Network Slice Instance Management Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the 5G communication system, network slicing technology struggles to authenticate terminals for third-party service providers efficiently, as existing methods lack a streamlined process for user authentication across tenanted network slices.

Innovation Solution

A method where a terminal requests authentication from a third-party server by transmitting a service request message with a tenant identifier and slice type to a common control plane network function, establishing a limited data session for authentication, and sending an authentication request through this session, facilitated by a network slice instance management device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network slicing technology is implemented to support third-party service providers, then service diversity and adaptability are improved, but authentication complexity and device complexity increase

Engineering Contradiction:
Improveservice diversityVSAvoidauthentication complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct phases: service request phase, authentication phase, and service provision phase. The network slice instance management device separates authentication functionality from service management, allowing independent handling of authentication requests through dedicated reference points while maintaining overall system integration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The network slice instance management device acts as an intermediary between the terminal and the authentication server function. It receives service requests, establishes appropriate reference points, and facilitates authentication by routing messages through the proper network paths, thereby simplifying the overall authentication complexity while supporting multiple third-party providers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a streamlined authentication process is implemented for third-party servers, then ease of operation is improved, but authentication reliability may deteriorate

Engineering Contradiction:
Improveauthentication easeVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a universal authentication framework where the network slice instance management device handles multiple authentication scenarios through a single standardized interface. The same reference point mechanism and message routing logic serve both simple and complex authentication cases, ensuring consistent reliability across different third-party service providers while maintaining ease of operation through standardized procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If existing authentication methods are used without modification, then device complexity is reduced, but productivity and authentication efficiency deteriorate

Engineering Contradiction:
Improvesystem complexityVSAvoidauthentication efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The network slice instance management device performs preliminary actions by pre-establishing reference points and configuring authentication paths before actual authentication occurs. Service requests trigger pre-configured authentication flows, eliminating the need for complex real-time decision-making and improving authentication efficiency without significantly increasing device complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12256003B2Method for requesting authentication between terminal and 3rd party server in wireless communication system, terminal therefor, and network slice instance management device
Publication Date: 2025.03.18 SAMSUNG ELECTRONICS CO LTD
  • US12256003B2 patent drawing
  • US12256003B2 patent drawing
  • US12256003B2 patent drawing

AI summary

The present invention relates to a communication system and method for merging, with IoT technology, a 5G communication system for supporting a data transmission rate higher than that of a 4G system. The present invention provides a system and method by which a user equipment (UE) transmits, to an access and mobility management function (AMF), a first message including information related to a network slice in a first authentication, and receives, from the AMF, a third message including a result of a second authentication, wherein whether to require the second authentication is determined by the AMF based on the information and subscription information, and wherein the second authentication between the UE and a server is triggered based on the determination.