Unified Access Control for Private Slices in PLMN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current wireless communication systems, particularly in 5G networks, face challenges in providing unified access control for user equipment (UE) accessing non-public networks and private slices within public land mobile networks (PLMNs), especially when third-party operators manage these networks, leading to security and control issues.

Innovation Solution

The implementation of a Unified Access Control (UAC) mechanism that includes provisioning access control parameters to UE through a Policy Control Function (PCF) and Access and Mobility Management Function (AMF), using Network Exposure Function (NEF) and other network entities to manage access identities, categories, and configurations, ensuring secure access to authorized network slices and non-public networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If unified access control is implemented for non-public networks and private slices, then security and control are improved, but device complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control mechanism is designed to serve multiple network types (non-public networks and private slices within PLMN) through a single unified framework. The PCF and AMF work together to provide universal access control functionality that handles both NPN and private slice scenarios, eliminating the need for separate control mechanisms for each network type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The Policy Control Function (PCF) acts as an intermediary that receives access control decisions from the Access and Mobility Management Function (AMF) and translates them into actionable access control information. This intermediary layer simplifies the overall control mechanism by centralizing policy decision logic and distributing it efficiently to relevant network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control parameters are provisioned through PCF and AMF, then access control reliability is improved, but network complexity increases

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidnetwork entity complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control function is segmented into distinct responsibilities: the AMF handles access control decisions based on subscriber data and network conditions, while the PCF handles policy translation and distribution. This segmentation allows each function to be optimized independently and simplifies the overall network architecture by dividing complex control tasks into manageable modules.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Access control parameters and policies are pre-configured and stored in the network entities before actual access control operations are needed. The PCF provisions access control information in advance based on pre-established policies, so that when access control decisions are required, the necessary parameters are already ready, reducing real-time processing complexity.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If third-party operators manage network slices, then network versatility is improved, but trust and security control are worsened

Engineering Contradiction:
Improvenetwork slice flexibilityVSAvoidtrust relationship
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The access control mechanism incorporates feedback loops where the AMF continuously monitors access control decisions and the PCF adjusts policies based on observed behavior and network conditions. This feedback mechanism ensures that third-party operators operating network slices maintain trust relationships by providing continuous verification and adjustment of access control parameters.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The access control system dynamically adjusts policies and parameters based on real-time network conditions, subscriber characteristics, and operational requirements. This dynamic capability allows the system to adapt to changing trust requirements and network states, enabling third-party operators to manage network slices with evolving security needs while maintaining controlled trust relationships.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12177776B2Systems, methods, and devices for access control for private slices in a PLMN
Publication Date: 2024.12.24 APPLE INC
  • US12177776B2 patent drawing
  • US12177776B2 patent drawing
  • US12177776B2 patent drawing

AI summary

Systems and methods provide user equipment (UE) access parameters for access control when, for example, the UE is accessing a non-public network, the UE is accessing a private slice in a public land mobile network (PLMN), the UE is accessing a non-public network for PLMN service, and/or the UE is accessing a private slice in a PLMN for a non-public network service.