Slice-Specific Access Control Using Generic Subscription Identifiers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Wireless communication networks lack efficient mechanisms for secondary or slice-specific access control, particularly when dealing with external data networks or network slices, leading to potential authentication and authorization failures and ambiguities due to the absence of generic subscription identifiers.

Innovation Solution

Implementing a data management network node that stores subscription data and selectively triggers or refrains from triggering secondary or slice-specific access control procedures based on the presence of a generic subscription identifier, such as GPSI, ensuring that procedures are only initiated when the identifier is available, thereby preventing failures and ambiguities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secondary or slice-specific access control procedures are triggered for all devices subscribed to external data networks or network slices, then external networks can authenticate or authorize devices, but authentication failures and ambiguities occur when generic subscription identifiers are not available

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidaccess control procedure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary checking of subscription data to determine the presence of generic subscription identifiers (GPSI) before triggering secondary access control procedures. This preliminary action prevents authentication failures by ensuring necessary identifiers are available before initiating external authentication processes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies different access control procedures based on local conditions - devices with GPSI undergo secondary access control while devices without GPSI use only primary access control. This local differentiation resolves ambiguities by tailoring the authentication process to each device's specific subscription characteristics.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If secondary access control procedures are implemented for devices without generic subscription identifiers, then external networks can attempt authentication, but the procedures fail and waste network resources

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidnetwork resource waste
Core Design Contradiction:
Adaptability or versatilityVSLoss of energy

Solution Approach 1:

The system checks subscription data in advance to identify devices with GPSI before initiating secondary access control. This preliminary identification prevents wasteful authentication attempts on devices without generic identifiers, conserving network resources while maintaining flexibility for devices that do have identifiers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies secondary access control selectively - not to all devices, but only to those with GPSI. This partial application of the access control mechanism achieves the necessary flexibility and security for applicable devices while avoiding the resource waste that would result from universal application.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If multiple generic subscription identifiers are included in subscription data, then devices can access multiple external networks, but ambiguities occur about which identifier to use

Engineering Contradiction:
Improvemulti-network access capabilityVSAvoididentifier selection clarity
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system uses feedback from the access control procedure outcomes to determine which GPSI to use. When multiple identifiers are present, the system attempts authentication with each in sequence, using the results of each attempt as feedback to guide selection of the appropriate identifier, thereby resolving the ambiguity through iterative testing and response analysis.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12593209B2Secondary or splice-specific access control in a wireless communication network
Publication Date: 2026.03.31 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US12593209B2 patent drawing
  • US12593209B2 patent drawing
  • US12593209B2 patent drawing

AI summary

A data management network node (12) is configured for use in a wireless communication network (10). The data management network node (12) stores subscription data (14) for a wireless device (16). The data management network node (12) receives, from network equipment (26), a request that requests subscription data (14) for the wireless device (16). Responsive to the request, the data management network node (12) transmits to the network equipment (26) a response that includes at least some of the stored subscription data (14). If the subscription data (14) included in the response indicates the wireless device (16) is subscribed to use a certain data network or network slice that is subject to secondary or slice-specific access control, the subscription data (14) included in the response includes a least one generic subscription identifier for the wireless device (16).