5G Slice Identifier Privacy With Encrypted NSSAI and Temporary IDs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G systems lack adequate confidentiality and integrity protection for Network Slice Selection Assistance Information (NSSAI) during initial registration, leading to potential privacy breaches and inefficient AMF selection, and persistent identifiers can be used to track users.
Innovation Solution
Introduce a privacy attribute (PrivAttr) for NSSAI and S-NSSAI, encrypt sensitive information using pre-provisioned keys, and employ cryptographic hashes for temporary identifiers to ensure confidentiality and unlinkability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If NSSAI is transmitted in clear text during initial registration, then AMF selection can be performed efficiently, but user privacy and slice information confidentiality are compromised
Solution Approach 1:
The patent applies preliminary action by pre-provisioning encryption keys in the UE before registration. This allows the UE to encrypt NSSAI information beforehand using these pre-stored keys, ensuring confidentiality is maintained from the outset without requiring complex key exchange protocols during the registration process itself.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism that mediates between the need for confidential NSSAI transmission and efficient AMF selection. The encryption layer acts as an intermediary, allowing the AMF to receive encrypted slice information and perform selection based on decrypted data, thus maintaining both security and efficiency.
2Ease of operation
If persistent identifiers are used for UE tracking, then network management and mobility control are simplified, but user anonymity and tracking privacy are violated
Solution Approach 1:
The patent segments the identifier system by introducing temporary identifiers that are separate from persistent identifiers. The UE is assigned a temporary identifier for each registration session, which is distinct from its permanent subscription identifier. This segmentation allows network management functions to operate on temporary identifiers while preserving user anonymity.
Solution Approach 2:
The patent applies parameter changes by dynamically changing the identifier parameter from persistent to temporary on a per-session basis. The network can switch between using temporary identifiers for anonymity and persistent identifiers for long-term management, changing the identifier parameter according to the operational context.
3Measurement precision
If all S-NSSAIs are included in Requested NSSAI, then complete slice information is provided for optimal network selection, but privacy exposure and signaling overhead increase
Solution Approach 1:
The patent extracts only the necessary S-NSSAIs for the current service context into the Requested NSSAI, rather than including all configured S-NSSAIs. This extraction principle allows the UE to provide precise slice selection information for the needed service while leaving other slice information out, thus reducing privacy exposure without compromising selection accuracy.
Solution Approach 2:
The patent applies partial action by including only a subset of S-NSSAIs in the Requested NSSAI based on current service requirements. Rather than providing complete slice information (excessive action), the UE provides just enough information for accurate slice selection, balancing precision with privacy protection.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
It is recognized herein that current methods and systems for performing procedures in 5G systems may not adequately protect the confidentiality and/or integrity of exchanged NSSAI and other identifiers. In methods and systems that protect NSSAI by not initially sending unprotected NSSAI, a non-optimal AMF may be selected for use by a UE, and an AMF relocation procedure may need to be performed when the NSSAI is later sent in a protected manner, wasting time and resources. In methods and systems with persistent UE identifiers, it may be possible to map the identifiers to users of an AMF and track those users. Various embodiments described herein address solutions to these and other issues.