Network Node Connection Restriction for Private Slice Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a 5G system, user equipment designed to connect only to a private network slice may attempt to connect to a public network slice when the private slice becomes unavailable, leading to unauthorized access and service disruptions.

Innovation Solution

A network node is configured to transmit a message to the user equipment with information restricting access to only the private network slice, preventing it from connecting to any other network slice, including a default public network, by transitioning the user equipment into a state where it is registered but not allowed to use services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If user equipment is allowed to connect to multiple network slices including public network, then network accessibility and service continuity are improved, but network security and authorization control deteriorate

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The network node applies preliminary anti-action by proactively sending a connection restriction message to the user equipment before the equipment can attempt unauthorized connection to public network slices. This message preemptively establishes a restricted state that prevents the harmful action (unauthorized access) before it can occur, while still allowing the equipment to maintain a registered state for potential future authorization.

Inventive Principle:
Principle #9Preliminary anti-action

2Productivity

If user equipment transitions to registered state with service access, then service availability is improved, but network security control worsens

Engineering Contradiction:
Improveservice availabilityVSAvoidauthorization control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The network state is segmented into two independent components: registration status and service access permission. The user equipment is placed in a registered state (maintaining productivity/service availability) while simultaneously being denied service access permission (maintaining reliability/authorization control). This segmentation allows the network to control each aspect independently through the connection restriction message.

Inventive Principle:
Principle #1Segmentation

3Duration of action of stationary object

If user equipment attempts to connect to alternative network slices, then service continuity is improved, but network security and policy compliance worsen

Engineering Contradiction:
Improveservice continuityVSAvoidpolicy violation
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The network node acts as an intermediary by sending a connection restriction message that mediates between the user equipment's desire for service continuity and the network's security policies. This intermediary message establishes a restricted registered state that allows the equipment to remain connected to the network infrastructure (maintaining service continuity potential) while blocking access to unauthorized network slices (preventing policy violations).

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12022380B2Network node and user equipment that initiate a connection
Publication Date: 2024.06.25 NTT DOCOMO INC
  • US12022380B2 patent drawing
  • US12022380B2 patent drawing
  • US12022380B2 patent drawing

AI summary

A network node includes a receiver configured to receive, from a user equipment, a message requesting an initial registration or a location registration from a user equipment; and a transmitter configured to transmit a message to the user equipment when the user equipment is disallowed to connect to any one of one or more network slices, the message allowing the initial registration or the location registration including information related to a connection restriction that causes the user equipment to transition into a state in which the user equipment is registered and the user equipment is not allowed to use a service.