Network Slice Isolation via Associated Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current 5G systems lack a defined method for network slice isolation and storage of identities and credentials for Network Slice-Specific Authentication and Authorization (NSSAA), leading to unclear usage of identities and potential security risks.
Innovation Solution
The implementation of associated identifiers, such as Subscription Permanent Identifiers (SUPI) and Global Public Subscriber Identifiers (GPSI), is used to isolate and manage network slices, ensuring that each slice set is isolated from others by allocating distinct identifiers and using these identifiers for authentication and authorization processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple network slices are allowed to be used simultaneously by a UE, then network versatility and service availability are improved, but security and slice isolation are compromised
Solution Approach 1:
The patent segments network slice access by introducing separate authentication mechanisms. Primary authentication via SUPI/AKA provides base security, while secondary NSSAA authentication via EAP-ID/EAP-credentials provides slice-specific security. This segmentation allows multiple slices to be used simultaneously while maintaining isolation through layered authentication credentials stored in different locations (UICC for primary, ME for secondary).
Solution Approach 2:
The patent introduces an intermediary secondary authentication mechanism (NSSAA) that mediates between the UE and network slices. The EAP-based secondary authentication acts as a mediator that verifies slice-specific credentials independently of primary authentication, enabling secure multi-slice usage by inserting an additional security verification layer between the UE and the network slices.
2Reliability
If separate subscriptions are configured for isolated network slices using multiple UICC or USIM, then slice isolation security is improved, but device complexity and user operation difficulty increase
Solution Approach 1:
The patent merges multiple authentication credentials into a single UE device by storing primary credentials (SUPI/AKA) in the UICC and secondary credentials (EAP-ID/EAP-credentials) in the ME. This combining of authentication mechanisms within one device eliminates the need for multiple physical UICC cards while maintaining slice isolation security through separate credential stores and authentication procedures.
Solution Approach 2:
The patent makes the UE device universal by enabling it to handle both UICC-based primary authentication and ME-based secondary authentication. The device can simultaneously manage multiple types of credentials and authentication protocols, making it multi-functional in terms of authentication methods while maintaining a single physical device structure, thus reducing complexity compared to requiring multiple separate UICC cards.
3Reliability
If identities and credentials for NSSAA are stored in the UICC, then authentication security is improved, but storage flexibility and credential management adaptability decrease
Solution Approach 1:
The patent adds another dimension to credential storage by utilizing both the UICC (traditional card-based storage) and the ME (device-based storage) for different types of authentication credentials. Primary credentials (SUPI/AKA) remain in the UICC for security, while secondary credentials (EAP-ID/EAP-credentials) are stored in the ME, creating a multi-dimensional storage architecture that provides both security and flexibility simultaneously.
Data Source
AI summary
Apparatuses and methods for resource isolation via associated identifiers are disclosed. In one embodiment, a method implemented in a user equipment (UE) configured with a first identifier and a second identifier includes determining that resources and data associated with the first identifier require end-to-end isolation from the resources and data associated with the second identifier; transmitting a registration message to a network node comprising the first identifier; and if the UE has existing connections associated with the second identifier, releasing the existing connections associated with the second identifier to provide end-to-end isolation of the resources and data when the first identifier is transmitted in the registration message.


