Certificate-Based Network Slice Selection for Secure Low-Overhead Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems lack efficient methods for secure network slice selection, leading to resource wastage and increased signaling and processing burdens on network entities due to the absence of secure identification methods for network slices.

Innovation Solution

Implementing a certificate-based approach for network slice selection, where a digital certificate, managed by an application service provider or mobile network operator, is used to validate and facilitate the availability of network slices for user equipment, reducing the burden on network entities and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If certificate-based network slice selection is implemented, then security is improved and resource utilization is optimized, but device complexity increases due to certificate management requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate authority (CA) as an intermediary entity that manages digital certificates for network slice selection. The CA issues, validates, and revokes certificates, thereby centralizing the complexity management. User equipment and network entities obtain certificates from the CA, eliminating the need for each device to manage its own certificate validation logic while maintaining strong security through the trusted intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary certificate issuance and validation before network slice selection. The CA pre-issues digital certificates to authorized entities, and the network validates these certificates in advance before allowing access to specific network slices. This preliminary action ensures that when network slice selection occurs, the security verification is already complete, reducing real-time processing complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If certificate validation is performed by network entities, then security is enhanced, but signaling overhead and processing burden on network entities increase

Engineering Contradiction:
ImprovesecurityVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables user equipment to perform self-validation of certificates using locally stored root certificates or validation credentials. Instead of requiring network entities to validate every certificate request, the UE autonomously verifies the certificate's validity, signature, and expiration status. This self-service approach significantly reduces signaling overhead and processing burden on network entities while maintaining enhanced security through distributed validation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements partial validation where only critical certificate attributes (validity period, signature verification, authorized network slice identification) are validated, rather than performing comprehensive certificate analysis. This partial action approach maintains essential security requirements while minimizing processing time and network entity involvement in the validation process.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12382288B2Certificate based application descriptors for network slice selection
Publication Date: 2025.08.05 QUALCOMM INC
  • US12382288B2 patent drawing
  • US12382288B2 patent drawing
  • US12382288B2 patent drawing

AI summary

Various aspects of the present disclosure generally relate to certificate based application descriptors for network slice selection. In some aspects, a user equipment (UE) may receive a first certificate associated with obtaining a network slice for executing an application. The UE may transmit, to a device, a request for the network slice with the first certificate, and receive an indication that the network slice is available to the UE for the application, based at least in part on the request. Numerous other aspects are provided.