Network Slice Selection Assistance Information Encryption in 5G

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network slice selection procedures in 5G wireless communication networks reveal sensitive information about the network slices subscribed to by user equipment (UE), compromising user privacy, as Network Slice Selection Assistance Information (NSSAI) is sent in both RRC and NAS layers over the open air interface.

Innovation Solution

The NSSAI is encrypted using public key cryptography, and the encrypted information is included in the NAS registration request, while an AMF selection ID can replace NSSAI in RRC, or both may be encrypted, ensuring that only the network function with the private key can decrypt it, thus maintaining privacy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If NSSAI is sent in both RRC and NAS layers over the air interface, then the network can select the correct network slice(s) for the UE, but sensitive information about subscribed network slices is revealed, compromising user privacy

Engineering Contradiction:
Improvenetwork slice selection informationVSAvoiduser privacy exposure
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary encryption mechanism using public key cryptography. The NSSAI information is encrypted using the network's public key before being transmitted over the air interface. This intermediary encryption layer prevents direct exposure of sensitive slice subscription information while still allowing the network to decrypt and process the information using its private key, thus resolving the contradiction between information transmission and privacy protection

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the state of the NSSAI information from plaintext to encrypted form. By applying encryption transformation, the information maintains its functional value for network slice selection while changing its representational state to protect sensitivity. The encrypted NSSAI can still be processed by the network infrastructure but appears as protected data over the air interface, addressing both information loss prevention and privacy protection

Inventive Principle:
Principle #35Parameter changes

2Productivity

If NSSAI is included in RRC connection establishment, then AMF selection can be optimized to avoid unnecessary re-directions, but the complexity of the registration procedure increases

Engineering Contradiction:
ImproveAMF selection efficiencyVSAvoidregistration procedure complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies preliminary encryption action to the NSSAI information before it is included in the RRC connection establishment. By pre-encrypting the NSSAI using the network's public key, the system enables efficient AMF selection based on encrypted information without requiring additional decryption steps during the connection establishment phase. This preliminary preparation maintains productivity benefits while managing complexity through standardized cryptographic operations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3639542B1Network, network nodes, wireless communication devices and method therein for handling network slices in a wireless communication network
Publication Date: 2023.01.04 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3639542B1 patent drawingFigure 1
  • EP3639542B1 patent drawingFigure 2
  • EP3639542B1 patent drawingFigure 3

AI summary

A communication device, network node and methods therein in for handling network slices in a wireless communication network are disclosed. The communication device encrypts Network Slice Selection Assistance information, NSSAI, using public key cryptography and includes the encrypted NSSAI in a Non Access Stratum, NAS, registration request. Then the communication device sends a Radio Resource Control, RRC, request to the network node including the NAS registration request. The network node receives the RRC connection request from the communication device and selects a network function based on information in the RRC connection request. The network node forwards the NAS registration request to the network function and forwards to the communication device a NAS registration response received from the network function after the network function decrypting the NSSAI using a PLMN private key.