Network Exposure Function for Secure Dynamic Slice Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G/NR network slicing technologies face security risks due to exposure of network topology and lack of control over downlink traffic levels, as service providers must share network slice selection assistance information (NSSAI) with vendors, which can compromise network security and require frequent updates.

Innovation Solution

Implementing a network exposure function (NEF) within the core network to determine service levels based on application server identifiers, enabling dynamic service-based network slicing for both uplink and downlink traffic by associating identifiers with service profiles and providing this information to security devices for controlled traffic management, thus avoiding the need to expose network topology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network slice selection assistance information (NSSAI) is shared with vendors to enable service provisioning, then service differentiation capability is improved, but network security deteriorates due to exposure of network topology

Engineering Contradiction:
Improveservice differentiation capabilityVSAvoidnetwork security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a network exposure function (NEF) as an intermediary component that sits between the network slice selection function (NSSF) and external vendors. The NEF receives service requests from vendors, determines appropriate network slices based on service requirements rather than exposing topology information, and returns service profile information. This mediator architecture enables service differentiation while protecting network security by preventing direct access to sensitive network topology data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If network topology information is exposed to vendors for service management, then service provisioning flexibility is improved, but vulnerability to security attacks increases

Engineering Contradiction:
Improveservice provisioning flexibilityVSAvoidvulnerability to security attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and separates sensitive network topology information from the service provisioning process. Instead of providing vendors with direct access to network topology and slice configuration details, the system extracts only the necessary service profile information (such as service identifiers and quality of service parameters) that vendors need to manage services. This extraction approach maintains service provisioning flexibility while removing vulnerable topology exposure.

Inventive Principle:
Principle #2Taking out (Extraction)

3Measurement precision

If frequent updates of network slice information are provided to vendors, then service accuracy is improved, but system complexity and maintenance burden increase

Engineering Contradiction:
Improveservice accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the network exposure function monitors changes in network slice configurations and automatically notifies subscribed vendors of relevant updates. Instead of requiring continuous polling or manual synchronization, the system provides targeted notifications only when changes occur that affect service profiles. This feedback approach maintains service accuracy by ensuring vendors have current information while reducing system complexity by eliminating unnecessary update cycles.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11825396B2Systems and methods for network based dynamic network slice selection control and federation
Publication Date: 2023.11.21 VERIZON PATENT & LICENSING INC
  • US11825396B2 patent drawing
  • US11825396B2 patent drawing
  • US11825396B2 patent drawing

AI summary

In some implementations, a network device may receive an identifier associated with an application server. The network device may associate the identifier with a service profile associated with a network slice based on a quality of service associated with the network slice. The network device may provide, to a device associated with the application server, information indicating that the identifier is associated with the service profile. The network device may receive address information associated with the application server. The network device may associate the address information with the service profile. The network device may provide service profile information to a security device included in a core network to cause the security device to forward traffic transmitted by the application server toward a destination via the network slice. The service profile information may include an identifier associated with the service profile, the identifier, and the address information.