Network Slice Authentication via Intermediary Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 5G communication system, network slicing technology isolates network slices functionally, making it challenging for third-party service providers to authenticate terminals for service access, which complicates the deployment of wireless communication networks and increases costs.
Innovation Solution
A method where a terminal requests authentication from a third-party server by transmitting a service request message with a tenant identifier and slice type to a common control plane network function, establishing a limited data session for authentication, and sending an authentication request through this session, simplifying the authentication process and allowing legacy user authentication schemes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network slicing technology is implemented to isolate network slices functionally, then network security and service isolation are improved, but authentication complexity between terminals and third-party servers increases
Solution Approach 1:
The patent introduces an authentication server as an intermediary component that mediates between terminals and third-party servers. The authentication server receives authentication requests from terminals, verifies credentials, and coordinates with third-party servers to establish authenticated sessions. This intermediary approach maintains network slice isolation while simplifying the authentication process by centralizing authentication logic and reducing direct communication complexity between terminals and multiple third-party servers.
2Reliability
If network slicing is implemented for service isolation, then service quality is improved, but deployment complexity and costs increase
Solution Approach 1:
The patent implements a universal authentication server that serves multiple network slices and supports various authentication methods (e.g., legacy authentication, modern authentication protocols). This multi-functional authentication server can handle authentication requests across different service types and third-party servers, reducing the need for separate authentication mechanisms for each network slice. This universality simplifies deployment by providing a single authentication infrastructure that supports diverse services while maintaining service isolation through logical routing and policy enforcement.
Data Source
AI summary
The present invention relates to a communication system and method for merging, with IoT technology, a 5G communication system for supporting a data transmission rate higher than that of a 4G system. The present invention provides a system and method by which a user equipment (UE) transmits, to an access and mobility management function (AMF), a first message including information related to a network slice in a first authentication, and receives, from the AMF, a third message including a result of a second authentication, wherein whether to require the second authentication is determined by the AMF based on the information and subscription information, and wherein the second authentication between the UE and a server is triggered based on the determination.


