Network Slice Admission Control via Segmented NSSAA and NSAC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication networks face challenges in network slice admission control, particularly when an access and mobility management function does not support network slice admission control, leading to issues with registration and authentication processes.
Innovation Solution
The implementation of methods and apparatuses that perform network slice specific secondary authentication and authorization (NSSAA) and network slice admission control (NSAC), including receiving registration requests, transmitting registration accept messages with pending network slice selection assistance information, and initiating NSSAA procedures, as well as determining availability checks for network slice admission control across different network functions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network slice admission control is implemented, then network slice management reliability is improved, but device complexity increases
Solution Approach 1:
The patent segments network slice admission control into two distinct phases: (1) network slice specific secondary authentication and authorization (NSSAA) during registration, and (2) network slice admission control (NSAC) availability checks during PDU session establishment. This segmentation allows each phase to be handled by appropriate network functions, reducing overall system complexity while maintaining reliability.
Solution Approach 2:
The patent introduces an intermediary mechanism where the AMF acts as a mediator between the UE and the network slice admission control system. The AMF performs NSSAA and coordinates with other network functions for NSAC, enabling slice admission control without requiring direct complex interactions between all network components.
2Ease of operation
If registration procedure is performed with pending NSSAI, then user equipment mobility is improved, but registration process time increases
Solution Approach 1:
The patent implements preliminary action by performing network slice specific secondary authentication and authorization (NSSAA) during the registration procedure, before the UE actually needs to access network slices. The pending NSSAI is prepared in advance and stored, so when the UE needs to establish PDU sessions, the authentication is already complete, reducing access latency.
Solution Approach 2:
The patent introduces dynamic state management for network slice admission control through the pending NSSAI mechanism. The network slice admission control status transitions dynamically between registered, pending authentication, and rejected states, allowing the system to adapt to different UE scenarios and optimize both mobility and timing.
3Reliability
If network slice specific secondary authentication is performed, then network security is improved, but authentication process complexity increases
Solution Approach 1:
The patent implements a universal authentication framework where the AMF performs network slice specific secondary authentication (NSSAA) for multiple network slices using a standardized procedure. The same authentication mechanism serves multiple slices and multiple UEs, reducing the need for slice-specific authentication implementations and thereby reducing overall complexity while maintaining security.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for network slice admission control. One method includes receiving, at a first network function (NF), a registration request message including a registration request for a network slice. The network slice is subject to network slice specific secondary authentication and authorization (NSSAA) and network slice admission control. The method includes determining to perform a registration procedure by transmitting a registration accept message to a user equipment (UE). The registration accept message includes pending network slice selection assistance information (NSSAI) including a network slice identity corresponding to the network slice. The method includes transmitting information initiating the NSSAA procedure to the user equipment. The method includes, in response to the NSSAA procedure being successful, transmitting an availability check message for network slice admission control to a second NF.


