Network Slice Privacy Protection in 5G Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current communication systems using Network Slicing in 5G networks face challenges in ensuring privacy considerations, particularly during initial registration and data transmission, as sensitive network slice information is not adequately protected from unauthorized access and leakage.

Innovation Solution

The proposed solution involves user equipment and core network nodes that securely manage network slice privacy by assigning privacy attributes during registration and using secure methods to transmit sensitive information, such as the 'Ciphered Options Transfer Flag' to establish encrypted connections, ensuring that only non-private network slice information is sent unencrypted and private information is protected until a secure context is established.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network slice information is transmitted during initial registration without encryption, then network slice selection can be performed, but privacy leakage and unauthorized access occur

Engineering Contradiction:
Improvenetwork slice selectionVSAvoidprivacy leakage
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a secure context and encryption mechanism before transmitting network slice information. The UE and network node perform authentication and key agreement procedures in advance, creating encrypted channels and secure contexts that protect subsequent information exchange, thereby preventing privacy leakage while enabling network slice selection.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If all network slice information is encrypted during transmission, then privacy is protected, but network slice selection efficiency decreases

Engineering Contradiction:
Improveprivacy protectionVSAvoidnetwork slice selection efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies local quality by selectively applying encryption only to specific sensitive information elements rather than encrypting all network slice information uniformly. The UE and network node identify and protect only the confidential portions of network slice information while allowing non-sensitive information to be transmitted in cleartext, thereby maintaining both privacy protection and selection efficiency.

Inventive Principle:
Principle #3Local quality

3Loss of time

If security context establishment procedures are simplified, then initial registration is faster, but security protection against attacks is weakened

Engineering Contradiction:
Improveinitial registration timeVSAvoidsecurity protection
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the security context establishment into separate phases: essential authentication procedures are completed first to enable basic network access, while additional security enhancements and optional authentication steps can be performed subsequently. This segmented approach reduces initial registration time while maintaining adequate security protection against common attacks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11924642B2Privacy considerations for network slice selection
Publication Date: 2024.03.05 NEC CORP
  • US11924642B2 patent drawing
  • US11924642B2 patent drawing
  • US11924642B2 patent drawing

AI summary

User equipment performing communication with a core network node by using network slices obtained by logically dividing a network includes: means for sending information related to security of one network slice; and means for sending identity information of the one network slice in a secure method, based on a request to send information in the secure method sent from the core network node based on the sent information.