Selective Network Slice Authentication Skipping Signaling Overhead

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network slicing architectures in 3GPP mobile networks, such as 5G, result in excessive signaling between user equipment and the mobile core network, consuming network and radio resources due to the need for separate authentication and authorization procedures for each network slice.

Innovation Solution

Implementing selective network slice authentication and authorization techniques, where successful authentication with one network slice allows skipping of authentication for other slices, using network slice mapping policies to reduce signaling and optimize resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate authentication and authorization procedures are performed for each network slice, then security and authorization control are improved, but signaling overhead and resource consumption increase

Engineering Contradiction:
Improveauthorization controlVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines multiple authentication and authorization procedures into a single unified process. When a user equipment requests access to multiple network slices, the system performs one authentication and one authorization check that validates access to all requested slices simultaneously, rather than repeating the process for each slice individually. This merging eliminates redundant signaling while maintaining security control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authorization mechanism is designed to be universal across multiple network slices. A single authorization decision can grant or deny access to multiple slices at once, making the authorization function multi-functional. The system evaluates the user's credentials and service requirements once, then applies the authorization outcome to all requested slices, reducing the need for slice-specific authorization procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If authentication is performed for multiple network slices, then access control security is improved, but processing time and network resource usage increase

Engineering Contradiction:
Improveaccess controlVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary evaluation of the user equipment's authentication credentials and service requirements before initiating separate authentication procedures for each network slice. By pre-assessing the user's authorization level and service entitlements, the system can determine upfront which slices the user is authorized to access, eliminating the need for time-consuming sequential authentication processes for each slice.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Multiple authentication and authorization operations are merged into a single consolidated process. Instead of executing authentication sequentially for each network slice, the system combines these operations into one unified authentication and authorization check that validates access to all requested slices simultaneously, significantly reducing total processing time.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If separate authorization procedures are conducted for each network slice, then service-specific control is improved, but configuration complexity and signaling load increase

Engineering Contradiction:
Improveservice-specific controlVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The authorization system uses a universal evaluation framework that can handle multiple service-specific requirements through a single process. Rather than implementing separate configuration sets for each slice, the system evaluates user credentials, service requirements, and network policies universally, then applies the authorization outcome appropriately to each requested slice based on its specific service characteristics.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

While maintaining a unified authorization process, the system segments the evaluation criteria to accommodate different service requirements. The authorization mechanism evaluates each network slice's specific service requirements independently within the overall authorization framework, allowing service-specific control without requiring separate authorization procedures. This segmentation occurs in the evaluation logic rather than in the procedural structure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12177663B2Selective network slice authentication and authorization in a mobile network environment
Publication Date: 2024.12.24 CISCO TECHNOLOGY INC
  • US12177663B2 patent drawing
  • US12177663B2 patent drawing
  • US12177663B2 patent drawing

AI summary

Presented herein are techniques to provide selective network slice authentication and authorization in a mobile network environment. In one example, a method may include obtaining, by an access management element of a mobile network, a registration request from a user equipment, wherein the registration request identifies a plurality of network slices with which the user equipment seeks authentication; determining that if authentication for the user equipment with a first network slice is successful, authentication for the user equipment with one or more other network slices can be skipped; and upon successful authentication for the user equipment with the first network slice, skipping authentication for the user equipment with the one or more other network slices.