Network Slice Credential Management for Dynamic Service Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G mobile networks lack effective techniques for managing slice-specific credentials, leading to inadequate logical isolation between network slices and insufficient support for dynamic service deployments, updates, and terminations.

Innovation Solution

Implementing a credential manager that imports, stores, and protects slice-specific credentials using encryption, access control, and integrity protection policies, and modifies or withdraws credentials in response to triggers such as security changes or service lifecycle events.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If network slices share a common credential storage mechanism, then device complexity is reduced, but logical isolation between network slices deteriorates

Engineering Contradiction:
Improvecredential management complexityVSAvoidlogical isolation between network slices
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the credential storage mechanism by introducing slice-specific credential identifiers and separate storage locations for different network slices. The credential manager divides the credential repository into isolated segments, each protected by slice-specific access control policies, thereby maintaining logical isolation while using a unified management architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The credential manager acts as an intermediary between the unified credential repository and individual network slices. It enforces access control policies that prevent unauthorized cross-slice credential access, mediating between the simplified unified storage and the required isolation, thus resolving the contradiction between complexity reduction and isolation maintenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If credentials are statically configured, then security integrity is maintained, but adaptability to dynamic service deployments deteriorates

Engineering Contradiction:
Improvesecurity integrityVSAvoidsupport for dynamic service deployments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic credential management where credentials can be created, modified, and deleted based on service lifecycle events. The system dynamically provisions credentials when services are deployed and revokes them when services are terminated, maintaining security integrity through controlled dynamic changes rather than static configuration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback mechanisms that monitor service deployment status and automatically trigger credential provisioning or revocation. When a service is deployed, the system detects this event and provisions appropriate credentials; when a service is terminated, it detects this and revokes credentials, ensuring security integrity adapts to dynamic service changes.

Inventive Principle:
Principle #23Feedback

3Reliability

If credential updates require manual intervention, then security control is maintained, but productivity of service deployment deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidservice deployment speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The credential manager implements self-service functionality by automatically provisioning, updating, and revoking credentials based on service lifecycle events without requiring manual security administrator intervention. The system autonomously enforces security policies while accelerating service deployment, resolving the contradiction between security control and deployment productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary credential provisioning actions in advance of service deployment by pre-configuring credential templates and access control policies. When services are deployed, credentials are already prepared and can be quickly instantiated, maintaining security control while significantly improving service deployment speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3987834B1Dynamic allocation of network slice-specific credentials
Publication Date: 2025.10.01 NOKIA TECHNOLOGIES OY
  • EP3987834B1 patent drawingFigure 1
  • EP3987834B1 patent drawingFigure 2
  • EP3987834B1 patent drawingFigure 3

AI summary

A credential manager imports credentials for a network slice in response to deployment of the network slice. The credentials are not known to other network slices. A repository is configured to store the credentials and protect the credentials based on credential protection policies that are defined by a service profile of the network slice. The repository is implemented in the credential manager, an authentication, authorization, and accounting (AAA) server, or other location. Properties of the credentials are modified in response to a modification trigger and the credentials are withdrawn in response to a withdrawal trigger.