Core Network Access Control in Private 5G Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems struggle to efficiently manage device network capabilities in private networks, particularly in fifth-generation (5G) networks, where access control and service provisioning for user equipment (UE) are delayed due to the need for primary authentication before verifying Subscription Permanent Identifier (SUPI), leading to inefficiencies in access control procedures.
Innovation Solution
A core network apparatus (CNA) is configured to perform access control checks during initial registration and service provisioning by determining access identities and categories without waiting for primary authentication, using a core network apparatus (CNA) to manage UE capabilities and facilitate communication between user equipment and network entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If primary authentication is performed before access control checks in private networks, then security and authentication reliability are improved, but access control procedure latency and processing time increase
Solution Approach 1:
The patent applies preliminary action by performing access control checks based on SUPI and access identities before completing primary authentication. The core network device determines access identities and categories in advance, enabling access control decisions to be made during the authentication process itself rather than waiting for authentication to complete, thus reducing latency while maintaining security
Solution Approach 2:
The patent segments the authentication and access control procedures into independent stages. Access control checks are separated from the primary authentication flow, allowing them to be performed in parallel or beforehand using preliminary determination of access identities, thereby reducing the sequential dependency that causes latency
2Loss of time
If access control checks are performed during initial registration without primary authentication, then access control latency is reduced, but authentication security may be compromised
Solution Approach 1:
The core network device performs preliminary determination of access identities and categories before access control checks. This preliminary action provides the necessary authentication context upfront, enabling secure access control decisions to be made during initial registration without waiting for complete primary authentication, thus reducing latency while maintaining security
Solution Approach 2:
The patent introduces access identities as an intermediary element that bridges the gap between initial registration and primary authentication. These access identities serve as a mediator that carries authentication-relevant information, allowing access control checks to be performed securely based on this intermediate credential rather than requiring complete authentication first
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Described is an approach for managing network capabilities for a user equipment (UE). A UE can maintain subscriber data that comprises an entry index of networks for which various access modes are enabled/disabled, and a counter for each network/access mode combination. After requesting access to a network, the UE may receive a non-integrity protected rejection message that indicates the network does not allow a particular access mode. Based on the cause of access rejection, the UE can disallow the particular access mode for the network, start a timer, and increment a counter associated with the network/access mode combination. Once the timer expires, if the counter value is below a threshold the UE re-enables the particular access mode for the network, or if the counter value is at or above the threshold, the UE removes the respective entry index for the particular access mode for the network.