Network Slice Access via Application Entitlement Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing communication systems, particularly 5G networks, face challenges in securely authenticating applications to prevent misappropriation of network slicing services, which can lead to unauthorized access and economic burdens on service providers.
Innovation Solution
An entitlement system is introduced to authenticate applications by verifying their authenticity through reference authenticity information, such as application signatures and identifiers, allowing only legitimate applications to access specific network slices without relying on Enterprise Mobility Management systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If applications are allowed to access network slices without strict authentication, then ease of operation is improved, but security and reliability deteriorate due to unauthorized access and misappropriation
Solution Approach 1:
The system performs preliminary authentication of applications before allowing network slice access. The entitlement system validates applications against a database of authorized applications and their permitted network slices in advance, preventing unauthorized access before it can occur rather than reacting to security violations afterward.
Solution Approach 2:
An entitlement system acts as an intermediary between applications and network slices. This mediator component receives authentication requests from applications, verifies them against the database of authorized applications, and controls access to network slices based on validation results, thereby securing the system without requiring changes to the applications or network slice infrastructure.
2Reliability
If traditional Enterprise Mobility Management systems are used for authentication, then security is improved, but device complexity and resource consumption increase
Solution Approach 1:
The authentication functionality is extracted from the User Equipment (UE) and relocated to a separate entitlement system. The UE only needs to present application identifiers to the entitlement system, which handles the complex authentication logic and database queries. This extraction eliminates the need for complex EMM systems in mobile devices while maintaining security.
Solution Approach 2:
The entitlement system autonomously performs authentication by automatically querying its internal database of authorized applications and comparing presented application identifiers against stored credentials. The system self-manages the authentication process without requiring external EMM infrastructure or complex device-side authentication mechanisms.
Data Source
AI summary
Examples described herein relate to techniques for routing application data through a selected network slice based on validation of an application entitlement request. In some examples, an entitlement system may receive an application entitlement request corresponding to an application that is on a user equipment. The entitlement system may validate the authenticity of the application based on the application authenticity information from the entitlement request. The entitlement device may in response to validation of the application entitlement request, send an application entitlement response to the user equipment such that the user equipment selects a network slice to route application data corresponding to the application.


