Core Network Node NSSAA Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks, when a core network node is not compatible with the network slice-specific authentication and authorization (NSSAA) feature, the NSSAA procedure is not properly interpreted, leading to unauthorized access to network slices by user equipment (UE) even if the UE supports the NSSAA feature.

Innovation Solution

Implementing a mechanism where core network nodes can determine and communicate support for the NSSAA feature, ensuring that only compatible network slices are accessed by transmitting specific information about supported NSSAA features and associated network slices to the UE.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the core network node does not support the NSSAA feature, then the network slice access is simplified and more devices can connect, but unauthorized access to network slices occurs and security is compromised

Engineering Contradiction:
Improvenetwork slice access compatibilityVSAvoidunauthorized access prevention
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism (the determination unit and information transmission unit) that mediates between the NSSAA feature support status and network slice access control. The core network node acts as an intermediary that determines whether to permit access based on the UE's NSSAA capability and the network slice's requirements, preventing unauthorized access while maintaining compatibility with both NSSAA-supported and non-NSSAA-supported UEs

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of access permission based on the NSSAA feature support status. When a UE indicates it supports NSSAA, the core network node changes the access parameter to require NSSAA procedure completion. When the UE does not support NSSAA, the access parameter remains permissive. This dynamic parameter change resolves the contradiction by adapting access control to the specific capabilities of each UE

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the core network node permits access without determining NSSAA necessity, then device compatibility is improved, but the NSSAA procedure cannot be properly performed

Engineering Contradiction:
Improveaccess permission processingVSAvoidNSSAA procedure execution
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by determining whether the NSSAA procedure is necessary before permitting network slice access. The core network node performs this determination based on the UE's indicated NSSAA support capability and the network slice's requirements. This preliminary check ensures that when access is permitted, the appropriate NSSAA procedure will be executed, maintaining both ease of operation and procedural reliability

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the core network node interprets NSSAA commands, then security control is improved, but processing complexity increases

Engineering Contradiction:
ImproveNSSAA procedure controlVSAvoidcommand interpretation capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by implementing NSSAA command interpretation capability only where necessary - specifically in core network nodes that need to control network slice access for UEs supporting NSSAA. Not all core network nodes need this complex interpretation capability, only those positioned to make access determination decisions. This localized implementation maintains security control while minimizing overall system complexity

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3993470B1Core network node, accessibility management device, and communication method
Publication Date: 2024.01.03 NEC CORP
  • EP3993470B1 patent drawingFigure 1
  • EP3993470B1 patent drawingFigure 2
  • EP3993470B1 patent drawingFigure 3

AI summary

An object is to provide an access mobility management apparatus capable of appropriately determining whether access to a network slice is enabled. An access mobility management apparatus (10) according to the present disclosure includes: a communication unit (11) configured to transmit, to a core network node (15), first information indicating whether a network slice-specific authentication and authorization (NSSAA) feature is supported, and receive, from the core network node (15), second information related to a network slice being associated with the first information; and a control unit (12) configured to determine whether to permit a wireless terminal to use a network slice, based on the second information.