5G Slice Authentication Across Equivalent PLMNs and Pending NSSAI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 3GPP 5G network slice-specific authentication and authorization (NSSAA) procedures face issues such as handling of Pending NSSAI across equivalent PLMNs, improper handling of back-off timers during 5GSM secondary authentication, and blocking of non-slice-related services like location services when no allowed NSSAI is available.

Innovation Solution

The UE stores pending NSSAI for all equivalent PLMNs, stops back-off timers upon receiving a PDU SESSION AUTHENTICATION COMMAND, and allows certain services like location services during NSSAA even without an allowed NSSAI.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single unified authentication and authorization framework is used for all network slices, then device complexity is reduced and ease of operation is improved, but security reliability deteriorates because the framework cannot account for slice-specific security requirements and constraints

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidauthentication framework complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication and authorization framework into slice-specific components. Each network slice has its own authentication rules, authorization policies, and security parameters defined in the network slice template. This allows the system to handle different security requirements for different slices while maintaining a unified overall architecture, thus improving security reliability without excessive complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-defining authentication and authorization parameters in network slice templates before actual network slice instantiation. The network slice template includes pre-configured security rules, authentication methods, and authorization policies that are automatically applied when a network slice is created, eliminating the need for complex real-time configuration and improving both security and operational simplicity.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If network slice-specific authentication and authorization parameters are implemented, then security reliability and adaptability are improved, but device complexity increases due to the need to manage and enforce slice-specific rules

Engineering Contradiction:
Improveauthentication adaptabilityVSAvoidparameter management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamics by making the authentication and authorization framework adaptable to different network slice types. The system can dynamically select and apply appropriate authentication methods and authorization rules based on the specific network slice template being used. This allows high adaptability for different slice requirements while the underlying framework manages the complexity through automated template-based configuration.

Inventive Principle:
Principle #15Dynamics

3Reliability

If slice-specific authentication rules are enforced, then security reliability is improved, but processing time and operational complexity increase

Engineering Contradiction:
Improveauthorization reliabilityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent reduces authentication processing time by performing preliminary configuration of authorization rules and authentication parameters in the network slice templates. When a user equipment requests authentication for a specific network slice, the system can quickly retrieve and apply the pre-defined rules from the template without requiring complex real-time decision-making, thus maintaining high authorization reliability while minimizing processing time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4140192B1Network slice-specific authentication and authorization
Publication Date: 2026.05.06 SAMSUNG ELECTRONICS CO LTD
  • EP4140192B1 patent drawingFigure 1a~1b
  • EP4140192B1 patent drawingFigure 2
  • EP4140192B1 patent drawingFigure 3

AI summary

There is disclosed a method for a user equipment (UE) in a wireless communication system, receiving pending network slice selection assistance information (NSSAI) including one or more single NSSAIs (S-NSSAIs), and applying the received pending NSSAI to at least one second public land mobile network (PLMN) in the registration area, wherein the UE is assigned to a registration area comprising two or more tracking areas (TAs) including at least a first set of TAs belonging to a first public land mobile network (PLMN) to which the UE is registered.