Non-3GPP Network Slice Discovery Using Privacy-Preserving Group Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network architectures for non-3GPP access in communication systems expose user equipment's network slice information, leading to privacy concerns and potential security risks from Man-in-the-Middle attacks.

Innovation Solution

Implementing a mechanism that uses network slice group information instead of slice identification information for discovery procedures, ensuring privacy by encrypting and mapping slice group data between user equipment, access network devices, and core network devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network slice identification information is used in discovery procedures, then network slice selection accuracy is improved, but user privacy and security are compromised due to exposure of sensitive information

Engineering Contradiction:
Improvenetwork slice selection accuracyVSAvoidprivacy exposure and security risks
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent introduces network slice group information as an intermediary element that mediates between the need for accurate network slice selection and the requirement for user privacy protection. Instead of directly exposing detailed network slice identification information, the system uses aggregated group information that preserves selection accuracy while hiding sensitive individual slice details from access network devices during discovery procedures

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts and separates the essential selection criteria (network slice group information) from the sensitive detailed information (specific network slice identification). By taking out only the necessary aggregated information for discovery procedures, the system maintains selection functionality while removing the privacy-risking detailed slice identifiers from the communication between UE and access network devices

Inventive Principle:
Principle #2Taking out (Extraction)

2Manufacturing precision

If detailed network slice identification information is transmitted during access, then network service precision is improved, but vulnerability to Man-in-the-Middle attacks increases

Engineering Contradiction:
Improvenetwork service precisionVSAvoidsecurity against MITM attacks
Core Design Contradiction:
Manufacturing precisionVSReliability

Solution Approach 1:

Network slice group information serves as a protective intermediary layer that enables precise network service selection without directly transmitting vulnerable detailed slice identifiers. This intermediary approach maintains service precision while reducing the attack surface for MITM attacks by obscuring the specific slice information that attackers would target

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments network slice information into two distinct layers: network slice group information for discovery and selection purposes, and detailed network slice identification information for authenticated core network communication. This segmentation allows precise service selection to occur at the group level during vulnerable transmission phases, while detailed slice information remains protected and is only used in secure authenticated sessions

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260040197A1Network slice security for non 3GPP access
Publication Date: 2026.02.05 NOKIA TECHNOLOGIES OY
  • US20260040197A1 patent drawing
  • US20260040197A1 patent drawing
  • US20260040197A1 patent drawing

AI summary

Various example embodiments relate to methods and apparatuses for network slice security for non-3GPP access. An apparatus may be configured to send to an access network device, a request message comprising network slice group information corresponding to network slice identification information of the terminal device; and receive from the access network device, an identification of a non-3GPP access network device capable of serving at least one network slice indicated in the network slice identification information in response to the request message.