Temporary Network Slice Identifier for 5G Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In 5G networks utilizing network function virtualization (NFV), the correlation between network slice identifiers and user equipment (UE) subscription identifiers can lead to privacy vulnerabilities, enabling denial-of-service attacks by allowing attackers to identify groups of users on the same network slice.

Innovation Solution

A method is introduced where user equipment (UE) and network entities generate temporary network slice identifiers based on user parameters, network parameters, and subscriber-related information, ensuring privacy by maintaining a one-to-one mapping between these identifiers, thus protecting the network slice identifier privacy during attachment to a network slice.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network slice identifier is used directly for UE attachment, then network slice selection is simplified, but UE privacy is compromised and denial-of-service attacks become possible

Engineering Contradiction:
Improvenetwork slice selectionVSAvoidprivacy vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a temporary network slice identifier as an intermediary between the UE and the network slice. This temporary identifier is generated based on the original network slice identifier but does not directly expose it. The temporary identifier acts as a mediator that allows network slice selection while protecting the original identifier from direct exposure, thus preventing attackers from correlating UEs on the same network slice.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a copy of the network slice identifier in the form of a temporary identifier. This copy contains the necessary information for network slice selection but is designed to be non-correlatable with the original identifier. The temporary identifier serves as a functional duplicate that protects the privacy of the original identifier while maintaining operational functionality.

Inventive Principle:
Principle #26Copying

2Reliability

If physical separation of network entities is used, then security protection is provided, but network function virtualization cannot be implemented

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork function virtualization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The temporary network slice identifier acts as an intermediary that enables virtualized network functions to maintain security properties similar to physical separation. By using this temporary identifier, the system can virtualize network functions while preventing direct correlation attacks that would otherwise be possible in a virtualized environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of the network slice identifier from a static, direct identifier to a dynamic temporary identifier that is generated based on specific parameters including the original network slice identifier, a random value, and a counter. This parameter transformation enables virtualization while maintaining security by making the identifier non-correlatable.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If temporary network slice identifier is generated using multiple parameters, then privacy protection is enhanced, but generation complexity increases

Engineering Contradiction:
Improveprivacy protectionVSAvoididentifier generation
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a universal generation mechanism that can be applied to any network slice identifier using the same algorithm. The generation function takes multiple inputs (original identifier, random value, counter) and produces a temporary identifier that works across different network slices and scenarios. This multi-functionality reduces the need for slice-specific customization while maintaining strong privacy protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12035230B2Method and apparatus for attaching user equipment to a network slice
Publication Date: 2024.07.09 ZTE CORP
  • US12035230B2 patent drawing
  • US12035230B2 patent drawing
  • US12035230B2 patent drawing

AI summary

A method for attaching user equipment, UE, with a network slice supported by one or more network entities is described herein. A user parameter and subscriber-related information identifying the UE are sent from the UE to at least one of the one or more network entities. A network parameter is sent to the UE. A temporary network slice identifier is generated at (i) the UE and at (ii) at least one of the one or more network entities for use in attaching the UE to the network slice. The temporary network slice identifier is generated based on (a) the user parameter, (b) the network parameter, and (c) subscriber-related information. The temporary network slice identifier generated at the UE may be identical to the temporary network slice identifier generated at the at least one network entity.