Wireless Device Network Slice Identifier Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication networks lack effective mechanisms to protect the privacy of network slice identifiers, which are critical for providing specific network capabilities and characteristics.

Innovation Solution

The proposed solution involves encrypting the network slice identifier using cryptographic key material shared between the wireless device and its home network, which is derived from authentication processes, thereby ensuring confidentiality protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the network slice identifier is transmitted in plaintext for network selection, then the serving network can efficiently identify and select the appropriate network slice, but the privacy of the network slice identifier is compromised

Engineering Contradiction:
Improvenetwork slice selection efficiencyVSAvoidprivacy exposure of network slice identifier
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encrypted form of the network slice identifier as an intermediary between the plaintext identifier and the privacy protection goal. The wireless device encrypts the network slice identifier using cryptographic key material before transmission, creating a ciphertext version that preserves functionality while protecting privacy. The serving network decrypts this intermediary form to access the original identifier, thus maintaining selection efficiency while eliminating plaintext exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If cryptographic key material is shared between the wireless device and the serving network for encryption, then the network slice identifier can be protected, but the key material becomes more vulnerable to compromise

Engineering Contradiction:
Improvenetwork slice identifier privacy protectionVSAvoidcryptographic key material security
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent extracts the cryptographic key material from the serving network and relocates it to the home network, where it is generated and stored. The serving network no longer possesses the key material, eliminating the security vulnerability of sharing keys across multiple networks. The home network, which already holds authentication credentials, becomes the sole custodian of the encryption keys, thereby strengthening key material security while maintaining privacy protection capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If the same cryptographic key material is used across multiple networks for device authentication, then device portability is improved, but the impact of key compromise is amplified

Engineering Contradiction:
Improvedevice portability across networksVSAvoidimpact of key material compromise
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cryptographic architecture by separating key generation, storage, and usage functions across different networks. The home network generates and stores the master key material, while the serving network uses temporary derived keys for specific authentication sessions. This segmentation ensures that even if a serving network's session keys are compromised, the master key material remains secure in the home network, limiting the impact of compromises while maintaining device portability through home network-anchored authentication.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12273711B2Home controlled network slice privacy
Publication Date: 2025.04.08 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12273711B2 patent drawing
  • US12273711B2 patent drawing
  • US12273711B2 patent drawing

AI summary

A wireless device (12) performs authentication (14) with a home network (10H) of the wireless device (12). The wireless device (12) encrypts a network slice identifier (24) with cryptographic key material (22) that is available from the authentication (14) with the home network (10H) and that is shared between the wireless device (12) and the home network (10H). The wireless device (12) transmits a message (20) that includes the encrypted network slice identifier (26). In some embodiments, a network node in a serving network (10S) of the wireless device (12) receives the message (20) and decrypts, or requests decryption of, the encrypted network slice identifier (26) using cryptographic key material (22) that is available to the wireless device (12) from authentication (14) of the wireless device (12) with the home network (10H) and that is shared between the wireless device (12) and the home network (10H).