UDM Network Slice Access Control via Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches for managing mutually exclusive access to network slices in 5G communications networks are prone to network security vulnerabilities and malicious activities, as they lack a secure and efficient method to control device access to multiple slices.

Innovation Solution

The implementation of a Unified Data Management (UDM) network function within the 5G communications network, which tracks subscription data and manages access requests, applies a network slice access-control function to determine whether a user equipment (UE) can access specific slices based on defined policies, thereby restricting or allowing access to ensure secure and controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current approaches for managing mutually exclusive access to network slices are used, then device access control is implemented, but network security vulnerabilities and malicious activities increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a dedicated access control function as an intermediary component between the UE and network slices. This function acts as a mediator that receives access requests, evaluates them against stored policies, and makes authorization decisions. By placing this intermediary in charge of access control, the system achieves reliable security without the vulnerabilities present in previous direct access approaches

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The access control function implements feedback mechanisms by continuously monitoring access requests and comparing them against stored access control policies. When a request is received, the system feedbacks by evaluating the policy conditions and adjusting access authorization accordingly, creating a closed-loop security system that adapts to different access scenarios

Inventive Principle:
Principle #23Feedback

2Ease of operation

If network slice access control is simplified, then ease of operation improves, but access security and control precision deteriorate

Engineering Contradiction:
Improveaccess control managementVSAvoidaccess security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The access control function implements self-service by automatically evaluating access requests against stored policies without requiring manual intervention. The system autonomously determines authorization decisions based on the access control policy stored in memory, making the process easy to operate while maintaining strong security through automated policy enforcement

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-storing access control policies in the access control function before access requests are received. These policies are prepared in advance and used to immediately evaluate incoming requests, enabling both easy operation through automated decision-making and reliable security through pre-defined access rules

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11937170B2Managing mutually exclusive access to network slices
Publication Date: 2024.03.19 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11937170B2 patent drawing
  • US11937170B2 patent drawing
  • US11937170B2 patent drawing

AI summary

Examples relate to managing mutually exclusive access to network slices in a communications network. A unified data management (UDM) node implementing a UDM network function of the communications network receives, from a session management function (SMF) node, a session registration request for accessing a first network slice to which a user equipment (UE) seeks access. Responsive to receiving the session registration request, the UDM node determines whether the UE has an active session registration for a second network slice, The UDM further selectively rejects the session registration request for accessing the first network slice based on a policy in response to determining that the UE has the active session registration for the second network slice.