5G UE NSSAI Management for Slice Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the 5G System (5GS), there is a lack of specific measures and methods for managing information related to pending network slices during the Network Slice-specific Authentication and Authorization process.
Innovation Solution
A user equipment (UE) and an intra-core network apparatus are configured to manage Network Slice Selection Assistance Information (NSSAI) by storing Single NSSAI (S-NSSAI) and including it in a second NSSAI, which is used to identify slices with pending access requests due to authentication and authorization procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the network rejects access to a network slice requiring Network Slice-specific Authentication and Authorization, then the network can protect resources and security, but the UE cannot access the slice until authentication is completed
Solution Approach 1:
The network performs authentication and authorization procedures in advance before allowing slice access. The rejection with pending indication notifies the UE to perform preliminary actions (authentication) before access is granted, resolving the contradiction between security protection and access efficiency.
Solution Approach 2:
The network provides feedback to the UE through the registration reject message with specific cause values indicating pending authentication status. This feedback mechanism allows the UE to understand the rejection reason and take appropriate actions, improving access efficiency while maintaining security requirements.
2Reliability
If the UE stores rejected NSSAI information to prevent repeated rejection, then access control is improved, but the UE may incorrectly block slices that are pending authentication
Solution Approach 1:
The rejected NSSAI information is segmented into different categories based on rejection causes. The UE distinguishes between permanent rejections and pending authentication rejections, allowing selective blocking. This segmentation enables the UE to block slices with permanent rejection causes while maintaining access flexibility for slices pending authentication.
Solution Approach 2:
Different quality attributes are applied to different rejected NSSAI entries based on their rejection causes. Pending authentication rejections are treated differently from permanent rejections, with the former not triggering permanent blocking. This local quality differentiation resolves the contradiction between access control reliability and slice access flexibility.
3Measurement precision
If the network manages pending slice information separately, then authentication tracking is improved, but the system complexity increases
Solution Approach 1:
The rejected NSSAI information structure is designed to serve multiple functions: it tracks authentication status, provides feedback to the UE, and manages access control. This multi-functionality reduces the need for separate tracking mechanisms, improving authentication tracking while minimizing the increase in system complexity.
Data Source
AI summary
According to an aspect of the present invention, a procedure and a communicator for initial registration of UE or periodic or mobility-based registration for achieving Network Slice Specific Authentication and Authorization in 5GS. Furthermore, a communicator for achieving a function related to Network Slice Specific Authentication and Authorization in 5GS is provided by providing a procedure and a communicator for changing a UE configuration initiated by a network, the procedure being initiated based on the Network Slice Specific Authentication and Authorization initiated by the network and completion of the Network Slice Specific Authentication and Authorization.


