Application-Based Access Control for Network Slicing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control methods in wireless networks operate at a per-device or per-subscriber level, leading to inefficient resource utilization and congestion issues, as they do not differentiate between applications running on an end device, potentially allowing high-priority applications to be barred from accessing a congested radio access network.
Innovation Solution
An application-based access control service that assigns network slice priority levels to applications or portions of applications, transmitting this information to end devices, allowing network devices to control access based on congestion levels by granting or barring access to specific network slices, thereby optimizing resource utilization and quality of service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access control is implemented at per-device or per-subscriber level, then device-level access management is simplified, but application-level resource utilization efficiency deteriorates and congestion issues arise
Solution Approach 1:
The patent segments access control from device level to application level by introducing per-application access control mechanisms. The system divides the access control granularity into individual applications running on end devices, allowing each application to be evaluated independently for network access based on its own characteristics and requirements, thereby resolving the contradiction between management simplicity and resource utilization efficiency
Solution Approach 2:
The patent adds a new dimension of control by introducing application-level awareness into the access control architecture. Instead of controlling access only at the device level, the system now operates at the application layer, enabling differentiated access policies for different applications based on their priority, resource requirements, and network conditions, thus improving resource utilization while maintaining manageable control through standardized application identification mechanisms
2Device complexity
If per-device access control is used, then implementation complexity is reduced, but quality of service for prioritized applications deteriorates
Solution Approach 1:
The patent applies preliminary action by pre-configuring application identification mechanisms and access control policies before network congestion occurs. The system pre-establishes application profiles, priority levels, and access control rules that are automatically applied when access decisions are needed, thereby maintaining simple implementation while ensuring quality of service for prioritized applications through advance preparation
Solution Approach 2:
The patent implements feedback mechanisms that monitor application performance, network conditions, and access control effectiveness. This feedback loop enables the system to dynamically adjust access decisions based on real-time conditions while maintaining the simplicity of per-device control architecture, thereby improving quality of service for prioritized applications without significantly increasing implementation complexity
3Productivity
If application-based access control is implemented, then resource utilization efficiency is improved, but network device complexity increases
Solution Approach 1:
The patent applies universality by designing a multi-functional access control framework that can handle multiple applications and scenarios through a single unified mechanism. The system uses universal application identification and classification tools that work across different application types, allowing network devices to manage diverse access control requirements through standardized procedures, thereby improving resource utilization without proportionally increasing device complexity
Solution Approach 2:
The patent introduces intermediary components such as application identification functions and access control decision engines that mediate between the complex application-level requirements and the network device's access control capabilities. These intermediaries simplify the interaction between applications and network infrastructure, enabling improved resource utilization efficiency while keeping network device complexity manageable through modular design
4Stability of the object's composition
If congestion control bars all applications during high load, then network stability is maintained, but productivity of legitimate applications deteriorates
Solution Approach 1:
The patent applies local quality by implementing differentiated access control policies for different applications based on their individual characteristics, priority levels, and network conditions. Instead of uniform blocking during congestion, the system applies localized quality control that allows high-priority applications to maintain access while restricting lower-priority applications, thereby maintaining network stability without completely blocking legitimate application traffic
Solution Approach 2:
The patent implements dynamic access control that adapts congestion control strategies in real-time based on network conditions and application requirements. The system dynamically adjusts access decisions, priority levels, and resource allocation during congestion events, allowing network stability to be maintained while preserving productivity for legitimate applications through flexible, condition-based control rather than static blocking
Data Source
AI summary
A method, a device, and a non-transitory storage medium are described in which an application-based access control service is provided. The service assigns network slice priority values to network slices that are associated with an application or a portion of an application pertaining to end devices. The service calculates a network slice priority value to manage access barring based on a congestion level, and transmits the network slice priority value to end devices. End devices may determine whether access is permitted or not based on the network slice priority value and the assigned network slice priority values associated with the network slices. The service further provides access barring information to network devices of an access network that allows the network devices to reject connection requests and release existing connections. The access barring information may include a network slice priority value and/or network slice identifiers.


