IP Library Granted Patent US 12,317,074
Granted Patent B2
US 12,317,074 · App. 18/050,586 · Granted May 27, 2025

Validating authenticity of an application accessing a network slice

Inventors: Wei Shen (Plano, TX); Mu-Jin Liu (Shanghai, CN)
H04W12/06H04W48/18
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,317,074
App. No.
18/050,586
Granted
May 27, 2025
Kind
B2
Abstract

Examples described herein relate to techniques for routing application data through a selected network slice based on validation of an application entitlement request. In some examples, an entitlement system may receive an application entitlement request corresponding to an application that is on a user equipment. The entitlement system may validate the authenticity of the application based on the application authenticity information from the entitlement request. The entitlement device may in response to validation of the application entitlement request, send an application entitlement response to the user equipment such that the user equipment selects a network slice to route application data corresponding to the application.

Claims (41)

1. A method, comprising:

receiving, by an entitlement system, an application entitlement request corresponding to an application that is on a user equipment, wherein the application entitlement request includes application authenticity information;

validating, by the entitlement system, authenticity of the application based on the application authenticity information; and

in response to validation of the application entitlement request, sending, by the entitlement system, an application entitlement response to the user equipment, wherein the application entitlement response includes application validity information that enables the user equipment to route application data corresponding to the application through a selected network slice.

2. The method of claim 1 , wherein the selected network slice is a target network slice of a communication system responsive to a successful validation of the application entitlement request.

3. The method of claim 1 , wherein the selected network slice is a default network slice of a communication system based on a condition that the validation of the application entitlement request is unsuccessful.

4. The method of claim 1 , wherein validating the authenticity of the application includes:

comparing the application authenticity information with reference authenticity information stored in a database that is accessible by the entitlement system.

5. The method of claim 4 , further comprising:

receiving, by the entitlement system, an authentication request along with the application entitlement request; and

validating, by the entitlement system, the authentication request prior to validation of the application entitlement request.

6. The method of claim 5 , wherein the authentication request is at least one of an Extensible Authentication Protocol (EAP)-Authentication and Key Agreement (AKA), an Extensible Authentication Protocol (EAP)-Authentication and Key Agreement Prime (AKA′) and other authentication protocol.

7. The method of claim 1 , further comprising:

receiving, by the entitlement system, reference authenticity information corresponding to the application from an application owner; and

storing, by the entitlement system, the reference authenticity information that is received in the database.

8. The method of claim 1 , wherein receiving the application entitlement request is performed in response to at least one of detection of the application and launching of the application on the user equipment and the application triggering a service Application Programming Interface (API) to initiate the application entitlement request.

9. The method of claim 1 , wherein the user equipment includes a User Equipment Route Selection Policy (URSP) rule that includes one or more Traffic Descriptors (TDs) and a Route Selection Descriptors (RSDs); and based on the application validity information, the user equipment refers to one or more TDs to select an RSD to route the application data.

10. A system, comprising:

a processor; and

a storage medium operatively connected to the processor and storing instructions that when executed, causes the processor to:

receive reference authenticity information corresponding to an application from an application owner;

store the reference authenticity information that is received in a database;

receive an application entitlement request corresponding to the application from a user equipment (UE), wherein the application entitlement request includes application authenticity information;

validate authenticity of the application by comparing the application authenticity information with the reference authenticity information stored in the database; and

in response to validation of the application entitlement request, send an application entitlement response to the user equipment, wherein the application entitlement response includes application validity information, and based on the application entitlement response, the UE refers to a User Equipment Router Selection Policy (URSP) rule available on the UE to select a network slice to route application data corresponding to the application.

11. The system of claim 10 , wherein the instructions that cause the processor to send the application entitlement response, further includes instructions that cause the processor to:

send the application entitlement response to the user equipment such that the user equipment routes data through a default network slice due to failed validation of the application entitlement request.

12. The system of claim 10 , wherein the reference authenticity information includes at least one of an application signature, an application identifier, and an Operating System (OS) information.

