Network Slice Credential Management for Dynamic Service Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G mobile networks lack effective techniques for managing slice-specific credentials, leading to inadequate logical isolation between network slices and insufficient support for dynamic service deployments, updates, and terminations.
Innovation Solution
Implementing a credential manager that imports, stores, and protects slice-specific credentials using encryption, access control, and integrity protection policies, and modifies or withdraws credentials in response to triggers such as security changes or service lifecycle events.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If network slices share a common credential storage mechanism, then device complexity is reduced, but logical isolation between network slices deteriorates
Solution Approach 1:
The patent segments the credential storage mechanism by introducing slice-specific credential identifiers and separate storage locations for different network slices. The credential manager divides the credential repository into isolated segments, each protected by slice-specific access control policies, thereby maintaining logical isolation while using a unified management architecture.
Solution Approach 2:
The credential manager acts as an intermediary between the unified credential repository and individual network slices. It enforces access control policies that prevent unauthorized cross-slice credential access, mediating between the simplified unified storage and the required isolation, thus resolving the contradiction between complexity reduction and isolation maintenance.
2Reliability
If credentials are statically configured, then security integrity is maintained, but adaptability to dynamic service deployments deteriorates
Solution Approach 1:
The patent implements dynamic credential management where credentials can be created, modified, and deleted based on service lifecycle events. The system dynamically provisions credentials when services are deployed and revokes them when services are terminated, maintaining security integrity through controlled dynamic changes rather than static configuration.
Solution Approach 2:
The system incorporates feedback mechanisms that monitor service deployment status and automatically trigger credential provisioning or revocation. When a service is deployed, the system detects this event and provisions appropriate credentials; when a service is terminated, it detects this and revokes credentials, ensuring security integrity adapts to dynamic service changes.
3Reliability
If credential updates require manual intervention, then security control is maintained, but productivity of service deployment deteriorates
Solution Approach 1:
The credential manager implements self-service functionality by automatically provisioning, updating, and revoking credentials based on service lifecycle events without requiring manual security administrator intervention. The system autonomously enforces security policies while accelerating service deployment, resolving the contradiction between security control and deployment productivity.
Solution Approach 2:
The system performs preliminary credential provisioning actions in advance of service deployment by pre-configuring credential templates and access control policies. When services are deployed, credentials are already prepared and can be quickly instantiated, maintaining security control while significantly improving service deployment speed.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A credential manager imports credentials for a network slice in response to deployment of the network slice. The credentials are not known to other network slices. A repository is configured to store the credentials and protect the credentials based on credential protection policies that are defined by a service profile of the network slice. The repository is implemented in the credential manager, an authentication, authorization, and accounting (AAA) server, or other location. Properties of the credentials are modified in response to a modification trigger and the credentials are withdrawn in response to a withdrawal trigger.