Network Slice Access Control With NSSAA-First User Counting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to accurately determine whether to allow access of a terminal device to a network slice that requires both Network Slice Specific Authentication and Authorization (NSSAA) and user counting, leading to inefficiencies in network management and resource utilization.
Innovation Solution
A communication method where the Network Slice Selection Function (NSSF) first performs NSSAA on slices requiring both NSSAA and user counting, and then determines access based on the authentication result, reducing unnecessary user counting and signaling overheads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If both NSSAA and user counting are performed on a network slice, then authentication security and resource control are improved, but access determination accuracy deteriorates
Solution Approach 1:
The patent applies preliminary action by performing NSSAA authentication before user counting. The AMF first determines whether NSSAA is required based on subscription data and requested NSSAI, then performs the authentication process. Only after successful authentication does the system proceed to user counting and access determination. This sequencing ensures that authentication security and resource control are both implemented while maintaining accurate access determination by avoiding redundant operations on unauthorized devices.
2Reliability
If user counting is performed on all requested slices, then resource quota control is improved, but signaling overhead increases
Solution Approach 1:
The patent applies preliminary action by performing NSSAA authentication before user counting. The AMF first determines whether NSSAA is required based on subscription data and requested NSSAI, then performs the authentication process. Only after successful authentication does the system proceed to user counting and access determination. This sequencing ensures that authentication security and resource control are both implemented while maintaining accurate access determination by avoiding redundant operations on unauthorized devices.
Solution Approach 2:
The patent extracts the NSSAA authentication step as a separate preliminary process before user counting. By separating authentication from resource quota control, the system avoids performing user counting on devices that will ultimately be rejected due to authentication failure. This extraction reduces unnecessary signaling overhead while maintaining accurate resource quota control for authorized users.
3Speed
If access determination is performed before NSSAA, then processing speed is improved, but access control accuracy deteriorates
Solution Approach 1:
The patent applies preliminary action by performing NSSAA authentication before user counting. The AMF first determines whether NSSAA is required based on subscription data and requested NSSAI, then performs the authentication process. Only after successful authentication does the system proceed to user counting and access determination. This sequencing ensures that authentication security and resource control are both implemented while maintaining accurate access determination by avoiding redundant operations on unauthorized devices.
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
This application provides a communication method, apparatus, and system. The method includes: A network slice selection network element sends identification information of a first slice to a mobility management network element. The network slice selection network element receives a slice authentication result corresponding to the first slice from the mobility management network element. If the slice authentication result corresponding to the first slice is that slice authentication succeeds, the network slice selection network element performs user counting on the first slice. The network slice selection network element determines, based on a user counting result corresponding to the first slice, whether to allow access of a terminal device to the first slice. In this way, for a slice on which both user counting and slice authentication need to be performed, the mobility management network element first performs slice authentication, and sends a slice authentication result to the network slice selection network element, and the network slice selection network element determines, based on the slice authentication result, whether to allow access of the terminal device to the network slice. According to the method, whether to allow access of the terminal device to a specific network slice can be accurately determined.