Device-Triggered 5G Slice Re-Authentication with NSSAI States

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication networks lack efficient mechanisms for handling slice-specific secondary authentication failures, leading to unauthorized access attempts and denial of service attacks due to the lack of clear standards for re-authentication and state information management between network components.

Innovation Solution

Implementing a network server and user equipment device configuration to generate and manage Unauthorized NSSAI, Pending NSSAI, and Rejected NSSAI information elements, along with slice-specific backoff timers and re-authentication procedures to handle secondary authentication failures and protect against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network slices are authorized without clear re-authentication standards, then network access is simplified, but security is compromised and denial of service attacks increase

Engineering Contradiction:
Improvenetwork securityVSAvoidre-authentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network slice authorization process into distinct states (Authorized NSSAI, Pending NSSAI, Rejected NSSAI) with specific transition conditions. Each state has defined entry and exit criteria, creating a structured state machine that manages re-authentication systematically without requiring complex ad-hoc decision logic at each network component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent establishes preliminary authorization states (Pending NSSAI) before final authorization is granted. Network slices are placed in a pending state with associated backoff timers before being fully authorized, allowing pre-processing of authentication requests and preventing immediate re-authentication attempts that could lead to denial of service attacks.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If unauthorized network slice access attempts are blocked, then network security is improved, but legitimate access attempts may be denied

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork slice access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic state transitions for network slice authorization. The same network slice can transition between Authorized, Pending, and Rejected states based on authentication outcomes and timer expirations. This dynamic approach allows the system to adapt to changing security conditions while maintaining clear rules for state transitions, balancing security with legitimate access needs.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent incorporates feedback mechanisms through backoff timers and state transition tracking. When authentication fails or is pending, the system sets timers that prevent immediate re-attempts and provide feedback to the network about the current authorization state. This feedback loop helps distinguish between legitimate access attempts that need to wait and unauthorized attempts that should be blocked.

Inventive Principle:
Principle #23Feedback

3Reliability

If re-authentication procedures are implemented for all network slices, then security is enhanced, but network performance and resource usage deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies re-authentication requirements selectively based on the specific network slice and its authorization state. Not all network slices require the same re-authentication treatment - authorized slices can access immediately while pending slices are subject to timer-based restrictions. This local differentiation allows security to be applied where needed without uniformly impacting all network traffic and performance.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses parameter changes, specifically backoff timers, to control re-authentication behavior. By adjusting timer values and state transition parameters, the system can balance security requirements with performance considerations. Longer timers provide greater security but may impact legitimate access, while shorter timers improve performance but may reduce security - the parameters can be tuned based on specific network conditions and slice requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4304224B1Systems and methods of supporting device triggered re-authentication of slice-specific secondary authentication and authorization
Publication Date: 2025.08.27 QUALCOMM INC
  • EP4304224B1 patent drawingFigure 1
  • EP4304224B1 patent drawingFigure 2
  • EP4304224B1 patent drawingFigure 3

AI summary

Various aspects of the present disclosure include methods, network servers or components and user equipment devices configured to authorize network slices that are associated with services provided by external providers. Various aspects enable access and use of network slices by user equipment devices connected to a network (e.g., 5G or New Radio network) via network components associated with a service provider by generating an allowed network slice selection assistance information (Allowed NSSAI) and an Unauthorized NSSAI, and sending the Allowed NSSAI and Unauthorized NSSAI to a user equipment device.