Core Network Secondary Authentication Management in 5G Slicing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional technologies lack effective management of secondary authentication in 5G network slicing, leading to security and operational defects in secondary authentication-based services.
Innovation Solution
A communication method where a network function entity in the core network assists the data network in performing secondary authentication with user equipment, obtaining and storing authentication results and restriction conditions, and sending them to the core network for proper management and security enhancement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secondary authentication is performed between data network and user equipment without proper management, then authentication can be completed, but security and operational effectiveness deteriorate
Solution Approach 1:
The patent introduces a core network entity as an intermediary to manage secondary authentication. This entity receives authentication results and restriction conditions from the data network, stores them, and provides them to user equipment. This mediator resolves the contradiction by centralizing management functions, improving security and reliability while maintaining operational effectiveness without requiring complex distributed management across all network elements.
2Ease of operation
If authentication results are stored without restriction conditions, then access is simplified, but unauthorized access risk increases
Solution Approach 1:
The patent applies parameter changes by introducing restriction conditions (such as validity periods, authorization levels, and service types) to authentication results. These parameters transform the authentication result from a simple pass/fail state to a structured data element with multiple attributes. This allows the system to maintain ease of operation through automated parameter checking while significantly reducing unauthorized access risk by enforcing granular control policies.
3Reliability
If secondary authentication is performed for every access request, then security is improved, but network resource utilization deteriorates
Solution Approach 1:
The patent implements preliminary action by performing secondary authentication in advance and storing the authentication results with restriction conditions in the core network. When user equipment needs to access services, the network retrieves pre-stored authentication results and checks restriction conditions, rather than performing full authentication procedures for each access request. This resolves the contradiction by maintaining high security through pre-validated authentication while improving network resource utilization by avoiding redundant authentication processes.
Data Source
AI summary
Embodiments provide a communication method and a related product. The method includes: After primary authentication between a core network and a user equipment succeeds, a network function entity in the core network assists a data network in performing secondary authentication between the data network and the user equipment if the secondary authentication further needs to be performed between the data network and the user equipment; the network function entity obtains an authentication result of the secondary authentication and a restriction condition of the secondary authentication from the data network; and the network function entity stores the authentication result and the restriction condition into the core network. The restriction condition may be introduced for the secondary authentication, to make it possible that the authentication result is properly restricted for use, and to lay a foundation for effective management of the authentication result of the secondary authentication.


