Network Slice Authentication via Attribute-Based Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions do not allow for on-demand access to network slices, particularly in scenarios where network slices need to be dynamically created or changed, and there is a challenge in ensuring secure and efficient distribution of access keys.
Innovation Solution
A method for authenticating wireless communications devices to a network slice, where a slice manager sends a secret key to the device based on its attributes, and an encrypted access key is sent using attribute-based access policies, allowing only authorized devices to decrypt and authenticate to the network slice.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network slices are dynamically created or changed, then adaptability is improved, but security and efficiency of access key distribution become more challenging
Solution Approach 1:
The system performs preliminary actions by pre-establishing attribute-based access policies and distributing encrypted access keys to wireless devices before they need to access the network slice. The slice manager encrypts access keys using attributes associated with wireless devices, allowing devices to authenticate in advance without requiring real-time key distribution when the network slice is dynamically created or changed.
2Reliability
If traditional authentication methods are used for network slices, then security is maintained, but device complexity and configuration requirements increase
Solution Approach 1:
The system enables self-service authentication where wireless devices automatically authenticate to network slices using their own attributes and previously received encrypted access keys. The slice manager distributes access keys encrypted based on device attributes, allowing devices to autonomously decrypt and use the keys for authentication without requiring complex configuration updates or manual intervention.
3Measurement precision
If multiple wireless devices are transitioned to network slices individually, then authentication accuracy is improved, but communication resources and time consumption increase
Solution Approach 1:
The system merges the authentication process for multiple wireless devices by distributing a single encrypted access key to multiple devices simultaneously. The slice manager encrypts the access key using attributes associated with multiple wireless devices, allowing all authorized devices to authenticate together without requiring individual authentication transactions for each device, thereby reducing communication resources and transition time.
Data Source
AI summary
A method for authenticating a wireless communications device to a network slice of a communications network is provided. The wireless communications device has one or more attributes associated with it, at least one of the one or more attributes fulfilling an attribute-based access policy of the network slice. The method is performed by a slice manager of the communications network and comprises sending a secret key to the wireless communications device, sending an encrypted access key to the wireless communications device, the encrypted access key being encrypted using the access policy, such that a secret key generated based at least one attribute that fulfill the attribute-based access policy can decrypt the encrypted access key.


