Application Function Brokerage for Per-Application Network Slice Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G network slicing standards do not adequately address per-application authentication and authorization for accessing network slices, leading to inefficiencies and challenges in managing network resources and user equipment behavior in varying locations.

Innovation Solution

Implementing per-application authentication and authorization (PAAA) mechanisms, enhanced S-NSSAIs with PAAA indicators, and utilizing consolidated temporal and spatial information to efficiently manage network slice access and redirect user equipment to authorized network slices, along with mechanisms for power saving and state management of applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If per-application authentication and authorization mechanisms are implemented, then network slice access security and resource allocation efficiency are improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvenetwork slice access securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an Application Function (AF) as an intermediary component that acts as a broker between applications and the network slice selection function. The AF receives application descriptors from applications, performs authentication and authorization, and interacts with the network to establish appropriate PDU sessions. This intermediary approach centralizes the complexity of per-application authentication while keeping the application and network components relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the network slice selection process into distinct functional components: application descriptor generation at the application level, AF-level authentication and authorization, network slice selection function processing, and PDU session establishment. This segmentation allows each component to handle specific tasks independently, making the overall complex system manageable through modular design.

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If per-application authentication and authorization is performed for all applications, then network resource allocation precision is improved, but processing time and operational overhead increase

Engineering Contradiction:
Improvenetwork resource allocation precisionVSAvoidprocessing time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent implements partial authentication and authorization by applying PAAA only to applications that require network slice access, rather than all applications uniformly. The AF determines on a per-application basis whether authentication is needed based on the application descriptor and network slice requirements. This selective approach reduces overall processing time while maintaining precision where necessary.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs authentication and authorization actions in advance during application registration and PDU session establishment phases. The AF authenticates applications beforehand before they attempt to access network slices, and pre-establishes appropriate PDU sessions with proper QoS parameters. This preliminary action prevents last-minute processing delays during actual data transmission.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If applications are restricted to authorized network slices only, then network security and resource isolation are improved, but application functionality and user experience may deteriorate

Engineering Contradiction:
Improvenetwork securityVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic network slice allocation where applications are assigned to network slices based on their specific requirements, current network conditions, and authorization status. The AF can dynamically adjust PDU session parameters, QoS settings, and slice selections in real-time. This dynamic approach allows applications to access appropriate network slices when authorized while maintaining security isolation, preventing the rigid restrictions that would harm functionality.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different authentication and authorization levels to different applications and network slices based on local requirements. Not all applications require the same level of authentication, and not all network slices have the same security requirements. The AF tailors the authentication process and slice allocation to each specific application-slice pair, providing appropriate security without unnecessary restrictions that would limit application functionality.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12432679B2Application interaction for network slicing
Publication Date: 2025.09.30 INTERDIGITAL PATENT HOLDINGS INC
  • US12432679B2 patent drawing
  • US12432679B2 patent drawing
  • US12432679B2 patent drawing

AI summary

Methods, apparatus, and systems are described for improved application interaction for network slicing. A wireless transmit/receive unit may send, to a network node, a registration request including an indication that the WTRU is capable of receiving information associated with a temporal availability of a network slice. The WTRU may receive a registration response including the information associated with the temporal availability of the network slice. The WTRU may determine, based on the temporal availability of the network slice, to stop use of a protocol data unit (PDU) session associated with the network slice.