Core Network Slice Authentication With Permission-Based Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of network slices accessed by a UE leads to increased time and processing load for secondary authentication during registration, as each slice requires separate authentication processing.
Innovation Solution
A core network device performs first authentication to determine registration eligibility, receives permission list information for usable network slices, and conducts secondary authentication only for slices within this list, reducing redundant processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secondary authentication is performed for each network slice during registration processing, then network slice access control is ensured, but time and processing load increase as the number of network slices increases
Solution Approach 1:
The patent applies preliminary action by performing secondary authentication during the registration processing phase, before the UE actually accesses network slices. The AMF receives permission list information from the UDM indicating which network slices the UE is authorized to access, and performs secondary authentication for each slice in the permission list during registration. This preliminary authentication approach ensures that when the UE later accesses a network slice, the authentication has already been completed, avoiding redundant authentication operations and reducing access time.
Solution Approach 2:
The patent applies segmentation by dividing the secondary authentication process into slice-specific segments. Instead of performing a single bulk authentication, the system performs separate secondary authentication for each network slice listed in the permission list information. The AMF processes each slice individually, receiving and evaluating permission list information that contains multiple network slice identifiers, and performs authentication operations segmented by slice. This segmentation allows for precise control and tracking of authentication status for each slice.
2Reliability
If secondary authentication is performed for each network slice during registration processing, then network slice access control is ensured, but processing load increases as the number of network slices increases
Solution Approach 1:
The patent reduces processing load during actual network slice access by performing secondary authentication in advance during registration processing. The AMF proactively authenticates the UE for each network slice in the permission list before the UE needs to access those slices. This preliminary action shifts the processing burden to the registration phase, where the authentication results can be cached and reused, significantly reducing the processing load during subsequent network slice access operations.
Solution Approach 2:
The patent applies copying by having the UDM generate and provide permission list information that contains authentication-related data for multiple network slices. The AMF receives this permission list information, which essentially copies the necessary authentication credentials and authorization data for each slice, and uses this copied information to perform secondary authentication without needing to query the UDM or other authentication servers repeatedly during actual slice access.
3Reliability
If secondary authentication is performed for all network slices in subscriber information, then comprehensive access control is achieved, but time required until UE performs communication increases
Solution Approach 1:
The patent applies the taking out principle by extracting only the network slices that are actually permitted for the UE from the complete subscriber information. The UDM generates permission list information that selectively extracts and lists only those network slices from the UE's subscriber information for which the UE has been authorized. The AMF then performs secondary authentication only for these extracted slices in the permission list, rather than for all slices in the subscriber information. This extraction approach maintains comprehensive access control for authorized slices while reducing the number of authentication operations.
Solution Approach 2:
The patent performs secondary authentication as a preliminary action during registration processing, before the UE initiates actual communication. By completing the authentication for all permitted network slices in advance during registration, the system ensures that when the UE needs to access a network slice, the authentication is already complete. This preliminary authentication eliminates delays that would occur if authentication were performed at the time of each network slice access, thereby reducing the time until communication can begin.
Data Source
AI summary
An object is to provide a core network device being able to efficiently perform secondary authentication to be performed for each network slice. A core network device (10) according to the present disclosure includes an authentication unit (11) configured to perform, during registration processing of registering a communication terminal in a core network, first authentication processing of determining whether the communication terminal is a communication terminal permitted to be registered in the core network, a communication unit (13) configured to receive permission list information indicating at least one network slice usable by the communication terminal in a serving network, and an authentication unit (12) configured to perform, during registration processing of registering the communication terminal in the core network, second authentication processing of determining whether the communication terminal is a communication terminal permitted to use a network slice included in the permission list information.


