Network Slice Verification Using Authentication Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In network slicing, the home network cannot verify whether a visited network provides the slice service, leading to potential deception and higher service fees, compromising network security.
Innovation Solution
A slice service verification method involving a slice service verification function entity that verifies a message authentication code based on a network identifier, using integrity keys and identifiers to ensure authenticity of the slice service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the home network does not implement verification mechanisms, then the system is simple and easy to operate, but the visited network can deceive the home network leading to poor network security
Solution Approach 1:
The patent implements preliminary verification actions by having the terminal device generate a message authentication code based on the network identifier before accessing the visited network. The home network verifies this code in advance through the slice service verification function entity, preventing deception before it occurs. This preliminary action ensures network security without requiring complex real-time monitoring systems.
Solution Approach 2:
The patent introduces a slice service verification function entity as an intermediary between the terminal device and the visited network. This intermediary receives the message authentication code, performs verification based on the network identifier, and communicates the verification result to the home network. By using this intermediary, the system achieves reliable verification without requiring direct complex interactions between all network components.
2Reliability
If the home network verifies slice service provision, then network security is improved, but the verification process requires additional time and resources
Solution Approach 1:
The verification process is performed as a preliminary action during the network access establishment phase, before the terminal device begins using slice services. The message authentication code is generated and verified in advance, so the verification time does not add to the service usage time. This approach minimizes time loss while ensuring network security.
Solution Approach 2:
The terminal device actively participates in the verification process by generating the message authentication code itself based on the network identifier. This self-service approach distributes the verification workload, reducing the time and resources required from the home network while maintaining security. The terminal device performs part of the verification work autonomously.
Data Source
AI summary
Implementations of this application disclose slice service verification methods and apparatuses. In an implementation, a method comprises: receiving a first message sent by a terminal device, wherein the first message comprises an identifier of a first network slice and a first message authentication code, verifying the first message authentication code based on a second network identifier, and sending the second network identifier to an authentication server in response to the verifying the first message authentication code being successful.


