UE device 102 may not have activated the requested / selected network slice 118. If the requested / selected network slice 118 is not available to the host UE device 102, the host UE device 102 attempts to activate the network slice 118 by sending an attach / registration request 146 for the network slice 118 to one or more components 122 of the network, such as a network slice management component. In at least some embodiments, information such as network slice selection assistance information (NSSAI) is included in the attach / registration request 146. In at least some embodiments, the context 124 of one or both of the host UE device 102 and the client UE device 104 is sent to the network component 122 along with the attach / registration request 146. The network component 122 receives and processes the request. It should be understood that different network configurations may process the network slice attach / registration request in different manners. As such, the techniques or mechanisms described herein are not limited to any particular mechanism for the host UE device 102 to obtain the network slice 118 from the network 100.
[0046] In at least some embodiments, one or both of the host UE device 102 and the client UE device 104 may need to be authenticated by the network 110 as part of the network slice attachment / registration process. It should be understood that various types of authentication may be performed, such as EAP-based authentication, and the techniques described herein are not limited to any particular authentication mechanism implemented by the network 100. In one example, one or more network components 122, such as a network slice management component or other authentication component, may send a request for authentication 148 (also referred to as an authentication request 148) to the host UE device 102. The access control module 136 of the host UE device 102, in at least some embodiments, determines whether the authentication request 148 can be fulfilled locally or should be forwarded to the client UE device 104. For example, the authentication request 148 may indicate that information, such as an identifier or an MD5 challenge associated with the host UE device 102, is being requested by the network component 122. In this example, the access control module 136 determines that the authentication request 148 can be fulfilled locally because the network component 122 is requesting information associated with the host UE device 102. In another example, the authentication request 148 may indicate that information, such as an identifier or MD5 challenge, associated with the client UE device 104 or one or both of an application running on the client UE device 104 is being requested by the network component 122. In this example, the access control module 136 determines that the authentication request 148 cannot be fulfilled locally and forwards the authentication request to the network slicing-aware application 140 of the client UE device 104 via the secure connection 138. However, in at least some embodiments, the host UE device 102 maintains information related to authentication associated with the client UE device 104 and can fulfill the authentication request locally.The client UE device 104 may provide information related to authentication to the host UE device 102 in response to establishing the tethered connection 114 or the secure connection 138, being already authenticated, a combination thereof, etc.
[0047] The network slicing-aware application 140 of the client UE device 104 receives the authentication request 148 forwarded by the host UE device 102 and generates a response packet 144 that is returned to the access control module 136 of the host UE device 102 via the secure connection 138. The response packet 144 includes the authentication information requested by the network component 122 in the authentication request 148. The access control module 136 receives the response packet 144 from the network slicing-aware application 140 and transmits the response packet 144 to the network component 122. This process is repeated until the network component 122 has sufficient information to determine whether one or more of the host UE device 102 and the client UE device 104 should be granted access to the requested network slice 118. If this determination is made, the network component 122 transmits a message to the UE device 102 indicating whether access to the requested network slice 118 has been granted. If access permission for the requested network slice 118 is granted, the host UE device 102 establishes (if not already established) the upstream link 116-2 or 116-3 of the requested / selected non-default network slice 118-2 or 118-3. The host UE device 102 begins transmitting and receiving data for the client UE device 104 via the requested / selected network slice 118-2 or 118-3 using the associated upstream link 116-2 or 116-3.
[0048] In at least some embodiments, the access control module 136 may receive a request from the client UE device 104 to release or update the network slice 118. In these embodiments, the access control module 136 may repeat the authentication process described herein to determine whether the client UE device 104 (or application) is authorized to release or update the network slice 118. If the client UE device 104 is authorized to request / perform this operation, the host UE device 102 begins releasing or updating the network slice 118. Otherwise, the host UE device 102 notifies the client UE device 104 that the release or update request failed. The host UE device 102 can authenticate multiple client UE devices 104 so that multiple client UE devices 104 can simultaneously access multiple different network slices 118 available to the host UE device 102. As such, the techniques described herein enable a host UE device 102 to authenticate / authorize one or more client UE devices 104 to use one or more different (non-default) network slices 118 available to the host UE device 102.
