IP Library › Granted Patent US 12,520,148
Granted Patent B2
US 12,520,148 · App. 18/357,825 · Granted Jan 6, 2026

Network slice access control method and apparatus

Inventors: Fangyuan Zhu (Beijing, CN); Yan Li (Beijing, CN); Hui Ni (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04W12/082H04W12/66H04W28/0289H04W48/02H04W60/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,520,148
App. No.
18/357,825
Granted
Jan 6, 2026
Kind
B2
Abstract

This application provides a network slice access control method, including: determining, by an access and mobility management function network element, first allowed network slice selection assistance information of a terminal device in a registration process to register the terminal device to a network; learning, by the access and mobility management function network element, of an authentication failure of a first network slice corresponding to first single network slice selection assistance information from the first allowed network slice selection assistance information.

Claims (42)

1 . A network slice access control method, comprising:

determining, by an access and mobility management function network element, first allowed network slice selection assistance information of a terminal device in a registration process to register the terminal device to a network;

learning, by the access and mobility management function network element, of an authentication failure of a first network slice corresponding to first single network slice selection assistance information from the first allowed network slice selection assistance information;

in response to that there is no other single network slice selection assistance information in the first allowed network slice selection assistance information, sending, by the access and mobility management function network element, first information to the terminal device; and

requesting, by the terminal device in response to the first information, to deregister from the network.

2 . The method according to claim 1 , wherein the learning, by the access and mobility management function network element, of the authentication failure of the first network slice comprises:

learning, by the access and mobility management function network element, of the authentication failure of the first network slice from an authentication network element.

3 . The method according to claim 2 , wherein the authentication network element is integrated in an authentication server function.

4 . The method according to claim 2 , wherein the authentication network element is located in a third-party network.

5 . The method according to claim 1 , further comprising:

determining, by an authentication network element, that an authentication process based on a network slice granularity for the first network slice has failed.

6 . The method according to claim 1 , wherein that there is no other single network slice selection assistance information in the first allowed network slice selection assistance information comprises:

the first allowed network slice selection assistance information comprises only the first single network slice selection assistance information; or

the first allowed network slice selection assistance information comprises a plurality of pieces of single network slice selection assistance information that comprise the first single network slice selection assistance information, and authentication on network slices corresponding to the plurality of pieces of single network slice selection assistance information fail.

7 . The method according to claim 1 , wherein before learning the authentication failure of the first network slice, the method further comprises:

sending, by the access and mobility management function network element, the first allowed network slice selection assistance information to the terminal device in a registration procedure; and

receiving, by the terminal device, the first allowed network slice selection assistance information.

8 . The method according to claim 1 , further comprising:

sending, by the terminal device, a deregistration accept message to the access and mobility management function network element, wherein the deregistration accept message is for confirming with the access and mobility management function network element that the terminal device accepts deregistration request.

9 . A network slice access control system, comprising:

an access and mobility management function network element, configured to;

determine first allowed network slice selection assistance information of a terminal device in a registration process to register the terminal device to a network;

learn of an authentication failure of a first network slice corresponding to first single network slice selection assistance information from the first allowed network slice selection assistance information; and

in response to that there is no other single network slice selection assistance information in the first allowed network slice selection assistance information, send first information to the terminal device;

the terminal device, configured to:

deregister from the network in response to receiving the first information.

10 . The system according to claim 9 , wherein the access and mobility management function network element is configured to learn of the authentication failure of the first network slice from an authentication network element.

11 . The system according to claim 10 , wherein the authentication network element is integrated in an authentication server function.

12 . The system according to claim 10 , wherein the authentication network element is located in a third-party network.

13 . The system according to claim 9 ,

wherein an authentication network element is configured to determine that an authentication process based on a network slice granularity for the first network slice has failed.

14 . A network slice access control method, comprising:

receiving, by a terminal device, first information sent by an access and mobility management function network element after the access and mobility management function network element learns of an authentication failure of a network slice corresponding to single network slice selection assistance information from allowed network slice selection assistance information, wherein the first information is used to cause the terminal device to perform deregistration, the allowed network slice selection assistance information is obtained in a registration procedure; and

performing, by the terminal device, deregistration based on the first information.

15 . The method according to claim 14 , wherein the allowed network slice selection assistance information comprises selection assistance information of one or more single network slices, the receiving by the terminal device, the first information comprises:

after a network slice corresponding to the selection assistance information of the one or more single network slices are authenticated failure, receiving, by the terminal device, first information sent by an access and mobility management function network element after the access and mobility management function network element learns of the authentication failure of the one network slice corresponding to selection assistance information of the one single network slice from allowed network slice selection assistance information.

16 . An apparatus, comprising a processor, wherein

the processor is configured to read a program from a memory and run the program, to perform:

receiving, first information sent by an access and mobility management function network element after the access and mobility management function network element learns of an authentication failure of a network slice corresponding to single network slice selection assistance information from allowed network slice selection assistance information, wherein the first information is used to cause the apparatus to perform deregistration, the allowed network slice selection assistance information is obtained in a registration procedure; and

performing deregistration based on the first information.

