Network Slice Access Control for IoT Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network connection methods in IoT environments, particularly in 5G communication systems, face challenges in efficiently managing network access and security between terminals and base stations, especially when transitioning between public and private networks.

Innovation Solution

A network connection method and apparatus that allows terminals to obtain and access allowed network slices by detecting network information and identifying with gate devices, ensuring secure access through identification verification and network slice allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network access is allowed for all terminals in IoT environments, then network coverage and service availability are improved, but network security and access control management deteriorate

Engineering Contradiction:
Improvenetwork coverageVSAvoidnetwork security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The network is segmented into multiple network slices, each with specific security policies and access controls. Terminals are assigned to specific slices based on their identity and authorization, allowing differentiated security management while maintaining broad network coverage across multiple slices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security levels and access control mechanisms are applied to different network slices based on local requirements. Each slice can have customized security parameters, enabling tailored security management for specific services or terminal types while maintaining overall network security.

Inventive Principle:
Principle #3Local quality

2Reliability

If network slice allocation is restricted to authorized terminals only, then network security is improved, but network access efficiency and connection speed worsen

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Network slice authorization and allocation are performed in advance during terminal registration and network entry procedures. The base station pre-determines which network slices a terminal can access based on identity verification and authorization information, so that subsequent data transmission can proceed efficiently without repeated security checks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal itself carries authorization information (such as S-TMSI) that enables the base station to quickly determine network slice access rights without complex real-time authentication. This self-identifying mechanism streamlines the access process while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If identification verification procedures are performed for every network access request, then network security is improved, but network latency and processing time worsen

Engineering Contradiction:
Improveaccess control securityVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Identification verification is performed once during terminal registration and network entry, with the authorization results cached in the base station. Subsequent network access requests within the same network slice can proceed without repeated full authentication, significantly reducing latency while maintaining security through the pre-verified authorization information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11272552B2Network connection method and apparatus
Publication Date: 2022.03.08 SAMSUNG ELECTRONICS CO LTD
  • US11272552B2 patent drawing
  • US11272552B2 patent drawing
  • US11272552B2 patent drawing

AI summary

A network connection method and apparatus are provided. The network connection method includes obtaining information about at least one network to be accessed by the terminal, obtaining information about a network slice allowed for the terminal from among network slices included in the at least one network, and based on a network corresponding to the information about the at least one network being detected, accessing the allowed network slice of the detected network based on the information about the allowed network slice.