Core Network Node NSSAA Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G networks, when a core network node is not compatible with the network slice-specific authentication and authorization (NSSAA) feature, the NSSAA procedure is not properly interpreted, leading to unauthorized access to network slices by user equipment (UE) even if the UE supports the NSSAA feature.
Innovation Solution
Implementing a mechanism where core network nodes can determine and communicate support for the NSSAA feature, ensuring that only compatible network slices are accessed by transmitting specific information about supported NSSAA features and associated network slices to the UE.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the core network node does not support the NSSAA feature, then the network slice access is simplified and more devices can connect, but unauthorized access to network slices occurs and security is compromised
Solution Approach 1:
The patent introduces an intermediary mechanism (the determination unit and information transmission unit) that mediates between the NSSAA feature support status and network slice access control. The core network node acts as an intermediary that determines whether to permit access based on the UE's NSSAA capability and the network slice's requirements, preventing unauthorized access while maintaining compatibility with both NSSAA-supported and non-NSSAA-supported UEs
Solution Approach 2:
The patent changes the parameter of access permission based on the NSSAA feature support status. When a UE indicates it supports NSSAA, the core network node changes the access parameter to require NSSAA procedure completion. When the UE does not support NSSAA, the access parameter remains permissive. This dynamic parameter change resolves the contradiction by adapting access control to the specific capabilities of each UE
2Ease of operation
If the core network node permits access without determining NSSAA necessity, then device compatibility is improved, but the NSSAA procedure cannot be properly performed
Solution Approach 1:
The patent applies preliminary action by determining whether the NSSAA procedure is necessary before permitting network slice access. The core network node performs this determination based on the UE's indicated NSSAA support capability and the network slice's requirements. This preliminary check ensures that when access is permitted, the appropriate NSSAA procedure will be executed, maintaining both ease of operation and procedural reliability
3Reliability
If the core network node interprets NSSAA commands, then security control is improved, but processing complexity increases
Solution Approach 1:
The patent applies local quality by implementing NSSAA command interpretation capability only where necessary - specifically in core network nodes that need to control network slice access for UEs supporting NSSAA. Not all core network nodes need this complex interpretation capability, only those positioned to make access determination decisions. This localized implementation maintains security control while minimizing overall system complexity
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An object is to provide an access mobility management apparatus capable of appropriately determining whether access to a network slice is enabled. An access mobility management apparatus (10) according to the present disclosure includes: a communication unit (11) configured to transmit, to a core network node (15), first information indicating whether a network slice-specific authentication and authorization (NSSAA) feature is supported, and receive, from the core network node (15), second information related to a network slice being associated with the first information; and a control unit (12) configured to determine whether to permit a wireless terminal to use a network slice, based on the second information.