Slice-Specific Authentication in Mobile Network Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile telephony networks face challenges in efficiently managing Network Slicing, particularly in performing Slice Specific Secondary Authentication (SSSA) procedures, which can lead to delays and inefficiencies in user access to network slices.

Innovation Solution

The method involves a wireless transmit/receive unit (WTRU) performing primary authentication during registration with an Access and Mobility Management Function (AMF), receiving a message indicating successful registration, and subsequently undergoing Slice Specific Secondary Authentication (SSSA) for accessing specific network slices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If SSSA procedures are performed during the registration process, then network security and authorization are improved, but registration time and user access delay increase

Engineering Contradiction:
Improvenetwork securityVSAvoidregistration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs Slice Specific Secondary Authentication (SSSA) procedures during the registration process, executing authentication actions in advance before the user actually accesses network slices. This preliminary authentication ensures security requirements are met while preparing the user equipment (UE) for future slice access, thereby reducing authentication delays when users actually need to access slices.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent separates authentication procedures into distinct phases: primary authentication during registration, and slice-specific secondary authentication (SSSA) that can be performed either during registration or on-demand before slice access. This segmentation allows the system to flexibly manage authentication timing, performing security checks at appropriate stages without blocking the entire registration process.

Inventive Principle:
Principle #1Segmentation

2Manufacturing precision

If SSSA is performed for all slices during registration, then authorization accuracy is improved, but network processing load and complexity increase

Engineering Contradiction:
Improveauthorization accuracyVSAvoidnetwork processing complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent implements flexible SSSA execution where authentication can be performed for only certain slices rather than all slices during registration. The network can determine whether to perform SSSA based on subscription information, network policies, and specific slice requirements. This partial action approach maintains authorization accuracy for required slices while avoiding unnecessary processing overhead for slices that don't require additional authentication.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent enables dynamic SSSA execution where the authentication process can adapt based on real-time conditions. The network can choose to perform SSSA during registration for some users/slices and defer it to on-demand execution for others, allowing the system to optimize processing load dynamically based on network conditions, user subscriptions, and slice priorities.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250168636A1Methods and apparatuses for slice-specific authentication
Publication Date: 2025.05.22 INTERDIGITAL PATENT HOLDINGS INC
  • US20250168636A1 patent drawing
  • US20250168636A1 patent drawing
  • US20250168636A1 patent drawing

AI summary

A method for slice authentication in a mobile telephone network. A WTRU performs, during a registration procedure with an Access and Mobility management Function, AMF, of a network, primary authentication of the WTRU, during which registration procedure the WTRU receives from the AMF a message indicating successful registration and including at least one of an indication of at least one network slice-specific authentication and authorization for slice access, SSSA, procedure to be executed following the registration procedure, a list of slices for which the WTRU is allowed access, and a list of slices for which SSSA is needed for access by the WTRU, and performs, after successful registration, at least one SSSA of the WTRU for accessing a first slice in the network.