Network Node Connection Restriction for Private Slice Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a 5G system, user equipment designed to connect only to a private network slice may attempt to connect to a public network slice when the private slice becomes unavailable, leading to unauthorized access and service disruptions.
Innovation Solution
A network node is configured to transmit a message to the user equipment with information restricting access to only the private network slice, preventing it from connecting to any other network slice, including a default public network, by transitioning the user equipment into a state where it is registered but not allowed to use services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If user equipment is allowed to connect to multiple network slices including public network, then network accessibility and service continuity are improved, but network security and authorization control deteriorate
Solution Approach 1:
The network node applies preliminary anti-action by proactively sending a connection restriction message to the user equipment before the equipment can attempt unauthorized connection to public network slices. This message preemptively establishes a restricted state that prevents the harmful action (unauthorized access) before it can occur, while still allowing the equipment to maintain a registered state for potential future authorization.
2Productivity
If user equipment transitions to registered state with service access, then service availability is improved, but network security control worsens
Solution Approach 1:
The network state is segmented into two independent components: registration status and service access permission. The user equipment is placed in a registered state (maintaining productivity/service availability) while simultaneously being denied service access permission (maintaining reliability/authorization control). This segmentation allows the network to control each aspect independently through the connection restriction message.
3Duration of action of stationary object
If user equipment attempts to connect to alternative network slices, then service continuity is improved, but network security and policy compliance worsen
Solution Approach 1:
The network node acts as an intermediary by sending a connection restriction message that mediates between the user equipment's desire for service continuity and the network's security policies. This intermediary message establishes a restricted registered state that allows the equipment to remain connected to the network infrastructure (maintaining service continuity potential) while blocking access to unauthorized network slices (preventing policy violations).
Data Source
AI summary
A network node includes a receiver configured to receive, from a user equipment, a message requesting an initial registration or a location registration from a user equipment; and a transmitter configured to transmit a message to the user equipment when the user equipment is disallowed to connect to any one of one or more network slices, the message allowing the initial registration or the location registration including information related to a connection restriction that causes the user equipment to transition into a state in which the user equipment is registered and the user equipment is not allowed to use a service.


