Slice-Specific Security Contexts for 5G Privacy Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing 5G systems lack the ability to enforce slice-specific security requirements, leading to breaches in data privacy between operator and third-party services due to the use of a common security context, which fails to meet the varying privacy needs of different network slices.

Innovation Solution

Implement a Common Security Anchor Function (CSEAF) in the 5G core network to determine and enforce network slice security requirements, ensuring slice-specific security isolation and key provisioning, managing security contexts for different slices and domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a common security context is used for all network slices, then device complexity is reduced and ease of operation is improved, but data privacy and security isolation between different slices deteriorates

Engineering Contradiction:
Improvesecurity management simplicityVSAvoiddata privacy protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the common security context into slice-specific security contexts. The UDM retrieves SSI for specific network slices and provides them to the AMF, which then enforces slice-specific security. This segmentation allows different security parameters to be applied to different slices while maintaining a unified security management architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by applying different security requirements to different network slices based on their specific needs. The SSI contains security parameters tailored to each slice's privacy and security requirements, allowing operator services and third-party services to have customized security profiles within the same network infrastructure.

Inventive Principle:
Principle #3Local quality

2Reliability

If slice-specific security requirements are enforced, then data privacy and security isolation between slices is improved, but device complexity and security management overhead increases

Engineering Contradiction:
Improvedata privacy protectionVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces the UDM as an intermediary that manages slice-specific security information. The UDM retrieves SSI from the network slice and provides it to the AMF, which then enforces the security requirements. This intermediary approach centralizes security management complexity in the UDM while keeping the AMF and UE implementations relatively simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal security management framework where the UDM handles multiple functions: retrieving SSI for different slices, managing security contexts for both operator and third-party services, and providing slice-specific security information to appropriate network functions. This multi-functionality reduces the need for separate dedicated systems for each slice.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If common security context is used across all slices, then ease of manufacture and deployment is improved, but adaptability to different service provider requirements deteriorates

Engineering Contradiction:
Improvenetwork deployment simplicityVSAvoidservice-specific security adaptability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security context retrieval where the UDM fetches SSI specific to each network slice and service provider requirements. The security context is not static but dynamically adapted based on the slice type (operator service or third-party service) and the specific security requirements of each service provider, allowing flexible deployment scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables parameter changes in security contexts based on slice-specific requirements. The SSI contains security parameters that can be modified for different slices, allowing the same network infrastructure to adapt to varying service provider requirements through parameter adjustment rather than structural changes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12464346B2Slice-specific security requirement information
Publication Date: 2025.11.04 LENOVO (SINGAPORE) PTE LTD
  • US12464346B2 patent drawing
  • US12464346B2 patent drawing
  • US12464346B2 patent drawing

AI summary

Apparatuses, methods, and systems are disclosed for determining and enforcing service specific network slice security. One apparatus in a mobile communication network includes processor that performs primary authentication with a mobile communication network and a transceiver that receives a SMC message comprising SSI. The processor applies slice security for control plane and user plane traffic related to a network slice according to a Security Requirement Type indicated in the SSI.