Network Slice Security Context Management in 5G IoT Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The 5G network slicing technology uses shared security key information for all packet data network connections, which is not suitable for independent security management of each service, leading to potential security leakage and violation of the independent operating philosophy.
Innovation Solution
A method is proposed to adaptively manage security by using different security keys and algorithms for each service, where security contexts are generated based on identifiers and tokens from the authentication process, allowing independent security key management and application for each network slice.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If shared security key information is used for all packet data network connections, then device complexity is reduced and ease of operation is improved, but security reliability deteriorates due to potential security leakage across network slices
Solution Approach 1:
The patent segments the security management system by introducing service-specific security contexts and keys for each network slice. Instead of using a single shared security key for all connections, the system divides security management into isolated segments where each network slice has its own security parameters, preventing security leakage while maintaining manageable complexity through structured organization.
Solution Approach 2:
The patent applies local quality by allowing different security levels and mechanisms to be applied to different network slices based on their specific requirements. Each service can have customized security contexts, algorithms, and key management policies tailored to its security needs, rather than applying a uniform security approach across all services.
2Reliability
If different security keys and algorithms are used for each service, then security reliability is improved through independent security management, but device complexity increases due to multiple security contexts
Solution Approach 1:
The patent applies preliminary action by establishing service-specific security contexts during the initial service setup and authentication phase. Security keys and algorithms are pre-configured and bound to specific network slices before actual data transmission begins, which simplifies subsequent security management operations and reduces the complexity of real-time security decision-making.
Solution Approach 2:
The patent introduces dynamic security context selection based on service requirements and network conditions. The system can adaptively choose appropriate security algorithms and key lengths for each service, allowing the security management system to remain flexible and efficient rather than statically configured, thereby reducing overall system complexity while maintaining high security standards.
Data Source
AI summary
The present disclosure relates to a communication method and system for converging a 5th-generation (5G) communication system for supporting higher data rates beyond a 4th-generation (4G) system with a technology for internet of things (IoT). The present disclosure may be applied to intelligent services based on the 5G communication technology and the IoT-related technology, such as smart home, smart building, smart city, smart car, connected car, health care, digital education, smart retail, security and safety services. A method of a terminal according to the present disclosure includes: transmitting connection request messages for network slices, which are networks constructed for each service, to a network; receiving response messages including identifiers of the network slices from a base station; and generating security contexts for each network slice based on at least one of the identifiers of the network slices and tokens generated during an authentication process with a third party.