[0049] FIG. 2 illustrates an example device diagram 200 of a UE device 102 (or 104). In at least some aspects, the device diagram 200 represents a UE device capable of implementing various aspects of network slicing for tethered client UE devices. The UE device 102 may include additional functionality and interfaces that are omitted from FIG. 2 for clarity. The UE device 102, in at least some embodiments, includes an antenna 202, a radio frequency (RF) front end 204, and one or more RF transceivers 206 (e.g., a 3GPP Fourth Generation (4G) Long Term Evolution (LTE) transceiver 206-1 and a 5G NR transceiver 206-2) to communicate with base stations 112 in a RAN 106, such as a 5G RAN and / or an evolved universal mobile telecommunications system terrestrial radio access network (E-UTRAN). The UE device 102, in at least some embodiments, also includes one or more additional transceivers 206-3, such as a local wireless network transceiver, for communicating with other UE devices 104, such as UE devices 104 in a tethered configuration with the UE device 102, via one or more local wireless networks (e.g., wireless local area network (WLAN), Bluetooth, near field communication (NFC), personal area network (PAN), Wireless Fidelity Direct (Wi-Fi-Direct), IEEE 802.15.4, ZigBee, Thread, mmWave, etc.).The RF front end 204, in at least some embodiments, couples or connects the LTE transceiver 206-1, the 5G NR transceiver 206-2, and the local wireless network transceiver 206-3 to the antenna 202 to facilitate various types of wireless communications.
[0050] In at least some embodiments, the antenna 202 of the UE device 102 includes an array of multiple antennas configured similarly or differently from one another. The antenna 202 and RF front end 204, in at least some embodiments, can be tuned and / or tunable to one or more frequency bands, such as frequency bands defined by 3GPP LTE, 3GPP 5G NR, IEEE WLAN, IEEE WMAN (wireless metropolitan-area network), or other communications standards. In at least some embodiments, the antenna 202, RF front end 204, LTE transceiver 206-1, 5G NR transceiver 206-2, and / or local wireless network transceiver 206-3 are configured to support beamforming (e.g., analog, digital, or hybrid) or in-phase and quadrature (I / Q) operations (e.g., I / Q modulation or demodulation operations) for transmitting and receiving communications with the base station 112. By way of example, the antenna 202 and the RF front end 204 may operate in the sub-1 gigahertz, sub-6 GHz, and / or above-6 GHz bands defined by 3GPP LTE, 3GPP 5G NR, or other communications standards.
[0051] In at least some embodiments, for implementations including three or more receive antenna elements, the antenna 202 includes one or more receive antennas arranged in a one-dimensional shape (e.g., a line) or a two-dimensional shape (e.g., a triangle, a rectangle, or an L-shape). A one-dimensional shape allows for measurement of one angular dimension (e.g., azimuth or elevation), while a two-dimensional shape allows for two angular dimensions (e.g., both azimuth and elevation) to be measured. The UE device 102 can use at least a portion of the antenna 202 to form a steered or unsteered, wide or narrow, or shaped (e.g., hemispherical, cubic, sectorial, conical, cylindrical, etc.) beam. The one or more transmit antennas may have an unsteered, omnidirectional radiation pattern or may be capable of generating a wide, steerable beam. Either of these techniques allows the UE device 102 to transmit radar signals to illuminate a large amount of space. In some embodiments, the receive antenna uses digital beamforming to generate thousands of narrow steered beams (e.g., 2000 beams, 4000 beams, or 6000 beams) to achieve the desired level of angular accuracy and resolution.
