Shared RAN Onboarding for Network Slice Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G networks face challenges in efficiently onboarding and authenticating user equipment for network slices, particularly in Non-Public Networks (NPNs), due to the lack of standardized procedures for transmitting and receiving onboarding and authentication information between user equipment and network functions.
Innovation Solution
The method involves broadcasting onboarding support information and authentication requirements via radio access networks and access and mobility management functions to user equipment, allowing for the registration and connection establishment with selected network slices, including the transmission of network slice-specific credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If standardized procedures for transmitting onboarding and authentication information are implemented, then network access efficiency is improved, but device complexity increases
Solution Approach 1:
The patent segments the onboarding and authentication information into distinct standardized message formats (e.g., System Information Blocks, RRC messages) that can be independently processed. This segmentation allows user equipment to handle complex authentication procedures through modular message exchanges, improving network access efficiency while managing device complexity through structured information organization.
Solution Approach 2:
The patent implements universal standardized procedures that can be applied across multiple network types (PLMN, SNPN, PNI-NPN) and authentication scenarios. These multi-functional procedures enable user equipment to handle diverse onboarding and authentication requirements using a unified framework, improving overall network access efficiency without proportionally increasing device complexity through reuse of common processing logic.
2Reliability
If onboarding procedures are carried out for all user equipment accessing NPNs, then network security is improved, but loss of time increases
Solution Approach 1:
The patent performs preliminary actions by broadcasting onboarding support information and authentication requirements before actual user equipment access attempts. Network functions pre-configure and transmit authentication parameters, credential requirements, and onboarding procedures in advance (e.g., through system information broadcasts), so that user equipment can prepare appropriate authentication credentials beforehand, reducing onboarding time while maintaining security through pre-established authentication frameworks.
Solution Approach 2:
The patent enables user equipment to autonomously perform onboarding and authentication procedures by providing self-service capabilities. User equipment can independently retrieve broadcasted authentication requirements, select appropriate network slices, and execute credential verification without manual intervention. This self-service approach maintains network security through standardized authentication while significantly reducing the time loss associated with manual onboarding processes.
3Reliability
If network slice-specific credentials are transmitted during registration, then authentication reliability is improved, but loss of information increases
Solution Approach 1:
The patent applies local quality by transmitting network slice-specific credentials and authentication information targeted to particular network slices rather than universally. Each network slice receives only the credentials and parameters relevant to its specific authentication requirements, minimizing unnecessary information transmission. This targeted approach improves authentication reliability for each slice while reducing overall information loss by avoiding redundant credential distribution across all slices.
Data Source
AI summary
Methods, apparatuses, and computer program products are described that support transmission and receipt of onboarding support and/or authentication requirement information to a UE for registration with a network, such as a PLMN and/or SNPN, and/or network slice, via a RAN and/or the like. The onboarding support and/or authentication requirement information may be specifically configured for one or more networks, and/or network slices thereof, that utilize a shared RAN in communication with the UE. The UE selects a cell and network and/or network slice based on the onboarding support and/or authentication requirement information. The UE may camp on the shared RAN. The one or more networks comprise at least a RAN and respective AMF that provide the onboarding support and/or authentication requirement information to the UE before, or when, the UE contacts the AMF associated with the network and/or network slice.