17 . The apparatus according to claim 16 , wherein the allowed network slice selection assistance information comprises selection assistance information of one or more single network slices, the apparatus receives the first information comprises:

after a plurality of single network slices corresponding to the selection assistance information of the one or more single network slices are authenticated failure, receiving first information sent by an access and mobility management function network element after the access and mobility management function network element learns of the authentication failure of the plurality of single network slices corresponding to selection assistance information of the plurality of single network slices from allowed network slice selection assistance information.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 2, 2025
From: ZHU, FANGYUAN; LI, YAN; NI, HUI
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 070711/0842 →
Priority Claims (1)
CN 201811172535.1 · Oct 9, 2018 · national
Continuity (3)
Continuation 17226797 · Apr 9, 2021
Continuation PCTCN2019108809 · Sep 28, 2019
Related Publication 20230370844A1 · Nov 16, 2023
References Cited (35)
US 9615253B1 · Osborn · 2017 [cited by applicant]
US 20180183765A1 · Neumann et al. · 2018 [cited by applicant]
US 20180227873A1 · Vrzic et al. · 2018 [cited by applicant]
US 20180376446A1 · Youn et al. · 2018 [cited by applicant]
US 20190174449A1 · Shan · 2019 [cited by examiner]
US 20200322884A1 · Di Girolamo et al. · 2020 [cited by applicant]
US 20210092609A1 · Wang · 2021 [cited by applicant]
US 20210410060A1 · Ianev · 2021 [cited by examiner]
US 20220046416A1 · Suzuki · 2022 [cited by examiner]
CN 106060900A · 2016 [cited by applicant]
CN 107690791A · 2018 [cited by applicant]
CN 108347729A · 2018 [cited by applicant]
RU 2533059C2 · 2014 [cited by applicant]
RU 2628317C2 · 2017 [cited by applicant]
WO 2017193553A1 · 2017 [cited by applicant]
WO 2018137873A1 · 2018 [cited by applicant]
3GPP TR 22.830 V16.0.0 (Sep. 2018), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Feasibility Study on Business Role Models for Network Slicing (Release 16),” Sep. 2018,… [cited by applicant]
3GPP TR 23.740 V0.5.0 (Aug. 2018), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on Enhancement of Network Slicing (Release 16),” 53 pages. [cited by applicant]
3GPP TS 23.501 V15.3.0 (Sep. 2018), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System Architecture for the 5G System; Stage 2( Release 15),” Sep. 2018, 226 pages. [cited by applicant]
3GPP TS 23.502 V15.3.0 (Sep. 2018), “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System; Stage 2 (Release 15),” 329 pages. [cited by applicant]
3GPP TS 24.501 V15.1.0 (Sep. 2018), “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3 (Release 15),” Sep. 2018,… [cited by applicant]
3GPP TS 33.501 V15.2.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15),” Sep. 2018, 175 pages. [cited by applicant]
ETRI, “23.502—Alignment for 23.501 with 23.502 for PDU Session establishment,” SA WG2 Meeting #124, S2-178899, Reno, Nevada, Nov. 27-Dec. 1, 2017, 12 pages. [cited by applicant]
Extended European Search Report issued in European Application No. 19870529.5 on Nov. 9, 2021, 8 pages. [cited by applicant]
HTC, “Handling of Allowed NSSAI,” SA WG2 Meeting #S2-122, S2-175049, San Jose Del Cabo, Mexico, Jun. 26-30, 2017, 2 pages. [cited by applicant]
MediaTek Inc., “Correction to emergency registered,” 3GPP TSG SA WG2 Meeting #128bis, S2-188811, Sophia Antipolis, Aug. 20-24, 2018, 23 pages. [cited by applicant]
Motorola Mobility, Lenovo, “Solution for network slice authentication and authorization,” SA WG2 Meeting #128bis, S2-188261, Sophia Antipolis, France, Aug. 20-24, 2018, 5 pages. [cited by applicant]
Nokia, Alcatel-Lucent Shanghai Bell, Telecom Italia, “Network Slice access Subscription Management by a third party message flow P—Cr.,” SA WG2 Meeting #122bis, S2-175694, Sophia Antipolis, France, Aug. 21-25, 2017, 12 … [cited by applicant]
Nokia, Nokia Shanghai Bell, “Slice Specific Authentication and Authorization using non 3GPP credentials—Solution,” SA WG2 Meeting #128, S2-186613, Vilnius, Lithuania , Jul. 2-6, 2018, 5 pages. [cited by applicant]
Office Action issued in Chinese Application No. 201811172535.1 on Mar. 23, 2021, 15 pages (with English translation). [cited by applicant]
Office Action issued in Chinese Application No. 20181172535.1 on Nov. 3, 2021, 5 pages. [cited by applicant]
Office Action issued in Russian Application No. 2021112361/07(026358) on Jun. 29, 2022, 18 pages (with English translation). [cited by applicant]
PCT International Search Report and Written Opinion issued in International Application No. PCT/CN2019/108809 on Dec. 27, 2019, 14 pages (with English translation). [cited by applicant]
Qualcomm Incorporated, “Mechanism to limit frequency at which UE responds with SUCI in Identity Response message,” 3GPP TSG-CT WG1 Meeting #111, C1-183720, Osaka, Japan, May 21-25, 2018, 18 pages. [cited by applicant]
Qualcomm Incorporated, “Solution for Slice Specific Authentication and Authorization using non 3GPP credentials,” SA WG2 Meeting #128, S2-186674, Vilnius, Lithuania, Jul. 2-6, 2018, 2 pages. [cited by applicant]