[0052] The UE device 102, in at least some embodiments, includes one or more sensors 208 implemented to detect various characteristics such as temperature, power supplied, power usage, battery status, etc. The sensors 208 may include any one or combination of temperature sensors, thermistors, battery sensors, and power usage sensors.
[0053] The UE device 102 also includes at least one processor 210 and a non-transitory computer-readable storage medium 212 (CRM 212). The processor 210, in at least some embodiments, is a single-core or multi-core processor made of various materials, such as silicon, polysilicon, high-k dielectrics, copper, etc. The computer-readable storage media described herein exclude propagating signals. The CRM 212, in at least some embodiments, includes any suitable memory or storage device, such as random-access memory (RAM), static RAM (SRAM), dynamic RAM (DRAM), non-volatile RAM (NVRAM), read-only memory (ROM), or flash memory, that can be used to store device data 214 for the UE device 102. The device data 214 includes, for example, user data, multimedia data, beamforming codebooks, applications, and / or the operating system of the UE device 102 executable by the processor 210 to enable user plane communications, control plane signaling, and user interaction with the UE device 102.
[0054] The CRM 212, in at least some embodiments, also includes a communications manager 216. Alternatively or additionally, the communications manager 216, in at least some embodiments, is implemented in whole or in part as hardware logic or circuitry, integrated with or separate from other components of the UE device 102. In at least some embodiments, the communications manager 216 configures the RF front end 204, the LTE transceiver 206-1, the 5G NR transceiver 206-2, and / or the local wireless network transceiver 206-3 to perform one or more wireless communication operations.
[0055] In at least some embodiments, the CRM 212 further includes an access control module 136, a tethering manager 218, a network slice (NS) selection manager 220, device context information 124, network slice context information 134, network slice policy 126, etc. Alternatively or additionally, one or more of these components, in at least some embodiments, are implemented in whole or in part as hardware logic or circuitry, integrated with or separate from other components of the UE device 102. One or more of the access control module 136, the tethering manager 218, and the network slice selection manager 220, in at least some embodiments, configure the RF front end 204, the transceiver 206, the processor 210, and / or other components of the UE device 102 to implement the techniques described herein for providing access control mechanisms for the network slice 118 utilizing network slicing with a tethered client UE device 104.
[0056] 3-8 together illustrate an example method 300 for controlling access to a network slice 118 by a tethered client UE device 104 in a cellular network 100. The access control process of the method 300 is further described with reference to the example transaction (ladder) diagrams of FIGS. 6-8. It should be understood that the present disclosure is not limited to the depicted order of the operations shown in FIGS. 3-8. One or more of the operations may be performed in an order different from that shown, and multiple operations may be performed in parallel.
[0057] The method 300 begins in response to the host UE device 102 determining that a tethering mode should be enabled. In response to this determination, the host UE device 102 enables the tethering mode at block 302. At block 304, the host UE device 102 attaches to the cellular network 100. At block 306, the host UE device 102 obtains network slicing information 120. The network slice information 120, in at least some embodiments, includes a list of available network slices 118 and context information for each available network slice 118, such as parameters, attributes, capabilities, and requirements of the network slice 118. At block 308, the host UE device 102 selects a default network slice 118-1 based on the network slicing information 120. In other embodiments, the RAN 106 or a core network component 122 selects the default network slice 118-1 for the host UE device 102. At block 310, the host UE device 102 establishes a default upstream link 116-1 and activates a default network slice 118-1. In some embodiments, the default upstream link 116-1 may be established before selecting the default network slice 118-1. At block 312, the host UE device 102 establishes a tethered (downstream) link 114 with one or more client UE devices 104. In at least some embodiments, the host UE device 102 may establish a tethered connection 114 with one or more client UE devices 104 before selecting or activating the default network slice 118-1.
