5G Network Slice Authorization Through Core Network Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network slices in 5G networks are vulnerable to unauthorized usage due to compromised security in user device execution environments, leading to potential overloading.

Innovation Solution

Implement network slice access authorization through core network elements that verify user devices' authorization before setting up data sessions, using network slice information and tokens to ensure authorized usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network slice access is allowed without strict authorization verification, then network slice usage is convenient and fast, but unauthorized devices can compromise network security and cause overload

Engineering Contradiction:
Improvenetwork securityVSAvoidauthorization verification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs authorization verification in advance before allowing network slice access. The core network elements verify whether the user device is authorized to use the network slice before setting up the data session, preventing unauthorized access while maintaining network security without adding complex runtime verification mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces core network elements as intermediaries that mediate between user devices and network slices. These intermediaries perform the authorization verification by checking whether the user device is authorized to use the network slice, thereby simplifying the verification process while ensuring security through a dedicated intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authorization verification is performed by user device itself, then authorization process is simple, but security is compromised when device execution environment is compromised

Engineering Contradiction:
Improveauthorization securityVSAvoidauthorization process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces core network elements as intermediaries that mediate between user devices and network slices. These intermediaries perform the authorization verification by checking whether the user device is authorized to use the network slice, thereby simplifying the verification process while ensuring security through a dedicated intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The user device provides its authorization information and tokens to the core network elements for verification. The device itself participates in the authorization process by presenting its credentials, maintaining simplicity while the core network performs the actual security verification

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12389281B2Systems and methods for network-based slice access authorization
Publication Date: 2025.08.12 VERIZON PATENT & LICENSING INC
  • US12389281B2 patent drawing
  • US12389281B2 patent drawing
  • US12389281B2 patent drawing

AI summary

A method may include receiving, by at least one network device and from a user device, a registration message including a service identifier and at least one of a network slice identifier or a network slice token. The method may also include determining, based on information included in the registration message, whether the user device is authorized to use a network slice associated with the service identifier. The method may further include setting up a data session to be serviced by the network slice, in response to determining that the user device is authorized to use the network slice.