Network Slice Access Control for Dual-System 5G Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions fail to implement network slice grading for dual-system or multi-system environments without interfering between network slices, particularly in 5G network slicing technology, especially for dual-system Android devices where one system can only access certain slice levels.
Innovation Solution
A method and apparatus for network slice connection that distinguishes between different systems using unique user identities (UIDs) and slice traffic descriptors, determining allowable slice levels, and establishing connections based on these identities to ensure non-interference and secure data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a dual-system Android device shares a SIM card between working system and living system, then device resource utilization is improved, but network slice access security deteriorates because the living system cannot access high-security L3/L4 slices
Solution Approach 1:
The patent segments the network slice access rights by creating separate UID-based access control lists for different systems. The working system and living system are divided into distinct access domains, each with its own authorized slice levels, preventing unauthorized cross-access while maintaining shared SIM card functionality
Solution Approach 2:
The patent introduces an intermediary access control mechanism that mediates between the living system and high-security slices. This intermediary layer validates system identity and slice level permissions, allowing the working system to access L3/L4 slices while blocking the living system from doing so, thus securing access without preventing legitimate usage
2Reliability
If network slice grading is implemented for dual-system devices, then network security and slice isolation are improved, but system complexity increases due to the need for separate slice management
Solution Approach 1:
The patent creates a universal slice access control framework that handles multiple systems through a single unified mechanism. The access control list and UID-based authentication work across both working and living systems, providing slice isolation without requiring separate management infrastructure for each system
Solution Approach 2:
The system automatically determines the current system identity and enforces appropriate slice access permissions without manual intervention. The access control mechanism self-manages slice level verification and UID validation, reducing the operational burden of slice grading implementation
3Extent of automation
If URSP rules are configured for 5G network slicing, then automated route selection is improved, but dual-system compatibility deteriorates because existing URSP rules do not account for multiple systems sharing a device
Solution Approach 1:
The patent applies local quality by associating different URSP rule sets with different system contexts. Each system (working and living) has its own configured URSP rules tailored to its specific network slice requirements, allowing automated route selection to function correctly within each system while maintaining dual-system compatibility
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the present application relate to the technical field of communications, and provide a network slice connection method and apparatus, a storage medium, and an electronic apparatus. The method comprises: obtaining a network slice activation request of an application, the network slice activation request carrying an application user identity (UID) and a slice traffic descriptor identity; according to the UID, determining a system to which the application belongs, and obtaining a target application package name corresponding to the UID from the system to which the application belongs; determining a first slice level range which corresponds to the target application package name and which is allowed to be used by the application; and establishing a network slice connection with the first slice level range according to the slice traffic descriptor identity.