Selective Network Slice Authentication Skipping Signaling Overhead
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network slicing architectures in 3GPP mobile networks, such as 5G, result in excessive signaling between user equipment and the mobile core network, consuming network and radio resources due to the need for separate authentication and authorization procedures for each network slice.
Innovation Solution
Implementing selective network slice authentication and authorization techniques, where successful authentication with one network slice allows skipping of authentication for other slices, using network slice mapping policies to reduce signaling and optimize resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate authentication and authorization procedures are performed for each network slice, then security and authorization control are improved, but signaling overhead and resource consumption increase
Solution Approach 1:
The patent combines multiple authentication and authorization procedures into a single unified process. When a user equipment requests access to multiple network slices, the system performs one authentication and one authorization check that validates access to all requested slices simultaneously, rather than repeating the process for each slice individually. This merging eliminates redundant signaling while maintaining security control.
Solution Approach 2:
The authorization mechanism is designed to be universal across multiple network slices. A single authorization decision can grant or deny access to multiple slices at once, making the authorization function multi-functional. The system evaluates the user's credentials and service requirements once, then applies the authorization outcome to all requested slices, reducing the need for slice-specific authorization procedures.
2Reliability
If authentication is performed for multiple network slices, then access control security is improved, but processing time and network resource usage increase
Solution Approach 1:
The system performs preliminary evaluation of the user equipment's authentication credentials and service requirements before initiating separate authentication procedures for each network slice. By pre-assessing the user's authorization level and service entitlements, the system can determine upfront which slices the user is authorized to access, eliminating the need for time-consuming sequential authentication processes for each slice.
Solution Approach 2:
Multiple authentication and authorization operations are merged into a single consolidated process. Instead of executing authentication sequentially for each network slice, the system combines these operations into one unified authentication and authorization check that validates access to all requested slices simultaneously, significantly reducing total processing time.
3Adaptability or versatility
If separate authorization procedures are conducted for each network slice, then service-specific control is improved, but configuration complexity and signaling load increase
Solution Approach 1:
The authorization system uses a universal evaluation framework that can handle multiple service-specific requirements through a single process. Rather than implementing separate configuration sets for each slice, the system evaluates user credentials, service requirements, and network policies universally, then applies the authorization outcome appropriately to each requested slice based on its specific service characteristics.
Solution Approach 2:
While maintaining a unified authorization process, the system segments the evaluation criteria to accommodate different service requirements. The authorization mechanism evaluates each network slice's specific service requirements independently within the overall authorization framework, allowing service-specific control without requiring separate authorization procedures. This segmentation occurs in the evaluation logic rather than in the procedural structure.
Data Source
AI summary
Presented herein are techniques to provide selective network slice authentication and authorization in a mobile network environment. In one example, a method may include obtaining, by an access management element of a mobile network, a registration request from a user equipment, wherein the registration request identifies a plurality of network slices with which the user equipment seeks authentication; determining that if authentication for the user equipment with a first network slice is successful, authentication for the user equipment with one or more other network slices can be skipped; and upon successful authentication for the user equipment with the first network slice, skipping authentication for the user equipment with the one or more other network slices.


