Network Slice Access via Application Entitlement Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication systems, particularly 5G networks, face challenges in securely authenticating applications to prevent misappropriation of network slicing services, which can lead to unauthorized access and economic burdens on service providers.

Innovation Solution

An entitlement system is introduced to authenticate applications by verifying their authenticity through reference authenticity information, such as application signatures and identifiers, allowing only legitimate applications to access specific network slices without relying on Enterprise Mobility Management systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications are allowed to access network slices without strict authentication, then ease of operation is improved, but security and reliability deteriorate due to unauthorized access and misappropriation

Engineering Contradiction:
Improveapplication access to network sliceVSAvoidnetwork slice security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication of applications before allowing network slice access. The entitlement system validates applications against a database of authorized applications and their permitted network slices in advance, preventing unauthorized access before it can occur rather than reacting to security violations afterward.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An entitlement system acts as an intermediary between applications and network slices. This mediator component receives authentication requests from applications, verifies them against the database of authorized applications, and controls access to network slices based on validation results, thereby securing the system without requiring changes to the applications or network slice infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional Enterprise Mobility Management systems are used for authentication, then security is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication functionality is extracted from the User Equipment (UE) and relocated to a separate entitlement system. The UE only needs to present application identifiers to the entitlement system, which handles the complex authentication logic and database queries. This extraction eliminates the need for complex EMM systems in mobile devices while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The entitlement system autonomously performs authentication by automatically querying its internal database of authorized applications and comparing presented application identifiers against stored credentials. The system self-manages the authentication process without requiring external EMM infrastructure or complex device-side authentication mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12317074B2Validating authenticity of an application accessing a network slice
Publication Date: 2025.05.27 HCL TECH LTD
  • US12317074B2 patent drawing
  • US12317074B2 patent drawing
  • US12317074B2 patent drawing

AI summary

Examples described herein relate to techniques for routing application data through a selected network slice based on validation of an application entitlement request. In some examples, an entitlement system may receive an application entitlement request corresponding to an application that is on a user equipment. The entitlement system may validate the authenticity of the application based on the application authenticity information from the entitlement request. The entitlement device may in response to validation of the application entitlement request, send an application entitlement response to the user equipment such that the user equipment selects a network slice to route application data corresponding to the application.