Unified Access Control for Private Slices in PLMN
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current wireless communication systems, particularly in 5G networks, face challenges in providing unified access control for user equipment (UE) accessing non-public networks and private slices within public land mobile networks (PLMNs), especially when third-party operators manage these networks, leading to security and control issues.
Innovation Solution
The implementation of a Unified Access Control (UAC) mechanism that includes provisioning access control parameters to UE through a Policy Control Function (PCF) and Access and Mobility Management Function (AMF), using Network Exposure Function (NEF) and other network entities to manage access identities, categories, and configurations, ensuring secure access to authorized network slices and non-public networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If unified access control is implemented for non-public networks and private slices, then security and control are improved, but device complexity increases
Solution Approach 1:
The access control mechanism is designed to serve multiple network types (non-public networks and private slices within PLMN) through a single unified framework. The PCF and AMF work together to provide universal access control functionality that handles both NPN and private slice scenarios, eliminating the need for separate control mechanisms for each network type.
Solution Approach 2:
The Policy Control Function (PCF) acts as an intermediary that receives access control decisions from the Access and Mobility Management Function (AMF) and translates them into actionable access control information. This intermediary layer simplifies the overall control mechanism by centralizing policy decision logic and distributing it efficiently to relevant network elements.
2Reliability
If access control parameters are provisioned through PCF and AMF, then access control reliability is improved, but network complexity increases
Solution Approach 1:
The access control function is segmented into distinct responsibilities: the AMF handles access control decisions based on subscriber data and network conditions, while the PCF handles policy translation and distribution. This segmentation allows each function to be optimized independently and simplifies the overall network architecture by dividing complex control tasks into manageable modules.
Solution Approach 2:
Access control parameters and policies are pre-configured and stored in the network entities before actual access control operations are needed. The PCF provisions access control information in advance based on pre-established policies, so that when access control decisions are required, the necessary parameters are already ready, reducing real-time processing complexity.
3Adaptability or versatility
If third-party operators manage network slices, then network versatility is improved, but trust and security control are worsened
Solution Approach 1:
The access control mechanism incorporates feedback loops where the AMF continuously monitors access control decisions and the PCF adjusts policies based on observed behavior and network conditions. This feedback mechanism ensures that third-party operators operating network slices maintain trust relationships by providing continuous verification and adjustment of access control parameters.
Solution Approach 2:
The access control system dynamically adjusts policies and parameters based on real-time network conditions, subscriber characteristics, and operational requirements. This dynamic capability allows the system to adapt to changing trust requirements and network states, enabling third-party operators to manage network slices with evolving security needs while maintaining controlled trust relationships.
Data Source
AI summary
Systems and methods provide user equipment (UE) access parameters for access control when, for example, the UE is accessing a non-public network, the UE is accessing a private slice in a public land mobile network (PLMN), the UE is accessing a non-public network for PLMN service, and/or the UE is accessing a private slice in a PLMN for a non-public network service.


