Single Sign-On Function for 5G Network Slice Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile operators face challenges in delivering diverse network performance characteristics for emerging applications like remote operation of robots and self-driving cars, requiring efficient service differentiation and authentication processes to manage premium and regular users effectively, while existing systems burden users with multiple authentication credentials and security risks.
Innovation Solution
The introduction of a Single Sign-On Function (SOF) that bypasses service application authentication by securely mapping user credentials from the mobile network domain to service applications, using digitally signed single sign-on tickets and cookies for seamless access, allowing premium users to skip authentication steps and enabling differentiated services across various slice types.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication processes are used for each service application, then security is maintained through multiple authentication credentials, but user convenience deteriorates due to the burden of managing multiple authentication credentials
Solution Approach 1:
The patent segments the authentication process into two distinct parts: (1) mobile network authentication handled by the SOF, and (2) service application authentication handled by the application server. By separating these functions and allowing the SOF to provide authentication bypass for premium users, the system maintains security through structured authentication paths while improving user convenience by eliminating redundant credential management.
Solution Approach 2:
The Single Sign-On Function (SOF) acts as an intermediary between the mobile network authentication system and service application authentication systems. It receives authentication information from the mobile network, validates service requests, and provides authentication bypass when appropriate. This intermediary role allows the system to maintain security through controlled authentication paths while eliminating the need for users to manage multiple credentials manually.
2Adaptability or versatility
If network slicing is implemented to provide service differentiation, then network performance characteristics are improved for different service types, but system complexity increases due to multiple control functions and authentication mechanisms
Solution Approach 1:
The SOF is designed as a universal control function that handles authentication bypass for multiple service types and network slices. Rather than creating separate authentication mechanisms for each slice, the SOF provides a unified authentication bypass capability that works across eMBB, uRLLC, and massive IoT slices. This multi-functional approach enables service differentiation while avoiding the complexity of multiple separate authentication systems.
Solution Approach 2:
The patent merges the authentication bypass functionality into the existing 5G control plane architecture, integrating the SOF with the AMF, SMF, and UDM functions. By combining authentication bypass with the existing network slice management infrastructure rather than creating standalone systems, the patent reduces overall system complexity while maintaining service differentiation capabilities.
3Ease of operation
If premium users receive authentication bypass service, then user experience is improved through simplified access, but network control complexity increases due to the need to manage different authentication paths
Solution Approach 1:
The SOF performs preliminary authentication by receiving authentication information from the mobile network before the user accesses service applications. During this preliminary authentication phase, the SOF determines whether the user qualifies for authentication bypass based on their subscription and service type. This preliminary action simplifies the user experience by handling authentication decisions in advance, while the standardized integration with existing network functions keeps control complexity manageable.
Solution Approach 2:
The SOF implements a feedback mechanism where it receives authentication information from the mobile network, determines authentication bypass eligibility, and communicates decisions back to the service application. This structured feedback loop allows the network to maintain control over authentication paths while providing simplified access to eligible users. The feedback mechanism ensures that premium users receive the improved user experience through automatic authentication bypass without requiring complex manual control.
Data Source
AI summary
A new control function is defined for the control plane of a 5G mobile network to enable the operator's mobile user, who is using a premium network slice, to access application services on the public Internet, by operator sign-on only when accessing the application on said slice. This unique single sign-on capability allows the user to bypass the service authentication after operator authenticates the mobile device by the user session establishment procedure. The new function registers a plurality of service applications, which sign-up for single sign-on capability. It also coordinates the mapping and storage of credentials of the user across the mobile operator's service and the service provider's application for each of said plurality of service applications, and transfers user credentials to the application so that the user's sign-in step is bypassed.


