Temporary Network Slice Identifier for 5G Privacy Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In 5G networks utilizing network function virtualization (NFV), the correlation between network slice identifiers and user equipment (UE) subscription identifiers can lead to privacy vulnerabilities, enabling denial-of-service attacks by allowing attackers to identify groups of users on the same network slice.
Innovation Solution
A method is introduced where user equipment (UE) and network entities generate temporary network slice identifiers based on user parameters, network parameters, and subscriber-related information, ensuring privacy by maintaining a one-to-one mapping between these identifiers, thus protecting the network slice identifier privacy during attachment to a network slice.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If network slice identifier is used directly for UE attachment, then network slice selection is simplified, but UE privacy is compromised and denial-of-service attacks become possible
Solution Approach 1:
The patent introduces a temporary network slice identifier as an intermediary between the UE and the network slice. This temporary identifier is generated based on the original network slice identifier but does not directly expose it. The temporary identifier acts as a mediator that allows network slice selection while protecting the original identifier from direct exposure, thus preventing attackers from correlating UEs on the same network slice.
Solution Approach 2:
The patent creates a copy of the network slice identifier in the form of a temporary identifier. This copy contains the necessary information for network slice selection but is designed to be non-correlatable with the original identifier. The temporary identifier serves as a functional duplicate that protects the privacy of the original identifier while maintaining operational functionality.
2Reliability
If physical separation of network entities is used, then security protection is provided, but network function virtualization cannot be implemented
Solution Approach 1:
The temporary network slice identifier acts as an intermediary that enables virtualized network functions to maintain security properties similar to physical separation. By using this temporary identifier, the system can virtualize network functions while preventing direct correlation attacks that would otherwise be possible in a virtualized environment.
Solution Approach 2:
The patent changes the parameter of the network slice identifier from a static, direct identifier to a dynamic temporary identifier that is generated based on specific parameters including the original network slice identifier, a random value, and a counter. This parameter transformation enables virtualization while maintaining security by making the identifier non-correlatable.
3Object-affected harmful factors
If temporary network slice identifier is generated using multiple parameters, then privacy protection is enhanced, but generation complexity increases
Solution Approach 1:
The patent implements a universal generation mechanism that can be applied to any network slice identifier using the same algorithm. The generation function takes multiple inputs (original identifier, random value, counter) and produces a temporary identifier that works across different network slices and scenarios. This multi-functionality reduces the need for slice-specific customization while maintaining strong privacy protection.
Data Source
AI summary
A method for attaching user equipment, UE, with a network slice supported by one or more network entities is described herein. A user parameter and subscriber-related information identifying the UE are sent from the UE to at least one of the one or more network entities. A network parameter is sent to the UE. A temporary network slice identifier is generated at (i) the UE and at (ii) at least one of the one or more network entities for use in attaching the UE to the network slice. The temporary network slice identifier is generated based on (a) the user parameter, (b) the network parameter, and (c) subscriber-related information. The temporary network slice identifier generated at the UE may be identical to the temporary network slice identifier generated at the at least one network entity.


