NPN Access Control via CAG-NS Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network slicing methods fail to enforce closed access group (CAG) requirements, allowing unauthorized users to access non-public networks (NPNs) and network slices (NSs).
Innovation Solution
A communication method and apparatus that involve a terminal device receiving messages from a core network device and an access network device, which include correspondence between NS indication information and NPN or CAG identifiers. The terminal device determines the supported NS based on these messages, ensuring only authorized users access the NPN and NS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network slicing manner is used to implement NPN network, then network flexibility and service differentiation are improved, but CAG requirement cannot be met and unauthorized users can access the network
Solution Approach 1:
The patent segments the network access control by introducing CAG identifiers and establishing correspondence relationships between NS and CAG. This segmentation allows different access control policies to be applied to different network slices, enabling both network flexibility through slicing and security through CAG-based access control lists that prevent unauthorized access.
Solution Approach 2:
The patent introduces CAG identifier as an intermediary element that mediates between the network slicing mechanism and access control requirements. The CAG identifier establishes a mapping relationship between network slices and authorized user groups, acting as a bridge that enables both network flexibility and security control simultaneously.
2Reliability
If CAG identifier is introduced to enforce closed access, then access control security is improved, but device complexity and signaling overhead increase
Solution Approach 1:
The patent makes the CAG identifier multi-functional by using it for both access control identification and network slice selection. This single identifier serves multiple purposes: identifying closed access groups, selecting appropriate network slices, and establishing correspondence relationships, thereby reducing overall system complexity despite adding new functionality.
Solution Approach 2:
The patent performs preliminary actions by pre-establishing the correspondence relationship between NS and CAG identifiers during network configuration. This pre-configuration approach reduces real-time processing complexity and signaling overhead during actual access control operations, as the mapping relationships are already in place before access decisions need to be made.
Data Source
AI summary
The present disclosure relates to communication methods and apparatus. One example method includes obtaining, by a first access network device, a non-public network (NPN) identifier of an NPN supported by the first access network device, and sending, by the first access network device, a second message to a terminal device, where the second message is used to indicate the NPN identifier of the NPN supported by the first access network device.


