Network Slice Authentication via AMF Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile networks face challenges in authenticating and authorizing users for specific network slices, particularly when multiple network slices are used, and there is a lack of clarity on which User Identity to use for each slice during the authentication process.

Innovation Solution

The implementation of procedures for service subscription, network slice authentication information provisioning, and service provider-triggered unsubscription, which involve the Access and Mobility Management Function (AMF) to manage Single Network Slice Selection Assistance Information (S-NSSAI) and trigger authentication processes during UE registration, ensuring that only necessary User Identity information is shared for service provision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network slice authentication is implemented using existing User Identity information, then authentication process is simplified, but user privacy is compromised due to unnecessary sharing of User Identity information

Engineering Contradiction:
Improveauthentication processVSAvoiduser privacy
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent segments the authentication process into two distinct phases: initial network access authentication using existing User Identity information, and network slice-specific authentication using separate credentials. This segmentation allows the system to maintain user privacy by not sharing User Identity information across different authentication contexts, while still enabling simplified initial access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where a network function acts as a mediator between the UE and the authentication server. This intermediary manages the separation between User Identity information and slice-specific credentials, ensuring that User Identity is not unnecessarily exposed while still enabling authentication. The intermediary coordinates the two-phase authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If multiple User Identity information is used for different network slices, then authentication accuracy is improved, but device complexity increases due to managing multiple identities

Engineering Contradiction:
Improveauthentication accuracyVSAvoididentity management
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where the network function automatically manages the mapping between network slices and appropriate credentials. The system autonomously determines which credentials to use for each slice without requiring the UE to manually manage multiple identities. This reduces device complexity while maintaining authentication accuracy through automated credential selection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal authentication framework where a single authentication mechanism can handle multiple network slices using different credentials. The network function serves multiple purposes: initial authentication, slice identification, and credential management. This multi-functionality reduces the need for separate complex identity management systems for each slice.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If all User Identity information is shared for network slice authentication, then authentication reliability is improved, but user privacy protection deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidprivacy exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by using different authentication approaches for different network slices. For slices requiring high reliability, the system uses robust credential verification, while for slices where privacy is paramount, it uses minimal credential sharing. The network function dynamically adjusts the authentication strictness and information sharing level based on the specific slice requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the authentication parameters dynamically based on network slice characteristics. The system adjusts which credentials are used, the level of verification required, and the amount of User Identity information shared, depending on the specific slice's reliability requirements and privacy constraints. This parameter adaptation enables balanced authentication that respects both reliability and privacy needs.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12028341B2Network slice authentication
Publication Date: 2024.07.02 LENOVO (SINGAPORE) PTE LTD
  • US12028341B2 patent drawing
  • US12028341B2 patent drawing
  • US12028341B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for network slice authentication. One method includes receiving a registration request message associated with a UE and determining an authentication requirement for a network slice based at least in part on the received registration request. The method includes transmitting an authentication request to a network entity based at least in part on the determined authentication requirement for the network slice and receiving an authentication response from the network entity based at least in part on the transmitted authentication request. The method includes determining, based at least in part on the received authentication response, whether to include the network slice within a set of allowed NSSAI and transmitting a registration accept message comprising the allowed NSSAI.