[0058] At block 314, the host UE device 102 broadcasts a list of available network slices 118 and context information 134 (e.g., capabilities) of each network slice 118 in response to the establishment of one or more tethered connections 114. At block 316, the access control module 136 of the host UE device 102 establishes a secure connection 602 ( FIG. 6 ) with the client UE device 104. In one example, the access control module 136 establishes the secure connection 602 with the network slicing-aware application 140 (or other component) of the client UE device 104. In at least some embodiments, the secure connection 602 is established before, after, or simultaneously with another block of the method 300. As described below, the host UE device 102 receives a request 604 related to one or more network slices from the client UE device 104 via the secure connection 602. Examples of requests related to a network slice include a request to access a non-default network slice 118-2 or 118-3, or a request to release or update the network slice 118. In at least some embodiments, if the host UE device 102 selects the default network slice 118-1 (or the network slice 118 specified by the network slice policy 126) for the client UE device 104, the secure connection 602 with the client UE device 104 is not established. However, in other embodiments, the access control module 136 of the host UE device 102 establishes the secure connection 602 with the client UE device 104 in response to the host UE device 102 selecting the default network slice 118-1 (or the network slice 118 specified by the network slice policy 126) for the client UE device 104. In at least some embodiments, the access control module 136 establishes the secure connection 602 in response to detecting a request for the secure connection from the client UE device 104.
[0059] At block 318, the host UE device 102 receives a request 604 (FIG. 6) for one or more non-default network slices 118-2 or 118-3 from at least one client UE device 104 via the secure connection 602. In at least some embodiments, the request 604 is a request to access the cellular network 100. The request 604 can be an explicit request or an implicit request, such as, for example, a request for a network slice 118 or transmission of a data stream. The request 604, in at least some embodiments, can be associated with a single network slice 118 or multiple network slices 118. Flow then continues to block 326, described below.
[0060] Alternatively or additionally, the host UE device 102 selects one or more network slices 118 for the client UE device 104 at block 320 based on, for example, the UE context information 124, the network slice policy 126, the network slice context information 134, a combination thereof, etc. In at least some embodiments, the host UE device 102 selects a network slice 118 for the client UE device 104 when the request 604 received from the client UE device 104 does not explicitly identify one or more network slices 118. In some examples, the host UE device 102 selects the default network slice 118-1 for the client UE device 104. For example, the context 124 of the client UE device 104 may not satisfy any of the non-default network slices 118-2, 118-3, resulting in the default network slice 118-1 being selected. In other examples, the host UE device 102 selects the non-default network slice 118-2 or 118-3 for the client UE device 104. For example, the context 124 of the client UE device 104 may indicate that two applications (or services), such as music streaming and gaming, are running on the client UE device 104. Accordingly, the host UE device 102 selects the network slice 118-2 to wirelessly communicate data associated with the first application and selects a different network slice 118-3 to wirelessly communicate data associated with the second application. In at least some embodiments, if the host UE device 102 selects the non-default network slice 118-2 or 118-3 for the client UE device 104, the access control module 136 establishes a secure connection 602 with the client UE device 104, if one is not already established.
[0061] At block 322, the host UE device 102 determines whether a default network slice 118-1 has been selected for the client UE device 104. If the default network slice 118-1 has been selected, at block 324, the host UE device 102 transmits data to and from the client UE device 104 using the default network slice 118-1. Flow continues to block 342 of FIG. 4, where the host UE device 102 determines whether the client UE device 104 has requested activation of a new network slice 118. If the client UE device 104 has requested activation of a new network slice 118, flow returns to one or both of blocks 318 and 320 of FIG. 3. If the client UE device 104 has not requested a new network slice 118, the host UE device 102 determines, at block 344, whether tethering is still enabled. If tethering is still enabled, flow returns to block 324, and the host UE device 102 continues to send and receive data for the client UE device 104 via the default network slice 118-1 using the associated upstream link 116-1. If tethering is no longer enabled, the process ends at block 346.
