Core Network Secondary Authentication Management in 5G Slicing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional technologies lack effective management of secondary authentication in 5G network slicing, leading to security and operational defects in secondary authentication-based services.

Innovation Solution

A communication method where a network function entity in the core network assists the data network in performing secondary authentication with user equipment, obtaining and storing authentication results and restriction conditions, and sending them to the core network for proper management and security enhancement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secondary authentication is performed between data network and user equipment without proper management, then authentication can be completed, but security and operational effectiveness deteriorate

Engineering Contradiction:
Improvesecurity and operational effectivenessVSAvoidauthentication management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a core network entity as an intermediary to manage secondary authentication. This entity receives authentication results and restriction conditions from the data network, stores them, and provides them to user equipment. This mediator resolves the contradiction by centralizing management functions, improving security and reliability while maintaining operational effectiveness without requiring complex distributed management across all network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication results are stored without restriction conditions, then access is simplified, but unauthorized access risk increases

Engineering Contradiction:
Improveaccess simplicityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies parameter changes by introducing restriction conditions (such as validity periods, authorization levels, and service types) to authentication results. These parameters transform the authentication result from a simple pass/fail state to a structured data element with multiple attributes. This allows the system to maintain ease of operation through automated parameter checking while significantly reducing unauthorized access risk by enforcing granular control policies.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If secondary authentication is performed for every access request, then security is improved, but network resource utilization deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork resource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by performing secondary authentication in advance and storing the authentication results with restriction conditions in the core network. When user equipment needs to access services, the network retrieves pre-stored authentication results and checks restriction conditions, rather than performing full authentication procedures for each access request. This resolves the contradiction by maintaining high security through pre-validated authentication while improving network resource utilization by avoiding redundant authentication processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12114154B2Communication method and related device
Publication Date: 2024.10.08 HUAWEI TECH CO LTD
  • US12114154B2 patent drawing
  • US12114154B2 patent drawing
  • US12114154B2 patent drawing

AI summary

Embodiments provide a communication method and a related product. The method includes: After primary authentication between a core network and a user equipment succeeds, a network function entity in the core network assists a data network in performing secondary authentication between the data network and the user equipment if the secondary authentication further needs to be performed between the data network and the user equipment; the network function entity obtains an authentication result of the secondary authentication and a restriction condition of the secondary authentication from the data network; and the network function entity stores the authentication result and the restriction condition into the core network. The restriction condition may be introduced for the secondary authentication, to make it possible that the authentication result is properly restricted for use, and to lay a foundation for effective management of the authentication result of the secondary authentication.