5G Network Slice Authorization Through Core Network Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network slices in 5G networks are vulnerable to unauthorized usage due to compromised security in user device execution environments, leading to potential overloading.
Innovation Solution
Implement network slice access authorization through core network elements that verify user devices' authorization before setting up data sessions, using network slice information and tokens to ensure authorized usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network slice access is allowed without strict authorization verification, then network slice usage is convenient and fast, but unauthorized devices can compromise network security and cause overload
Solution Approach 1:
The patent performs authorization verification in advance before allowing network slice access. The core network elements verify whether the user device is authorized to use the network slice before setting up the data session, preventing unauthorized access while maintaining network security without adding complex runtime verification mechanisms
Solution Approach 2:
The patent introduces core network elements as intermediaries that mediate between user devices and network slices. These intermediaries perform the authorization verification by checking whether the user device is authorized to use the network slice, thereby simplifying the verification process while ensuring security through a dedicated intermediary layer
2Reliability
If authorization verification is performed by user device itself, then authorization process is simple, but security is compromised when device execution environment is compromised
Solution Approach 1:
The patent introduces core network elements as intermediaries that mediate between user devices and network slices. These intermediaries perform the authorization verification by checking whether the user device is authorized to use the network slice, thereby simplifying the verification process while ensuring security through a dedicated intermediary layer
Solution Approach 2:
The user device provides its authorization information and tokens to the core network elements for verification. The device itself participates in the authorization process by presenting its credentials, maintaining simplicity while the core network performs the actual security verification
Data Source
AI summary
A method may include receiving, by at least one network device and from a user device, a registration message including a service identifier and at least one of a network slice identifier or a network slice token. The method may also include determining, based on information included in the registration message, whether the user device is authorized to use a network slice associated with the service identifier. The method may further include setting up a data session to be serviced by the network slice, in response to determining that the user device is authorized to use the network slice.


