Network Slice Access Control With NSSAA-First User Counting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to accurately determine whether to allow access of a terminal device to a network slice that requires both Network Slice Specific Authentication and Authorization (NSSAA) and user counting, leading to inefficiencies in network management and resource utilization.

Innovation Solution

A communication method where the Network Slice Selection Function (NSSF) first performs NSSAA on slices requiring both NSSAA and user counting, and then determines access based on the authentication result, reducing unnecessary user counting and signaling overheads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If both NSSAA and user counting are performed on a network slice, then authentication security and resource control are improved, but access determination accuracy deteriorates

Engineering Contradiction:
Improveresource controlVSAvoidaccess determination accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by performing NSSAA authentication before user counting. The AMF first determines whether NSSAA is required based on subscription data and requested NSSAI, then performs the authentication process. Only after successful authentication does the system proceed to user counting and access determination. This sequencing ensures that authentication security and resource control are both implemented while maintaining accurate access determination by avoiding redundant operations on unauthorized devices.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If user counting is performed on all requested slices, then resource quota control is improved, but signaling overhead increases

Engineering Contradiction:
Improveresource quota controlVSAvoidsignaling overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent applies preliminary action by performing NSSAA authentication before user counting. The AMF first determines whether NSSAA is required based on subscription data and requested NSSAI, then performs the authentication process. Only after successful authentication does the system proceed to user counting and access determination. This sequencing ensures that authentication security and resource control are both implemented while maintaining accurate access determination by avoiding redundant operations on unauthorized devices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the NSSAA authentication step as a separate preliminary process before user counting. By separating authentication from resource quota control, the system avoids performing user counting on devices that will ultimately be rejected due to authentication failure. This extraction reduces unnecessary signaling overhead while maintaining accurate resource quota control for authorized users.

Inventive Principle:
Principle #2Taking out (Extraction)

3Speed

If access determination is performed before NSSAA, then processing speed is improved, but access control accuracy deteriorates

Engineering Contradiction:
Improveprocessing speedVSAvoidaccess control accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent applies preliminary action by performing NSSAA authentication before user counting. The AMF first determines whether NSSAA is required based on subscription data and requested NSSAI, then performs the authentication process. Only after successful authentication does the system proceed to user counting and access determination. This sequencing ensures that authentication security and resource control are both implemented while maintaining accurate access determination by avoiding redundant operations on unauthorized devices.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4090083B1Communication method, apparatus, and system
Publication Date: 2025.08.20 HUAWEI TECH CO LTD
  • EP4090083B1 patent drawingFigure 1A~1B
  • EP4090083B1 patent drawingFigure 2
  • EP4090083B1 patent drawingFigure 3

AI summary

This application provides a communication method, apparatus, and system. The method includes: A network slice selection network element sends identification information of a first slice to a mobility management network element. The network slice selection network element receives a slice authentication result corresponding to the first slice from the mobility management network element. If the slice authentication result corresponding to the first slice is that slice authentication succeeds, the network slice selection network element performs user counting on the first slice. The network slice selection network element determines, based on a user counting result corresponding to the first slice, whether to allow access of a terminal device to the first slice. In this way, for a slice on which both user counting and slice authentication need to be performed, the mobility management network element first performs slice authentication, and sends a slice authentication result to the network slice selection network element, and the network slice selection network element determines, based on the slice authentication result, whether to allow access of the terminal device to the network slice. According to the method, whether to allow access of the terminal device to a specific network slice can be accurately determined.