Slice-Specific Security Contexts for 5G Privacy Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing 5G systems lack the ability to enforce slice-specific security requirements, leading to breaches in data privacy between operator and third-party services due to the use of a common security context, which fails to meet the varying privacy needs of different network slices.
Innovation Solution
Implement a Common Security Anchor Function (CSEAF) in the 5G core network to determine and enforce network slice security requirements, ensuring slice-specific security isolation and key provisioning, managing security contexts for different slices and domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a common security context is used for all network slices, then device complexity is reduced and ease of operation is improved, but data privacy and security isolation between different slices deteriorates
Solution Approach 1:
The patent segments the common security context into slice-specific security contexts. The UDM retrieves SSI for specific network slices and provides them to the AMF, which then enforces slice-specific security. This segmentation allows different security parameters to be applied to different slices while maintaining a unified security management architecture.
Solution Approach 2:
The patent implements local quality by applying different security requirements to different network slices based on their specific needs. The SSI contains security parameters tailored to each slice's privacy and security requirements, allowing operator services and third-party services to have customized security profiles within the same network infrastructure.
2Reliability
If slice-specific security requirements are enforced, then data privacy and security isolation between slices is improved, but device complexity and security management overhead increases
Solution Approach 1:
The patent introduces the UDM as an intermediary that manages slice-specific security information. The UDM retrieves SSI from the network slice and provides it to the AMF, which then enforces the security requirements. This intermediary approach centralizes security management complexity in the UDM while keeping the AMF and UE implementations relatively simple.
Solution Approach 2:
The patent implements a universal security management framework where the UDM handles multiple functions: retrieving SSI for different slices, managing security contexts for both operator and third-party services, and providing slice-specific security information to appropriate network functions. This multi-functionality reduces the need for separate dedicated systems for each slice.
3Ease of manufacture
If common security context is used across all slices, then ease of manufacture and deployment is improved, but adaptability to different service provider requirements deteriorates
Solution Approach 1:
The patent implements dynamic security context retrieval where the UDM fetches SSI specific to each network slice and service provider requirements. The security context is not static but dynamically adapted based on the slice type (operator service or third-party service) and the specific security requirements of each service provider, allowing flexible deployment scenarios.
Solution Approach 2:
The patent enables parameter changes in security contexts based on slice-specific requirements. The SSI contains security parameters that can be modified for different slices, allowing the same network infrastructure to adapt to varying service provider requirements through parameter adjustment rather than structural changes.
Data Source
AI summary
Apparatuses, methods, and systems are disclosed for determining and enforcing service specific network slice security. One apparatus in a mobile communication network includes processor that performs primary authentication with a mobile communication network and a transceiver that receives a SMC message comprising SSI. The processor applies slice security for control plane and user plane traffic related to a network slice according to a Security Requirement Type indicated in the SSI.


