Network Slice Security Framework for 5G Roaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing communication networks face challenges in efficiently managing network slices and providing secure, flexible, and scalable communication services to diverse wireless devices with varying capabilities and technologies, particularly in scenarios involving roaming and untrusted access.

Innovation Solution

A framework for network slicing and service-based architecture is implemented, allowing for dynamic selection and management of network functions and resources based on device capabilities and traffic conditions, with enhanced security mechanisms for trusted and untrusted access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network slices are dynamically selected and managed based on device capabilities and traffic conditions, then resource allocation efficiency is improved, but system complexity increases

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The network is divided into multiple network slices, each tailored to specific device capabilities and traffic conditions. This segmentation allows dynamic resource allocation while managing complexity through standardized slice templates and automated selection mechanisms.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements dynamic network slice selection and management based on real-time device capabilities and traffic conditions. Resources are allocated and reassigned dynamically to optimize efficiency while maintaining manageable complexity through automated policies.

Inventive Principle:
Principle #15Dynamics

2Reliability

If enhanced security mechanisms are implemented for trusted and untrusted access, then communication security is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security framework introduces intermediary authentication and authorization mechanisms between devices and network slices. This mediator approach enhances security for both trusted and untrusted access while abstracting complexity from individual devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes security parameters dynamically based on device trust levels and access requirements. Different security measures are applied as parameters vary, enhancing security without requiring complex implementations at the device level.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If network functions are dynamically selected based on device capabilities, then service flexibility is improved, but management complexity increases

Engineering Contradiction:
Improveservice flexibilityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The framework implements universal network function selection mechanisms that work across diverse device capabilities. This multi-functional approach enhances service flexibility while managing complexity through standardized interfaces and automated management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses feedback mechanisms to dynamically select network functions based on actual device capabilities and performance. This feedback-driven approach improves flexibility while reducing management complexity through automated adaptation.

Inventive Principle:
Principle #23Feedback

4Productivity

If network resources are efficiently utilized across various slices, then resource utilization is improved, but detection and measurement difficulty increases

Engineering Contradiction:
Improveresource utilizationVSAvoiddetection and measurement difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The framework implements feedback mechanisms that continuously monitor and measure resource utilization across network slices. This enables efficient resource allocation while managing measurement complexity through standardized metrics and automated collection.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system replaces complex manual measurement and detection mechanisms with automated software-based monitoring and management functions. This substitution improves resource utilization efficiency while reducing the difficulty of detection and measurement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250211986A1Slice Security
Publication Date: 2025.06.26 OFINNO LLC
  • US20250211986A1 patent drawing
  • US20250211986A1 patent drawing
  • US20250211986A1 patent drawing

AI summary

A wireless device sends, to a base station associated with an evolved packet core (EPC), a request message requesting a packet data network (PDN) connectivity. The request message comprises an indication of support for network slice specific authentication and authorization (NSSAA) over the EPC, and the PDN connectivity is associated with a network slice of a 5G system (5GS).