13. The system of claim 10 , wherein the database is at least one of a local storage of the system, a network-connected storage, and remotely disposed storage.

14. The system of claim 10 , wherein the system is communicatively coupled to a Mobile Network Operator (MNO) network for authentication of the user equipment prior to validation of the application entitlement request.

15. The system of claim 10 , wherein the URSP rule is provided to the user equipment by at least one of a pre-configuration or communication from a core network of a Communication Service Provider (CSP).

16. The system of claim 10 , wherein the application entitlement request and the application entitlement response are communicated via an encrypted communication protocol.

17. A non-transitory storage medium storing instructions, the instructions executable by a processor, to:

receive reference authenticity information corresponding to an application from an application owner;

store the reference authenticity information that is received in a database;

receive an application entitlement request corresponding to the application that is on a user equipment, wherein the application entitlement request includes application authenticity information;

validate the application entitlement request by comparing the application authenticity information with the reference authenticity information stored in the database; and

in response to validation of the application entitlement request, send an application entitlement response to the user equipment, wherein the application entitlement response includes application validity information such that the user equipment selects a network slice to route application data corresponding to the application.

18. The non-transitory storage medium of claim 17 , wherein the network slice selected by the user equipment is a target network slice of a communication system based on a condition that the validation of the application entitlement request is successful, and the target network slice is optimized according to the application.

19. The non-transitory storage medium of claim 17 , wherein the application authenticity information includes at least one of an application signature generated by the application owner, identification information of the application owner, application identifier, an Operating System (OS) information, and a hardware information of the user equipment.

20. The non-transitory storage medium of claim 17 , wherein the instructions to receive the application entitlement request is executed in response to the application being launched on the user equipment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 17, 2024
From: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
To: HCL TECHNOLOGIES LIMITED
Reel/Frame 069715/0743 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2022
From: SHEN, WEI; LIU, MU-JIN
To: HEWLETT PACKARD ENTERPRISE DEVELOPMENT LP
Reel/Frame 061582/0900 →
Continuity (1)
Related Publication 20240147231A1 · May 2, 2024
References Cited (12)
US 20180007552A1 · Bae et al. · 2018 [cited by applicant]
US 20210306939A1 · Zhang · 2021 [cited by examiner]
US 20220369199A1 · Huang · 2022 [cited by examiner]
US 20230185983A1 · Ramanasankaran · 2023 [cited by examiner]
3GPP TS 24.526, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; User Equipment (UE) policies for 5G System (5GS); Stage 3 (Release 16)”, Sep. 2020, 52 pages. [cited by applicant]
Android Developers, “Add 5G capabilities to your app”, available online at <https://developer.android.com/about/versions/11/features/5g#meteredness>, 2022, 6 pages. [cited by applicant]
Android Open Source Project, “5G Network Slicing”, available online at https://source.android.com/docs/core/connect/5g-slicing>, 2022, 14 pages. [cited by applicant]
Android Open Source Project, “Application Signing”, available online at <https://source.android.com/docs/security/features/apksigning>, 2022, 4 pages. [cited by applicant]
Ericsson, “FarEasTone and Ericsson mark a breakthrough in 5G network slicing”, available online at <https://www.ericsson.com/en/press-releases/2/2021/11/20211102-fareastone-and-ericsson-mark-a-breakthrough-in-5g-network… [cited by applicant]
GSM Association, “Service Entitlement Configuration Version 8.0”, Jan. 28, 2022, 122 pages. [cited by applicant]
GTI, “5G Smart Devices Supporting Network Slicing White Paper”, NGMN Alliance, -Dec. 15, 2020, 40 Pages. [cited by applicant]
Nick Wood, “Google carves out a role in 5G slicing”, Telecom TV, available online at <https://www.telecomtv.com/content/5g/google-carves-out-a-role-in-5g-slicing-42835/>, Nov. 3, 2021, 3 pages. [cited by applicant]