Wireless Device Network Slice Identifier Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing wireless communication networks lack effective mechanisms to protect the privacy of network slice identifiers, which are critical for providing specific network capabilities and characteristics.
Innovation Solution
The proposed solution involves encrypting the network slice identifier using cryptographic key material shared between the wireless device and its home network, which is derived from authentication processes, thereby ensuring confidentiality protection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the network slice identifier is transmitted in plaintext for network selection, then the serving network can efficiently identify and select the appropriate network slice, but the privacy of the network slice identifier is compromised
Solution Approach 1:
The patent introduces an encrypted form of the network slice identifier as an intermediary between the plaintext identifier and the privacy protection goal. The wireless device encrypts the network slice identifier using cryptographic key material before transmission, creating a ciphertext version that preserves functionality while protecting privacy. The serving network decrypts this intermediary form to access the original identifier, thus maintaining selection efficiency while eliminating plaintext exposure.
2Object-affected harmful factors
If cryptographic key material is shared between the wireless device and the serving network for encryption, then the network slice identifier can be protected, but the key material becomes more vulnerable to compromise
Solution Approach 1:
The patent extracts the cryptographic key material from the serving network and relocates it to the home network, where it is generated and stored. The serving network no longer possesses the key material, eliminating the security vulnerability of sharing keys across multiple networks. The home network, which already holds authentication credentials, becomes the sole custodian of the encryption keys, thereby strengthening key material security while maintaining privacy protection capabilities.
3Adaptability or versatility
If the same cryptographic key material is used across multiple networks for device authentication, then device portability is improved, but the impact of key compromise is amplified
Solution Approach 1:
The patent segments the cryptographic architecture by separating key generation, storage, and usage functions across different networks. The home network generates and stores the master key material, while the serving network uses temporary derived keys for specific authentication sessions. This segmentation ensures that even if a serving network's session keys are compromised, the master key material remains secure in the home network, limiting the impact of compromises while maintaining device portability through home network-anchored authentication.
Data Source
AI summary
A wireless device (12) performs authentication (14) with a home network (10H) of the wireless device (12). The wireless device (12) encrypts a network slice identifier (24) with cryptographic key material (22) that is available from the authentication (14) with the home network (10H) and that is shared between the wireless device (12) and the home network (10H). The wireless device (12) transmits a message (20) that includes the encrypted network slice identifier (26). In some embodiments, a network node in a serving network (10S) of the wireless device (12) receives the message (20) and decrypts, or requests decryption of, the encrypted network slice identifier (26) using cryptographic key material (22) that is available to the wireless device (12) from authentication (14) of the wireless device (12) with the home network (10H) and that is shared between the wireless device (12) and the home network (10H).