[0062] Returning to FIG. 3 , if the client UE device 104 requests a non-default network slice 118-2 or 118-3, or if the host UE device 102 selects one or more non-default network slices 118-2 or 118-3 for the client UE device 104, the host UE device 102 determines, at block 326, whether the non-default network slice 118-2 or 118-3 is available to the host UE device 102 or whether a new network slice 118 should be acquired. If the non-default network slice 118-2 or 118-3 is available, the flow continues to block 328 of FIG. 4, where the host UE device 102 further determines whether local authentication of the client UE device 104 is required. For example, the network slice information 120 or the network slice policy 126 associated with the non-default network slice 118 may indicate that the client UE device 104 should be authenticated before using / accessing the network slice 118, releasing the network slice 118, or updating the network slice 118.
[0063] At block 330, if local authentication is not required for the client UE device 104, the host UE device 102 configures at least the client UE device 104 with network routes / rules to enable the client UE device 104 to use the non-default network slice 118. At block 332, the host UE device 102 notifies the client UE device 104 that the client UE device 104 is authorized to use (or release / update) the network slice 118-2 or 118-3. At block 334, the host UE device 102 establishes (if not already established) an upstream link 116-2 or 116-3 for each non-default network slice 118-2 or 118-3 and activates the network slice 118-2 or 118-3. In at least some embodiments, multiple upstream links 116 may be active or maintained simultaneously. At block 346, the host UE device 102 begins transmitting and receiving data for the client UE device 104 via the non-default network slice 118-2 or 118-3 using the associated upstream link 116-2 or 116-3. For example, the host UE device 102 receives a first data stream and transmits the first data stream via the second network slice 118-2 using the second upstream link 116-2. In at least some embodiments, the host UE device 102 determines which upstream link 116 and network slice 118 are associated with the data stream received from the client UE device 104 based on, for example, the context of the data stream. The context of the data stream includes, for example, the type of data being transmitted, the application / service associated with the data, the source IP address, the destination IP address, etc. The host UE device 102 receives the second data stream via the second network slice 118-2.The host UE device 102 determines that the second data stream is intended for the client UE device 104 and transmits the second data stream to the client UE device 104 using the second tethered connection 114-2. Similar operations are performed for the additional upstream link 116 and network slice 118 associated with the second (other) client UE device 104.
[0064] At block 338, the host UE device 102 determines whether the client UE device 104 requested to release the network slice 118. If the client UE device 104 requested to release the network slice 118, the host UE device 102 releases the network slice 118 at block 340, and the flow proceeds to block 342. If the client UE device 104 did not request to release the network slice 118, the host UE device 102 determines at block 342 whether the client UE device 104 requested to activate a new network slice 118. If the client UE device 104 requested to activate a new network slice 118, the flow returns to one or both of blocks 318 and 320 of FIG. 3. If the client UE device 104 did not request a new network slice 118, the host UE device 102 determines whether tethering is still enabled at block 344. If tethering is still enabled, flow returns to block 346, and the host UE device 102 continues to send and receive data for the client UE device 104 via the non-default network slice 118-2 or 118-3 using the associated upstream link 116-2 or 116-3. If tethering is no longer enabled, the process ends at block 346.
[0065] Returning to block 328, if local authentication is required for the client UE device 104, the access control module 136 sends an authentication request 606 ( FIG. 6 ) to the client UE device 104 at block 348. At block 350, the client UE device 104 responds with an authentication response 608 ( FIG. 6 ) that includes the authentication information requested by the access control module 136. At block 352, the access control module 136 determines whether additional information is required to verify whether the client UE device 104 is authorized to access (or release / update) the non-default network slice 118-2 or 118-3. If additional authentication information is required, the flow returns to block 348, and an additional authentication message 610 ( FIG. 6 ) and authentication response 612 ( FIG. 6 ) are sent between the host UE device 102 and the client UE device 104 via the secure connection 602.
