Network Slice Selection Assistance Information Encryption in 5G
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network slice selection procedures in 5G wireless communication networks reveal sensitive information about the network slices subscribed to by user equipment (UE), compromising user privacy, as Network Slice Selection Assistance Information (NSSAI) is sent in both RRC and NAS layers over the open air interface.
Innovation Solution
The NSSAI is encrypted using public key cryptography, and the encrypted information is included in the NAS registration request, while an AMF selection ID can replace NSSAI in RRC, or both may be encrypted, ensuring that only the network function with the private key can decrypt it, thus maintaining privacy.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If NSSAI is sent in both RRC and NAS layers over the air interface, then the network can select the correct network slice(s) for the UE, but sensitive information about subscribed network slices is revealed, compromising user privacy
Solution Approach 1:
The patent introduces an intermediary encryption mechanism using public key cryptography. The NSSAI information is encrypted using the network's public key before being transmitted over the air interface. This intermediary encryption layer prevents direct exposure of sensitive slice subscription information while still allowing the network to decrypt and process the information using its private key, thus resolving the contradiction between information transmission and privacy protection
Solution Approach 2:
The patent changes the state of the NSSAI information from plaintext to encrypted form. By applying encryption transformation, the information maintains its functional value for network slice selection while changing its representational state to protect sensitivity. The encrypted NSSAI can still be processed by the network infrastructure but appears as protected data over the air interface, addressing both information loss prevention and privacy protection
2Productivity
If NSSAI is included in RRC connection establishment, then AMF selection can be optimized to avoid unnecessary re-directions, but the complexity of the registration procedure increases
Solution Approach 1:
The patent applies preliminary encryption action to the NSSAI information before it is included in the RRC connection establishment. By pre-encrypting the NSSAI using the network's public key, the system enables efficient AMF selection based on encrypted information without requiring additional decryption steps during the connection establishment phase. This preliminary preparation maintains productivity benefits while managing complexity through standardized cryptographic operations
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A communication device, network node and methods therein in for handling network slices in a wireless communication network are disclosed. The communication device encrypts Network Slice Selection Assistance information, NSSAI, using public key cryptography and includes the encrypted NSSAI in a Non Access Stratum, NAS, registration request. Then the communication device sends a Radio Resource Control, RRC, request to the network node including the NAS registration request. The network node receives the RRC connection request from the communication device and selects a network function based on information in the RRC connection request. The network node forwards the NAS registration request to the network function and forwards to the communication device a NAS registration response received from the network function after the network function decrypting the NSSAI using a PLMN private key.