Token-Based Network Slice Authorization for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless networks face challenges in providing differentiated Quality of Service (QoS) to various applications without compromising user privacy, as they often require application identifiers to implement routing rules and Service Level Agreements (SLAs), which can infringe on user anonymity.

Innovation Solution

The implementation of a Slicing Authorization System (SAS) that uses tokens to authorize applications to access specific network slices, allowing applications to request communication sessions without revealing their identity, thereby maintaining user privacy while ensuring appropriate QoS treatment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application identifiers are provided to the network to implement routing rules and QoS, then differentiated service levels can be ensured, but user privacy and anonymity are compromised

Engineering Contradiction:
ImproveQoS treatmentVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a proxy client as an intermediary between the application and the network. The proxy client receives traffic from the application, attaches a token identifier instead of application identity to the traffic, and forwards it to the network. The network uses the token to route traffic and provide QoS without learning the actual application identity, thus maintaining user privacy while ensuring differentiated service levels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network slices are created to provide differentiated services, then QoS requirements can be met, but network complexity increases

Engineering Contradiction:
ImproveQoS fulfillmentVSAvoidnetwork structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the network into multiple network slices, each dedicated to specific applications or service types. Each slice is identified by a unique token and can be independently configured with specific QoS parameters. This segmentation allows the network to provide differentiated services to different applications simultaneously while managing complexity through modular slice design.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If application identity is revealed to the network for proper traffic handling, then routing rules can be applied, but user anonymity is lost

Engineering Contradiction:
Improvetraffic handlingVSAvoidapplication anonymity
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent uses token identifiers as copies or representations of application identity. Instead of transmitting the actual application identity to the network, the system transmits a token that copies the necessary identification functionality. The token serves as a placeholder that allows the network to perform routing and QoS operations without revealing the true application identity, thus maintaining anonymity while enabling proper traffic handling.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12075248B2Systems and methods for application-anonymous slice selection in a wireless network
Publication Date: 2024.08.27 VERIZON PATENT & LICENSING INC
  • US12075248B2 patent drawing
  • US12075248B2 patent drawing
  • US12075248B2 patent drawing

AI summary

A system described herein may maintain information associating one or more tokens to one or more network slices associated with a network. The system may receive a request, from an application executing at a User Equipment (“UE”), for communication session information, where the request includes a particular token. The system may identify a particular network slice associated with the particular token based on the information associating the one or more tokens to the one or more network slices. The system may receive communication session information, associated with the particular network slice, from the network, and may provide the communication session information to the application. The application may use the communication session information to communicate with the network via the particular network slice. The application may use such communication session information without providing an application identifier to the network.