UE Network Slice Status Handling for Pending NSSAI Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The introduction of Network Slice-Specific Authentication and Authorization (NSSAA) in 3GPP Release 16 has led to cases where UEs can use S-NSSAIs without performing the necessary authentication, potentially causing unauthorized use of network slices, as current specifications do not provide a solution for updating the status of S-NSSAIs in the UE.

Innovation Solution

A method and apparatus are introduced to change the status of S-NSSAIs in the UE by sending Pending NSSAI, performing NSSAA procedures, and updating the Allowed NSSAI and Pending NSSAI, with cause values indicating the status changes, thereby ensuring proper authentication and authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the AMF updates the Allowed NSSAI with S-NSSAI after NSSAA is needed, then the UE can use the S-NSSAI without re-authentication, but this causes unauthorized use of network slice

Engineering Contradiction:
ImproveUE operation convenienceVSAvoidNetwork security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the NSSAI into different status categories: Allowed NSSAI (for slices where NSSAA is not needed), Pending NSSAI (for slices where NSSAA is needed but not yet completed), and Rejected NSSAI (for slices where NSSAA failed). This segmentation allows the UE to distinguish between slices that can be used immediately and those that require authentication, preventing unauthorized access while maintaining operational convenience for authorized slices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic status management for S-NSSAI, where the status can change from Allowed to Pending when NSSAA becomes necessary. The UE continuously monitors the status of each S-NSSAI and adjusts its behavior accordingly - using slices with Allowed status while blocking those with Pending status. This dynamic approach ensures security is maintained without permanently restricting legitimate slices.

Inventive Principle:
Principle #15Dynamics

2Speed

If the UE stores S-NSSAI in Allowed NSSAI, then the UE can access network slice quickly, but the UE may use the slice without performing required NSSAA procedure

Engineering Contradiction:
ImproveNetwork slice access speedVSAvoidAuthentication compliance
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent divides the NSSAI into distinct status groups within the UE's storage structure. The Pending NSSAI is separated from the Allowed NSSAI, allowing the UE to quickly identify which slices require authentication and which are ready for immediate use. This segmentation enables fast access to authorized slices while ensuring authenticated slices are properly blocked.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary status marking where the AMF marks S-NSSAI with a Pending status before actually completing the NSSAA procedure. This preliminary action gives the UE advance warning that authentication is required, allowing the UE to prepare appropriately and block access before the actual authentication failure could occur, thus preventing unauthorized use while maintaining speed for already-authenticated slices.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If the AMF sends S-NSSAI in Allowed NSSAI without indicating NSSAA requirement, then the UE can use the slice immediately, but the network cannot ensure proper authentication

Engineering Contradiction:
ImproveNetwork slice deployment efficiencyVSAvoidAuthentication assurance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the network's response into distinct categories: Allowed NSSAI for slices where NSSAA is not required, Pending NSSAI for slices where NSSAA is required but not completed, and Rejected NSSAI for slices where NSSAA failed. This segmentation allows the network to efficiently communicate the authentication status of each slice, maintaining deployment efficiency while ensuring authentication assurance through clear status indication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a feedback mechanism where the AMF provides explicit status information about each S-NSSAI to the UE. The UE receives feedback indicating whether each slice requires NSSAA, is pending authentication, or has been rejected. This feedback loop ensures the UE understands the authentication requirements and adjusts its behavior accordingly, maintaining network efficiency while ensuring proper authentication through informed UE action.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250374174A1Method of communication apparatus and communication apparatus
Publication Date: 2025.12.04 NEC CORP
  • US20250374174A1 patent drawing
  • US20250374174A1 patent drawing
  • US20250374174A1 patent drawing

AI summary

The current 3GPP specification(s) does not provide solution for a problem such as an unauthorized use of network slice by the UE.An aspect of this disclosure includes a method of a communication apparatus. The method includes changing status of Single Network Slice Selection Assistance Information (S-NSSAI) included in Allowed Network Slice Selection Assistance Information (NSSAI). The method includes sending Pending NSSAI including the S-NSSAI in a case of changing the status.