Network Slice Area Restriction for Mobile Communication Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile communication networks lack mechanisms to restrict access to specific network slices in certain geographic regions based on user subscriptions and operator policies, leading to potential misuse of services like V2X or drone operations in sensitive areas.

Innovation Solution

Implementing a Network Slice Area Restriction (NESAR) mechanism that allows operators to restrict access to network slices based on user subscriptions and policies, using components like the Access and Mobility Management Function (AMF), Policy Control Function (PCF), and Network Slice Selection Function (NSSF) to provide and enforce restrictions on a per-tracking area basis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network slice access is allowed without regional restrictions, then service availability and user convenience are improved, but security and compliance with regulatory requirements deteriorate

Engineering Contradiction:
Improveservice availabilityVSAvoidsecurity and compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements region-specific access control by assigning different service availability characteristics to different geographical areas. Each region can have its own policy configuration that determines which network slices are accessible, allowing the system to maintain high service availability in permitted regions while ensuring security and compliance in restricted regions through localized policy enforcement

Inventive Principle:
Principle #3Local quality

2Reliability

If network slice access is restricted by region and subscription, then security and compliance are improved, but service availability and user convenience deteriorate

Engineering Contradiction:
Improvesecurity and complianceVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs preliminary checks of subscription data and regional policies before granting network slice access. The system proactively determines whether a user is authorized to access specific network slices in their current location by evaluating subscription information against region-specific policies in advance, preventing unauthorized access while maintaining smooth service delivery for authorized users

Inventive Principle:
Principle #10Preliminary action

3Reliability

If access control mechanisms are implemented, then security is improved, but network complexity and implementation difficulty worsen

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a policy control function as an intermediary component that manages access control logic separately from the core network slice management. This mediator handles the complexity of evaluating subscription data against regional policies, isolating the complex access control mechanisms from the main network operations and reducing overall system complexity while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3471464B1Method and apparatus for granting access to a communication service
Publication Date: 2020.04.01 NTT DOCOMO INC
  • EP3471464B1 patent drawingFigure 1
  • EP3471464B1 patent drawingFigure 2
  • EP3471464B1 patent drawingFigure 3

AI summary

According to one embodiment, a method for granting access to a communication service is described comprising receiving a request from a subscriber terminal of a mobile communication network for usage of a communication service in a specific region which the mobile communication network provides in the specific region, determining whether the subscriber terminal is allowed to use the communication service in the specific region based on a subscription of the subscriber terminal and/or based on the operator's policy and granting the subscriber terminal access to the communication service depending on whether the subscriber terminal is allowed to use the communication service in the specific region based on the subscription of the subscriber terminal and/or based on the operator's policy. Furthermore, approaches are described for configuring a specific region for the subscriber of a mobile communication network for usage of a communication service in a specific region.