Network Slice Session Management Blocking During NSSAA

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current 5G NR technologies face challenges in managing network slices during authentication and authorization procedures, leading to potential security vulnerabilities and inefficiencies in session management.

Innovation Solution

A method is implemented at a User Equipment (UE) to receive network slice-specific authentication commands, determine if a network slice is being authenticated, and block session management procedures accordingly, ensuring that session management is only initiated once authentication is complete.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If session management procedures are allowed during network slice authentication, then operational efficiency is improved, but security is compromised

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by completing the network slice authentication procedure before allowing session management procedures to occur. The UE monitors the authentication status and only permits session management operations after successful authentication is confirmed, ensuring security requirements are met while maintaining operational efficiency.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If session management procedures are blocked during network slice authentication, then security is improved, but operational efficiency deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by dynamically adjusting the blocking state of session management procedures based on real-time authentication status. The UE continuously monitors whether network slice authentication is complete and adjusts its behavior accordingly - blocking during authentication and permitting after authentication succeeds, thereby optimizing both security and operational efficiency.

Inventive Principle:
Principle #15Dynamics

3Reliability

If network slice authentication is performed, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by implementing authentication status monitoring and session management control entirely at the UE side. The UE autonomously determines whether network slice authentication is complete and independently manages the blocking/permitting of session management procedures without requiring additional network infrastructure or complex coordination, thereby improving security while minimizing device complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12035135B2Handling of slices subject to network slice specific authentication and authorization procedure
Publication Date: 2024.07.09 QUALCOMM INC
  • US12035135B2 patent drawing
  • US12035135B2 patent drawing
  • US12035135B2 patent drawing

AI summary

Method and apparatus for blocking session management procedures for a network slice during an NSSAA procedure. The apparatus receives a network slice-specific authentication command for a network slice that is currently allowed. The apparatus determines that the network slice is being authenticated based on the received network slice-specific authentication command. The apparatus blocks session management procedures associated with the network slice based on the determination that the network slice is being authenticated.