[0066] At block 354, if the access control module 136 obtains sufficient authentication information from the client UE device 104, the access control module 136 determines whether local authentication of the client UE device 104 was successful. At block 356, if local authentication was not successful, the access control module 136 sends an authentication status notification 614 (FIG. 6) notifying the client UE device 104 that access to the non-default network slice 118-2 or 118-3 has been denied. In some embodiments, flow continues to block 324, where the access control module 136 grants the client UE device 104 access to the default network slice 118-1 in response to the client UE device 104 being denied access to the non-default network slice 118-2 or 118-3 (616). In this embodiment, the host UE device 102 transmits and receives data for the client UE device 104 via the default network slice 118-1 using the associated upstream link 116-1 (618-624 of FIG. 6). If the local authentication is successful, flow returns to block 330, where the access control module 136 configures at least the client UE device 104 with network routes / rules to enable the client UE device 104 to use the non-default network slice 118-2 or 118-3 (702) (FIG. 7). The operations described above for blocks 332 through 346 are then performed. For example, the host UE device transmits and receives data for the client UE device 104 over the non-default network slice 118-2 or 118-3 using the associated upstream link 116-2 or 116-3 (704 through 710 in FIG. 7).
[0067] Returning to block 326 (FIG. 3), if a new network slice 118 is to be acquired, flow continues to block 358 of FIG. 5, where the host UE device 102 sends an attach / registration request 802 (FIG. 8) for the requested / selected non-default network slice 118-2 or 118-3 to one or more components 122 of the network, such as a network slice management component. At block 360, the host UE device 102 determines whether an authentication request 804 (FIG. 8) has been received from the network 100. At block 362, if an authentication request 804 has not been received from the network 100, the host UE device 102 determines whether the network slice attachment request 802 was successful. In other words, the host UE device 102 determines whether the network 100 has granted the host UE device 102 access permission to the non-default network slice 118-2 or 118-3. At block 364, if the attachment request 802 fails, the access control module 136 of the host UE device 102 notifies the client UE device 104 that access to the requested / selected non-default network slice 118-2 or 118-3 has been denied. Flow continues to block 324, where the host UE device 102 sends and receives data for the client UE device 104 via the default network slice 118-1 using the associated upstream link 116-1. If the attachment request 802 is successful, flow returns to block 330, where the host UE device 102 configures at least the client UE device 104 with network routes / rules to enable the client UE device 104 to use the non-default network slice 118-2 or 118-3. At block 332, the host UE device 102 notifies the client UE device 104 that it is authorized to use (or release / update) the requested / selected network slice 118.In block 334, the host UE device 102 establishes (if not already established) the upstream link 116-2 or 116-3 of the non-default network slice 118-2 or 118-3 and activates the network slice 118-2 or 118-3.
[0068] Returning to block 360, if the authentication request 804 is received, the access control module 136 of the host UE device 102 determines whether the authentication request 804 should be forwarded to the client UE device 104. For example, the authentication request 804 may request authentication information associated with the host UE device 102 or authentication information associated with the client UE device 104 that is locally available at the host UE device 102. In this example, the access control module 136 determines that the authentication request 804 does not need to be forwarded to the client UE device 104. In another example, the authentication request 804 may request authentication information associated with the client UE device 104 that is not locally available at the host UE device 102. In this example, the access control module 136 determines that the authentication request 804 needs to be forwarded to the client UE device 104. At block 368, if the authentication request 804 does not need to be forwarded to the client UE device 104, the access control module 136 sends an authentication response to the network 110. Flow continues to block 362 where the actions previously described for blocks 362 and 364 are performed.
