AMF Slice Authentication Flow for Pending 5G Network Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 4G/5G wireless communication systems lack efficient mechanisms for network slice-specific authentication and authorization, which is crucial for ensuring secure and optimized network resource allocation and service delivery.

Innovation Solution

Implementing a method within the Access and Mobility Management Function (AMF) to perform network slice-specific authentication and authorization (NSSAA) by receiving a NAS request message and sending an indication to the base station about pending network slices, enabling enhanced authentication and authorization processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network slice-specific authentication and authorization (NSSAA) is implemented, then security and reliability of network resource allocation is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity of network resource allocationVSAvoidcomplexity of authentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into network slice-specific authentication and authorization (NSSAA) procedures, separating slice-level security verification from general network authentication. This allows targeted security checks for each network slice while maintaining overall system security, resolving the contradiction by improving reliability through specialized authentication without proportionally increasing overall complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The AMF sends a pending indication to the base station before completing the NSSAA process, allowing the base station to prepare resources and coordinate authentication in advance. This preliminary action streamlines the authentication flow and reduces processing overhead during the actual authentication event, addressing the complexity concern while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If network slice-specific authentication and authorization (NSSAA) is performed, then service delivery optimization is improved, but processing time and loss of time increase

Engineering Contradiction:
Improveservice delivery efficiencyVSAvoidauthentication processing time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The NSSAA process is integrated into the existing registration and service request flows, allowing authentication to occur continuously alongside normal network operations rather than as a separate interruptive process. This maintains service delivery efficiency while completing necessary security verification, resolving the time loss contradiction.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

By sending pending indications and preparing authentication resources in advance, the system reduces the actual authentication processing time. The base station and AMF coordinate beforehand, allowing faster completion of NSSAA without compromising service delivery optimization.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4154566B1Network slice specific authentication and authorization
Publication Date: 2025.12.17 OFINNO LLC
  • EP4154566B1 patent drawingFigure 1
  • EP4154566B1 patent drawingFigure 2
  • EP4154566B1 patent drawingFigure 3

AI summary

An access and mobility management function (AMF) receives, from a base station, a non-access stratum (NAS) request message of a wireless device (100) indicating one or more network slices. The AMF determines to perform network slice specific authentication and authorization, NSSAA, for a first network slice of the one or more network slices. The AMF sends, to the base station, based on the determining, an indication that the first network slice is pending.