5G Network Slice Authentication Checks Across PLMNs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, the repeated initiation of network slice specific authentication and authorization procedures between terminal devices and the core network side leads to wasteful signaling, especially when a terminal device accesses the same network slice across different public land mobile networks (PLMNs).

Innovation Solution

A communication method where a network element determines the authentication status of a target network slice before initiating an authentication procedure, thereby avoiding redundant authentication by checking if an authentication procedure has already been performed, and optionally notifying the data management network element of the authentication result.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a terminal device accesses the same network slice through different PLMNs, then the terminal device can access the network slice from multiple networks, but the core network element repeatedly performs authentication procedures causing signaling waste

Engineering Contradiction:
Improvenetwork slice access capabilityVSAvoidsignaling waste
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by having the core network element check the authentication status of a network slice before performing authentication. The network element queries whether authentication has already been performed on the target network slice, and only performs authentication if it hasn't been done before. This prevents redundant authentication procedures when a terminal device accesses the same network slice through different PLMNs, thereby reducing signaling waste while maintaining multi-network access capability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If network slice specific authentication is performed on every access request, then authentication security is maintained, but signaling overhead increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements feedback by having the core network element query the authentication status of the network slice before performing authentication procedures. The network element receives feedback information indicating whether authentication has already been performed, and based on this feedback, decides whether to proceed with authentication. This feedback mechanism ensures authentication security is maintained for unauthorized access attempts while avoiding redundant signaling for already authenticated sessions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3989621B1Communication method and network element
Publication Date: 2025.09.10 HUAWEI TECH CO LTD
  • EP3989621B1 patent drawingFigure 1~2
  • EP3989621B1 patent drawingFigure 3
  • EP3989621B1 patent drawingFigure 4

AI summary

Embodiments of this application disclose a communication method. The method includes: A first network element obtains a first authentication status of a target network slice of a first terminal device from a data management function network element, where the first authentication status indicates a first authentication result of the target network slice, or the first authentication status indicates that no authentication procedure has been performed on the target network slice. The first network element determines, based on the first authentication status, whether to perform a first authentication procedure on the target network slice. The embodiments of this application further provide a corresponding network element. According to technical solutions provided in this application, the first network element determines, based on the first authentication status, whether to perform the first authentication procedure on the target network slice, to avoid a waste of signaling between a terminal device and a core network side caused because a network slice authentication procedure is repeatedly initiated on a same piece of S-NSSAI.