Device-Triggered 5G Slice Re-Authentication with NSSAI States
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication networks lack efficient mechanisms for handling slice-specific secondary authentication failures, leading to unauthorized access attempts and denial of service attacks due to the lack of clear standards for re-authentication and state information management between network components.
Innovation Solution
Implementing a network server and user equipment device configuration to generate and manage Unauthorized NSSAI, Pending NSSAI, and Rejected NSSAI information elements, along with slice-specific backoff timers and re-authentication procedures to handle secondary authentication failures and protect against unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network slices are authorized without clear re-authentication standards, then network access is simplified, but security is compromised and denial of service attacks increase
Solution Approach 1:
The patent segments the network slice authorization process into distinct states (Authorized NSSAI, Pending NSSAI, Rejected NSSAI) with specific transition conditions. Each state has defined entry and exit criteria, creating a structured state machine that manages re-authentication systematically without requiring complex ad-hoc decision logic at each network component.
Solution Approach 2:
The patent establishes preliminary authorization states (Pending NSSAI) before final authorization is granted. Network slices are placed in a pending state with associated backoff timers before being fully authorized, allowing pre-processing of authentication requests and preventing immediate re-authentication attempts that could lead to denial of service attacks.
2Reliability
If unauthorized network slice access attempts are blocked, then network security is improved, but legitimate access attempts may be denied
Solution Approach 1:
The patent implements dynamic state transitions for network slice authorization. The same network slice can transition between Authorized, Pending, and Rejected states based on authentication outcomes and timer expirations. This dynamic approach allows the system to adapt to changing security conditions while maintaining clear rules for state transitions, balancing security with legitimate access needs.
Solution Approach 2:
The patent incorporates feedback mechanisms through backoff timers and state transition tracking. When authentication fails or is pending, the system sets timers that prevent immediate re-attempts and provide feedback to the network about the current authorization state. This feedback loop helps distinguish between legitimate access attempts that need to wait and unauthorized attempts that should be blocked.
3Reliability
If re-authentication procedures are implemented for all network slices, then security is enhanced, but network performance and resource usage deteriorate
Solution Approach 1:
The patent applies re-authentication requirements selectively based on the specific network slice and its authorization state. Not all network slices require the same re-authentication treatment - authorized slices can access immediately while pending slices are subject to timer-based restrictions. This local differentiation allows security to be applied where needed without uniformly impacting all network traffic and performance.
Solution Approach 2:
The patent uses parameter changes, specifically backoff timers, to control re-authentication behavior. By adjusting timer values and state transition parameters, the system can balance security requirements with performance considerations. Longer timers provide greater security but may impact legitimate access, while shorter timers improve performance but may reduce security - the parameters can be tuned based on specific network conditions and slice requirements.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Various aspects of the present disclosure include methods, network servers or components and user equipment devices configured to authorize network slices that are associated with services provided by external providers. Various aspects enable access and use of network slices by user equipment devices connected to a network (e.g., 5G or New Radio network) via network components associated with a service provider by generating an allowed network slice selection assistance information (Allowed NSSAI) and an Unauthorized NSSAI, and sending the Allowed NSSAI and Unauthorized NSSAI to a user equipment device.