IP Library Granted Patent US 12,238,518
Granted Patent B2
US 12,238,518 · App. 17/777,319 · Granted Feb 25, 2025

Method for authenticating a user on a network slice

Inventors: Jan Siba (Austin, TX); Lionel Rozak-Draicchio (Austin, TX); Vincent Dany (Aubagne, FR)
Assignee: THALES DIS FRANCE SAS
H04W12/06H04L63/0853
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,518
App. No.
17/777,319
Granted
Feb 25, 2025
Kind
B2
Abstract

Provided is a method to operate a secure chip card for connecting to a user equipment operating in a cellular network comprising a plurality of network slices, wherein for at least one network slice a slice authentication server is operational, the secure chip card comprising a secured memory with at least one slice authentication application.

Claims (42)

1. A method to operate a secure chip card connected to a user equipment operating in a cellular network comprising a plurality of network slices, wherein for at least one network slice a slice authentication server is operational, the secure chip card comprising a secured memory with at least one slice authentication application,

the method comprising the steps of:

retrieving a slice authentication configuration message comprising a slice identification from the user equipment;

generating, by a slice authentication application of said secure chip card, an application user identifier considering the slice identification, said application user identifier representing a user who wants to get access to the network slice via the user equipment,

sending a slice attachment request comprising the application user identifier to the slice authentication server;

receiving a user verification request corresponding to said application user identifier from the slice authentication server;

acquiring user verification data acquired from the user of the user equipment,

sending a user verification result to the slice authentication server; and

receiving a slice authentication success message to the user equipment for the user of the user equipment to access to the slice corresponding to the slice identification.

2. The method according to claim 1 , wherein the secure chip card is configured to store a plurality of slice authentication applications, further comprising a slice authentication proxy application,

wherein the first of the plurality of slice authentication applications is assigned to a first slice of the cellular network, and a second slice of the plurality of slice authentication applications is assigned to a second slice of the cellular network,

the method comprising the step after receiving of the user verification request dispatching the user verification request to one of the plurality of slice authentication applications.

3. The method according to claim 2 , further comprising the steps for the secure chip card of

receiving from the slice authentication server a set of application configuration parameter, and

updating the stored at least one slice authentication application based on the received set of application configuration parameter.

4. The method according to claim 3 , wherein the user equipment has registered to the cellular network by means of network access credentials stored in the secured chip card.

5. The method according to claim 4 , wherein the step of sending a user verification result comprises encrypting the user verification result before submitting.

6. A secure chip card for connecting configured to be connected to a user equipment operating in a cellular network comprising a plurality of network slices, wherein for at least one network slice an slice authentication server is operational,

the secure chip card comprising a secured memory with at least one slice authentication application; wherein the secure chip card is configured to:

retrieve a slice authentication configuration message comprising a slice identification from the user equipment;

generate an application user identifier, by a slice authentication application of said secure chip card, considering the slice identification, said application user identifier representing a user who wants to get access to the network slice;

send, via the user equipment, a slice attachment request comprising the application user identifier to the slice authentication server;

receive a user verification request corresponding to said application user identifier from the slice authentication server;

retrieve user verification data acquired from the user of the user equipment;

send a user verification result to the slice authentication server; and

receive a slice authentication success message to the user equipment for the user of the user equipment to access to the slice corresponding to the slice identification.

7. The secure chip card according to claim 6 , further configured to store a plurality of slice authentication applications, further comprising a slice authentication proxy application,

wherein the first of the plurality of slice authentication applications is assigned to a first slice of the cellular network, and a second slice of the plurality of slice authentication applications is assigned to a second slice of the cellular network,

the secure chip card being configured after receiving of the user verification request to dispatch the user verification request to one of the plurality of slice authentication applications.

8. The secure chip card according to claim 6 , further being configured to:

receive from the slice authentication server a set of application configuration parameter, and

update the stored at least one slice authentication application based on the received set of application configuration parameter.

9. The secure chip card according to claim 8 , wherein the user equipment has registered to the cellular network by means of network access credentials stored in the secured chip card.

10. The secure chip card according to claim 9 , further configured upon sending a user verification result to encrypt the user verification result before submitting.

