5G UE NSSAI Management for Slice Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the 5G System (5GS), there is a lack of specific measures and methods for managing information related to pending network slices during the Network Slice-specific Authentication and Authorization process.

Innovation Solution

A user equipment (UE) and an intra-core network apparatus are configured to manage Network Slice Selection Assistance Information (NSSAI) by storing Single NSSAI (S-NSSAI) and including it in a second NSSAI, which is used to identify slices with pending access requests due to authentication and authorization procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the network rejects access to a network slice requiring Network Slice-specific Authentication and Authorization, then the network can protect resources and security, but the UE cannot access the slice until authentication is completed

Engineering Contradiction:
Improvenetwork securityVSAvoidaccess efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The network performs authentication and authorization procedures in advance before allowing slice access. The rejection with pending indication notifies the UE to perform preliminary actions (authentication) before access is granted, resolving the contradiction between security protection and access efficiency.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The network provides feedback to the UE through the registration reject message with specific cause values indicating pending authentication status. This feedback mechanism allows the UE to understand the rejection reason and take appropriate actions, improving access efficiency while maintaining security requirements.

Inventive Principle:
Principle #23Feedback

2Reliability

If the UE stores rejected NSSAI information to prevent repeated rejection, then access control is improved, but the UE may incorrectly block slices that are pending authentication

Engineering Contradiction:
Improveaccess controlVSAvoidslice access flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The rejected NSSAI information is segmented into different categories based on rejection causes. The UE distinguishes between permanent rejections and pending authentication rejections, allowing selective blocking. This segmentation enables the UE to block slices with permanent rejection causes while maintaining access flexibility for slices pending authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different quality attributes are applied to different rejected NSSAI entries based on their rejection causes. Pending authentication rejections are treated differently from permanent rejections, with the former not triggering permanent blocking. This local quality differentiation resolves the contradiction between access control reliability and slice access flexibility.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If the network manages pending slice information separately, then authentication tracking is improved, but the system complexity increases

Engineering Contradiction:
Improveauthentication trackingVSAvoidinformation management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The rejected NSSAI information structure is designed to serve multiple functions: it tracks authentication status, provides feedback to the UE, and manages access control. This multi-functionality reduces the need for separate tracking mechanisms, improving authentication tracking while minimizing the increase in system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12207089B2User equipment, intra-core network apparatus, and communication control method
Publication Date: 2025.01.21 SHARP KK
  • US12207089B2 patent drawing
  • US12207089B2 patent drawing
  • US12207089B2 patent drawing

AI summary

According to an aspect of the present invention, a procedure and a communicator for initial registration of UE or periodic or mobility-based registration for achieving Network Slice Specific Authentication and Authorization in 5GS. Furthermore, a communicator for achieving a function related to Network Slice Specific Authentication and Authorization in 5GS is provided by providing a procedure and a communicator for changing a UE configuration initiated by a network, the procedure being initiated based on the Network Slice Specific Authentication and Authorization initiated by the network and completion of the Network Slice Specific Authentication and Authorization.