Core Network Slice-Specific Security Parameter Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G network authentication processes fail to meet varying security requirements across different network slices, as they use a common security parameter for all slices, which cannot satisfy the unique security needs of each slice.

Innovation Solution

A core network device, access network device, and communication terminal that store and transmit specific security parameters associated with each network slice, allowing for tailored security processes by identifying and using slice-specific security profiles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a common security parameter is used for all network slices, then the authentication process is simplified and can be completed quickly, but the security requirements of individual network slices cannot be satisfied

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidsecurity requirement satisfaction
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the security parameter configuration by introducing network slice-specific security parameters. Each network slice is assigned dedicated security parameters (e.g., authentication algorithms, key lengths, security policies) that can be independently configured and managed, allowing different security levels for different slices while maintaining a unified authentication framework

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by allowing each network slice to have customized security parameters tailored to its specific requirements. For example, slices requiring higher security can use stronger encryption algorithms and longer key lengths, while slices prioritizing speed can use lighter algorithms, thereby optimizing security performance locally for each slice without affecting others

Inventive Principle:
Principle #3Local quality

2Reliability

If slice-specific security parameters are implemented, then the security requirements of each network slice can be satisfied, but the device complexity and parameter management burden increase

Engineering Contradiction:
Improvesecurity requirement satisfactionVSAvoidparameter management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the AMF (Access and Mobility Management Function) as an intermediary that centralizes the management and distribution of security parameters. The AMF receives security parameter configurations from the PCF (Policy Control Function) and distributes appropriate parameters to the UE and network elements, thereby simplifying the complexity for individual devices while enabling comprehensive slice-specific security management at the system level

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal security parameter management architecture where the PCF and AMF serve multiple functions: they manage security parameters for all network slices, handle authentication for different slice types, and provide policy control across the entire network. This multi-functional approach reduces the need for separate dedicated systems for each slice, thereby managing complexity through consolidation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12160740B2Core network device, access network device, communication terminal, communication system, and communication method
Publication Date: 2024.12.03 NEC CORP
  • US12160740B2 patent drawing
  • US12160740B2 patent drawing
  • US12160740B2 patent drawing

AI summary

It is an object to provide a core network device that can satisfy security requirements required for respective network slices. A core network device (10) according to the present disclosure includes a storage unit (11) configured to store a security parameter associated with a network slice allowing a communication terminal. The core network device (10) further includes a communication unit (12) configured to transmit identification information on the network slice, and identification information on the security parameter to the communication terminal.