UE Network Slice Status Handling for Pending NSSAI Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The introduction of Network Slice-Specific Authentication and Authorization (NSSAA) in 3GPP Release 16 has led to cases where UEs can use S-NSSAIs without performing the necessary authentication, potentially causing unauthorized use of network slices, as current specifications do not provide a solution for updating the status of S-NSSAIs in the UE.
Innovation Solution
A method and apparatus are introduced to change the status of S-NSSAIs in the UE by sending Pending NSSAI, performing NSSAA procedures, and updating the Allowed NSSAI and Pending NSSAI, with cause values indicating the status changes, thereby ensuring proper authentication and authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the AMF updates the Allowed NSSAI with S-NSSAI after NSSAA is needed, then the UE can use the S-NSSAI without re-authentication, but this causes unauthorized use of network slice
Solution Approach 1:
The patent segments the NSSAI into different status categories: Allowed NSSAI (for slices where NSSAA is not needed), Pending NSSAI (for slices where NSSAA is needed but not yet completed), and Rejected NSSAI (for slices where NSSAA failed). This segmentation allows the UE to distinguish between slices that can be used immediately and those that require authentication, preventing unauthorized access while maintaining operational convenience for authorized slices.
Solution Approach 2:
The patent introduces dynamic status management for S-NSSAI, where the status can change from Allowed to Pending when NSSAA becomes necessary. The UE continuously monitors the status of each S-NSSAI and adjusts its behavior accordingly - using slices with Allowed status while blocking those with Pending status. This dynamic approach ensures security is maintained without permanently restricting legitimate slices.
2Speed
If the UE stores S-NSSAI in Allowed NSSAI, then the UE can access network slice quickly, but the UE may use the slice without performing required NSSAA procedure
Solution Approach 1:
The patent divides the NSSAI into distinct status groups within the UE's storage structure. The Pending NSSAI is separated from the Allowed NSSAI, allowing the UE to quickly identify which slices require authentication and which are ready for immediate use. This segmentation enables fast access to authorized slices while ensuring authenticated slices are properly blocked.
Solution Approach 2:
The patent implements preliminary status marking where the AMF marks S-NSSAI with a Pending status before actually completing the NSSAA procedure. This preliminary action gives the UE advance warning that authentication is required, allowing the UE to prepare appropriately and block access before the actual authentication failure could occur, thus preventing unauthorized use while maintaining speed for already-authenticated slices.
3Productivity
If the AMF sends S-NSSAI in Allowed NSSAI without indicating NSSAA requirement, then the UE can use the slice immediately, but the network cannot ensure proper authentication
Solution Approach 1:
The patent segments the network's response into distinct categories: Allowed NSSAI for slices where NSSAA is not required, Pending NSSAI for slices where NSSAA is required but not completed, and Rejected NSSAI for slices where NSSAA failed. This segmentation allows the network to efficiently communicate the authentication status of each slice, maintaining deployment efficiency while ensuring authentication assurance through clear status indication.
Solution Approach 2:
The patent implements a feedback mechanism where the AMF provides explicit status information about each S-NSSAI to the UE. The UE receives feedback indicating whether each slice requires NSSAA, is pending authentication, or has been rejected. This feedback loop ensures the UE understands the authentication requirements and adjusts its behavior accordingly, maintaining network efficiency while ensuring proper authentication through informed UE action.
Data Source
AI summary
The current 3GPP specification(s) does not provide solution for a problem such as an unauthorized use of network slice by the UE.An aspect of this disclosure includes a method of a communication apparatus. The method includes changing status of Single Network Slice Selection Assistance Information (S-NSSAI) included in Allowed Network Slice Selection Assistance Information (NSSAI). The method includes sending Pending NSSAI including the S-NSSAI in a case of changing the status.