[0069] At block 370, if the authentication request 804 is to be forwarded to the client UE device 104, the access control module 136 of the host UE device 102 establishes a secure connection 806 ( FIG. 8 ) with the client UE device 104 (if not already established). In one example, the access control module 136 establishes the secure connection 806 with the network slicing-aware application 140 (or other component) of the client UE device 104. At block 372, the access control module 136 forwards the authentication request 804 to the client UE device 104 ( 808 ) ( FIG. 8 ). At block 374, the access control module 136 receives an authentication response 810 ( FIG. 8 ) from the client UE device 104 that includes authentication information requested by the network 100 ( FIG. 8 ). At block 376, the access control module 136 transmits the authentication response 810 to the network 100 ( 812 ) ( FIG. 8 ). At block 380, the access control module 136 determines whether an additional authentication message 814 (FIG. 8) has been received from the network 100. If an additional authentication message 814 has been received, flow returns to block 372, where the access control module 136 forwards (816) the additional authentication message 814 to the client UE device 104 (FIG. 8) and receives (820) an additional authentication response 818 (FIG. 8) from the client UE device 104. The access control module 136 forwards (820) the additional authentication response 818 (FIG. 8) to the network 110 (FIG. 8).
[0070] If (or when) an additional authentication message 814 is not received, flow continues to block 362, where the operations described above with respect to blocks 362 and 364 are performed. For example, the access control module 136 receives an authentication status message 822 from the network 100 indicating whether authentication of one or both of the host UE device 102 or the client UE device 104 was successful. If authentication was not successful, operations such as those described above with respect to block 364 of FIG. 5 are performed. If authentication was successful, flow returns to block 330, where the access control module 136 configures (824) at least the client UE device 104 with network routes / rules to enable the client UE device 104 to use the non-default network slice 118-2 or 118-3 (FIG. 8). Then, the operations described above with respect to blocks 332 through 346 and elements 704 through 710 of FIG. 7 are performed. For example, the host UE device transmits and receives data for the client UE device 104 via the non-default network slice 118-2 or 118-3 using the associated upstream link 116-2 or 116-3.
[0071] In some embodiments, certain aspects of the aforementioned techniques are implemented by one or more processors of a processing system executing software. The software includes one or more sets of executable instructions stored or otherwise tangibly embodied in a non-transitory computer-readable storage medium. The software may include instructions and certain data that, when executed by the one or more processors, operate the one or more processors to perform one or more aspects of the aforementioned techniques. The non-transitory computer-readable storage medium may include, for example, a magnetic or optical disk storage device, a semiconductor storage device such as flash memory, a cache, a random access memory (RAM), or one or more other non-volatile memory devices. The executable instructions stored on the non-transitory computer-readable storage medium may be source code, assembly language code, object code, or another format of instructions that is interpreted or otherwise executable by one or more processors.
[0072] A computer-readable storage medium includes any storage medium or combination of storage media that can be accessed by a computer system during use to provide instructions and / or data to the computer system. Such storage media can include, but are not limited to, optical media (e.g., compact disc (CD), digital versatile disc (DVD), Blu-ray disc), magnetic media (e.g., floppy disk, magnetic tape, or magnetic hard drive), volatile memory (e.g., random access memory (RAM) or cache), non-volatile memory (e.g., read-only memory (ROM) or flash memory), or microelectromechanical system (MEMS)-based storage media. The computer-readable storage medium may be embedded in the computing system (e.g., the system's RAM or ROM), permanently attached to the computing system (e.g., a magnetic hard drive), removably attached to the computing system (e.g., an optical disk or a Universal Serial Bus (USB)-based flash memory), or coupled to the computer system via a wired or wireless network (e.g., network accessible storage (NAS)).
[0073] It should be noted that not all of the activities or elements described above in the Summary are required, that some of the particular activities or devices may not be required, and that one or more additional activities may be performed or one or more additional elements may be included in addition to the described activities or elements. Furthermore, the order in which the activities are listed is not necessarily the order in which the activities are performed. Also, concepts have been described with reference to specific embodiments. However, those skilled in the art will recognize that various modifications and changes can be made without departing from the scope of the present disclosure as set forth in the claims below. Accordingly, the specification and drawings should be regarded as illustrative rather than restrictive, and all such modifications are intended to be within the scope of the present disclosure.
