5G Network Authentication Segmentation for Slice Access Efficiency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing authentication methods in 5G mobile communications networks are inefficient and insecure, particularly in network slicing, as they require multiple authentication steps and centralized processing, leading to low efficiency and potential security vulnerabilities when handling large quantities of user equipment (UE) accessing network slices.

Innovation Solution

A network authentication method where the MNO core network verifies the validity of user equipment, then initiates a user authentication request to the UE, without requiring the network server to generate authentication data, thereby improving access efficiency and ensuring security by decentralizing authentication processes and reducing the workload on centralized devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized authentication processing is used in existing 5G networks, then security control is maintained, but authentication efficiency deteriorates when handling large quantities of user equipment

Engineering Contradiction:
Improvenetwork security controlVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the authentication system into two parts: a centralized network authentication network element that maintains security control, and distributed slice authentication network elements that handle actual authentication processing. This segmentation allows security functions to remain centralized while processing functions are distributed, resolving the contradiction between security control and authentication efficiency.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network authentication network element acts as an intermediary between the user equipment and the slice authentication network element. It verifies the validity of identification information and initiates authentication requests, thereby maintaining centralized security control while enabling efficient distributed authentication processing.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple authentication steps are required for network slice access, then security is improved, but authentication time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The network authentication network element performs preliminary verification of identification information validity before initiating the authentication request. This preliminary action ensures security requirements are met while streamlining the subsequent authentication process, reducing overall authentication time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If centralized servers handle all authentication data generation, then security control is maintained, but server workload increases

Engineering Contradiction:
Improvenetwork control authorityVSAvoidcentralized server workload
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication data generation function from the centralized network server and relocates it to the distributed slice authentication network element. The centralized server retains control authority by verifying identification information and initiating requests, while the distributed element handles the computationally intensive authentication data generation, thereby reducing server workload while maintaining control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11272365B2Network authentication method, and related device and system
Publication Date: 2022.03.08 HUAWEI TECH CO LTD
  • US11272365B2 patent drawing
  • US11272365B2 patent drawing
  • US11272365B2 patent drawing

AI summary

This application discloses a network authentication method, and a related device and system. The method includes: receiving, by a network authentication network element, an access request sent by user equipment, where the access request includes identification information of the user equipment; verifying, by the network authentication network element, whether the identification information is valid, and if the identification information is valid, determining, based on the identification information, a slice authentication network element corresponding to the user equipment; and sending, by the network authentication network element, the identification information to the slice authentication network element corresponding to the user equipment, where the identification information is used by the slice authentication network element corresponding to the user equipment to generate authentication data for the user equipment and initiate a user authentication request to the user equipment by using the authentication data.