Network Slice Credential Encryption via Public Key
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems face challenges in protecting user identity and credentials during network slice authentication, as additional authorization and authentication processes expose user IDs and credentials to untrusted entities, lacking adequate privacy and security.
Innovation Solution
The implementation of a method where a public key is provided for network slice-specific authentication, allowing the user equipment (UE) or access management function (AMF) to encrypt and conceal user identities and credentials, ensuring privacy by encrypting a second set of credentials using the public key and sending the encrypted credentials for authentication, thereby protecting user identity and credentials during slice-specific authorization and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional authorization and authentication processes are implemented for network slice access, then network slice authentication security is improved, but user identity and credentials are exposed to untrusted entities
Solution Approach 1:
The patent introduces an intermediary encryption mechanism using public-key cryptography. The AMF acts as an intermediary that encrypts the second set of credentials (used for network slice authentication) with a public key before transmitting them to the AAA server. This intermediary encryption layer protects the credentials from exposure to untrusted entities while still enabling the necessary authentication process.
Solution Approach 2:
The patent segments the authentication credentials into two distinct sets: a first set of credentials for PLMN access authorization and authentication, and a second set of credentials for network slice-specific authentication. By separating these credentials and applying different protection mechanisms (the second set is encrypted with a public key), the system can maintain security while enabling slice-specific access control.
2Adaptability or versatility
If user identities and credentials are transmitted for network slice authentication, then authentication functionality is improved, but privacy protection deteriorates
Solution Approach 1:
Public-key encryption serves as an intermediary that enables credential transmission while preserving privacy. The AMF encrypts the second set of credentials using a public key obtained from the UDM, ensuring that even though credentials are transmitted for authentication purposes, their privacy is protected through cryptographic intermediation. Only the intended recipient with the corresponding private key can decrypt and access the credentials.
Solution Approach 2:
The patent changes the state of the credentials from plaintext to encrypted form by applying public-key encryption. This parameter change (from unencrypted to encrypted) allows the credentials to be transmitted and processed for authentication while maintaining privacy protection, as the encrypted form cannot be read without the private key.
3Loss of information
If public key encryption is applied to credentials, then privacy protection is improved, but processing complexity increases
Solution Approach 1:
The system implements self-service through automated public key management. The UDM automatically provisions the public key to the AMF, and the AMF automatically uses this public key to encrypt the second set of credentials without requiring manual intervention. This automation reduces the practical complexity burden despite the introduction of cryptographic operations.
Solution Approach 2:
The public key is provisioned in advance by the UDM to the AMF before the authentication process begins. This preliminary action of pre-provisioning the encryption key eliminates the need for complex key management operations during the actual authentication flow, reducing processing complexity at critical moments.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for protecting the user identity and credentials. One apparatus includes a processor registers with a mobile communication network using a first set of credentials, the mobile communication network supporting a plurality of network slices. The processor receives a public key for a network slice where slice-specific authentication is required and encrypts a second set of credentials using the public key. Here, the second set of credentials is used for authentication with the network slice. The apparatus includes a transceiver that sends a message to the mobile communication network, the message including the encrypted second set of credentials.