[0074] Benefits, other advantages, and solutions to problems have been described above with regard to specific embodiments. However, the benefits, advantages, solutions to problems, and any features that cause or make any benefit, advantage, or solution more pronounced should not be construed as critical, essential, or essential features of any or all of the claims. Moreover, the specific embodiments disclosed above are merely exemplary, as the disclosed subject matter may be modified and practiced in different but equivalent manners apparent to those skilled in the art having access to the teachings herein. No limitations are intended to the details of construction or design shown herein, other than as set forth in the claims below. It is therefore apparent that the specific embodiments disclosed above may be altered or modified, and that all such variations are considered within the scope of the disclosed subject matter. Accordingly, the protection sought herein is as set forth in the claims below.
Claims
1. A first user equipment (UE) (102) establishing a tethered connection (114) with a second UE (104); In response to determining (328) that local authentication of the second UE associated with access authorization to the first network slice (118-1) is required, sending an authentication request (142) to the second UE; receiving an authentication response (144) from the second UE in response to sending the authentication request; In response to determining that the local authentication is successful based on the authentication response, allowing the second UE access to the first network slice (118-1) among a plurality of network slices provided by a network (108).
2. 2. The method of claim 1, further comprising at least one of receiving a request for the first network slice from the second UE or selecting the first network slice from the plurality of network slices.
3. 3. The method of claim 1, further comprising establishing a secure connection with the second UE, wherein the authentication request is sent to the second UE via the secure connection and the authentication response is received via the secure connection.
4. determining that the first network slice is available to the first UE; and 3. The method of claim 1, further comprising: in response to the first network slice being available to the first UE, sending the authentication request to the second UE.
5. Controlling the access to the first network slice includes:
3. The method of claim 1, comprising wirelessly conveying data of the second UE via the first network slice using a first upstream link (116-1).
6. Controlling the access to the first network slice includes: Denying the access of the second UE to the first network slice based on the authentication response; and wirelessly communicating data of the second UE via a second network slice (118-2) using a second upstream link (116-2).
7. The method of claim 6 , further comprising maintaining the first upstream link simultaneously with the second upstream link.
8. A first user equipment (UE) (102) establishing a tethered connection (114) with a second UE (104); In response to receiving a request for access to a first network slice (118-2, 118-3) provided by a network (108) from the second UE, transmitting a request (358) for the first network slice to the network; and authenticating the second UE to use the first network slice in response to receiving, from the network, an authentication request (804) associated with access authorization to the first network slice; authenticating the second UE includes: determining that the second UE is not authorized to access the first network slice; and denying access of the second UE to the first network slice; In response to determining that the second UE is not authorized to access the first network slice, wirelessly communicating data of the second UE via a second network slice (118-1) provided by the network.
9. authenticating the second UE includes: The method of claim 8 , comprising establishing a secure connection with the second UE.
10. 10. The method of claim 8, wherein sending the request to the network is further in response to determining that the first network slice is not available to the first UE.
11. authenticating the second UE includes: forwarding the authentication request to the second UE; receiving an authentication response (144) to the authentication request from the second UE; and forwarding the authentication response to the network.
12. authenticating the second UE includes: determining, in response to forwarding the authorization response to the network, that the second UE is authorized to access the first network slice; and and wirelessly communicating data of the second UE via the first network slice using an upstream link.
13. 12. The method of claim 11, wherein determining that the second UE is not authorized to access the first network slice is in response to forwarding the authorization response to the network.
14. A device (102), a radio frequency (RF) antenna interface (204); at least one processor (210) coupled to the RF antenna interface (204); and a memory (212) storing executable instructions that, when executed by the at least one processor, cause the device to perform the method of any one of claims 1, 2, 8, and 9.
Citation Information
Patent Citations
Communication control method and communication terminal
JP2018170681A