Non-3GPP Network Slice Discovery Using Privacy-Preserving Group Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network architectures for non-3GPP access in communication systems expose user equipment's network slice information, leading to privacy concerns and potential security risks from Man-in-the-Middle attacks.
Innovation Solution
Implementing a mechanism that uses network slice group information instead of slice identification information for discovery procedures, ensuring privacy by encrypting and mapping slice group data between user equipment, access network devices, and core network devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If network slice identification information is used in discovery procedures, then network slice selection accuracy is improved, but user privacy and security are compromised due to exposure of sensitive information
Solution Approach 1:
The patent introduces network slice group information as an intermediary element that mediates between the need for accurate network slice selection and the requirement for user privacy protection. Instead of directly exposing detailed network slice identification information, the system uses aggregated group information that preserves selection accuracy while hiding sensitive individual slice details from access network devices during discovery procedures
Solution Approach 2:
The patent extracts and separates the essential selection criteria (network slice group information) from the sensitive detailed information (specific network slice identification). By taking out only the necessary aggregated information for discovery procedures, the system maintains selection functionality while removing the privacy-risking detailed slice identifiers from the communication between UE and access network devices
2Manufacturing precision
If detailed network slice identification information is transmitted during access, then network service precision is improved, but vulnerability to Man-in-the-Middle attacks increases
Solution Approach 1:
Network slice group information serves as a protective intermediary layer that enables precise network service selection without directly transmitting vulnerable detailed slice identifiers. This intermediary approach maintains service precision while reducing the attack surface for MITM attacks by obscuring the specific slice information that attackers would target
Solution Approach 2:
The patent segments network slice information into two distinct layers: network slice group information for discovery and selection purposes, and detailed network slice identification information for authenticated core network communication. This segmentation allows precise service selection to occur at the group level during vulnerable transmission phases, while detailed slice information remains protected and is only used in secure authenticated sessions
Data Source
AI summary
Various example embodiments relate to methods and apparatuses for network slice security for non-3GPP access. An apparatus may be configured to send to an access network device, a request message comprising network slice group information corresponding to network slice identification information of the terminal device; and receive from the access network device, an identification of a non-3GPP access network device capable of serving at least one network slice indicated in the network slice identification information in response to the request message.