11. A method for a slice authentication server being assigned to a network slice of a cellular network, the method comprising the step of:

receiving, at the slice authentication server, from a secure chip card of a user equipment a slice attachment request comprising an application user identifier generated from a slice identification representing a user who wants to get access to the network slice via the user equipment,

checking, by the slice authentication server, for the application user identifier, a stored record is available,

preparing, by the slice authentication server, a user verification request, wherein the user verification request instructs the secure chip card, in conjunction with the user equipment, to return a user verification request,

sending, by the slice authentication server, the user verification request to the secure chip card,

receiving, at the slice authentication server, a user verification result,

evaluating, by the slice authentication server, the user verification result, and

sending, by the slice authentication server, a slice authentication success message to the user equipment to access to the slice corresponding to the slice identification.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2022
From: SIBA, JAN; ROZAK-DRAICCHIO, LIONEL
To: GEMALTO INC.
Reel/Frame 061369/0897 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2022
From: DANY, VINCENT
To: THALES DIS FRANCE SA
Reel/Frame 061369/0977 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2022
From: THALES DIS FRANCE SA
To: THALES DIS FRANCE SAS
Reel/Frame 061370/0027 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 11, 2022
From: THALES DIS USA, INC.
To: THALES DIS FRANCE SA
Reel/Frame 061371/0793 →
CHANGE OF NAME Recorded Oct 11, 2022
From: GEMALTO, INC.
To: THALES DIS USA, INC.
Reel/Frame 061639/0365 →
Priority Claims (1)
EP 19306496 · Nov 21, 2019 · regional
Continuity (1)
Related Publication 20220408252A1 · Dec 22, 2022
References Cited (33)
US 11223947B2 · Casati · 2022 [cited by examiner]
US 20170164212A1 · Opsenica et al. · 2017 [cited by applicant]
US 20170332212A1 · Gage · 2017 [cited by examiner]
US 20180176858A1 · Wang · 2018 [cited by examiner]
US 20180192471A1 · Li · 2018 [cited by examiner]
US 20180242198A1 · Choi · 2018 [cited by examiner]
US 20180310238A1 · Opsenica · 2018 [cited by examiner]
US 20180317086A1 · Ben Henda · 2018 [cited by examiner]
US 20190159029A1 · Li · 2019 [cited by examiner]
US 20190230584A1 · Lou · 2019 [cited by examiner]
US 20190261180A1 · Lei · 2019 [cited by examiner]
US 20190357136A1 · Li · 2019 [cited by examiner]
US 20200029264A1 · Wang · 2020 [cited by examiner]
US 20200053083A1 · Kunz · 2020 [cited by examiner]
US 20200112492A1 · Chatras · 2020 [cited by examiner]
US 20200120721A1 · Lau · 2020 [cited by examiner]
US 20200252798A1 · Ito · 2020 [cited by examiner]
US 20210243600A1 · Yu · 2021 [cited by examiner]
US 20220007277A1 · Yu · 2022 [cited by examiner]
US 20220110050A1 · Won · 2022 [cited by examiner]
US 20220124079A1 · Patil · 2022 [cited by examiner]
US 20220141192A1 · Silveira · 2022 [cited by examiner]
US 20220377830A1 · Mecum · 2022 [cited by examiner]
US 20230096402A1 · Kang · 2023 [cited by examiner]
US 20240137748A1 · Cai · 2024 [cited by examiner]
S. Behrad, E. Bertin, S. Tuffin and N. Crespi, “5G-SSAAC: Slice-specific Authentication and Access Control in 5G,” 2019 IEEE Conference on Network Softwarization (NetSoft), Paris, France, 2019, pp. 281-285. (Year: 2019). [cited by examiner]
C. -I. Fan, Y. -T. Shih, J. -J. Huang and W. -R. Chiu, “Cross-Network-Slice Authentication Scheme for the 5th Generation Mobile Communication System,” in IEEE Transactions on Network and Service Management, vol. 18, No.… [cited by examiner]
R. F. Olimid and G. Nencioni, “5G Network Slicing: A Security Overview,” in IEEE Access, vol. 8, pp. 99999-100009, 2020. (Year: 2020). [cited by examiner]
International Search Report (PCT/ISA/210) and Written Opinion (PCT/ISA/237) mailed on Dec. 3, 2020, by the European Patent Office as the International Searching Authority for current International Application No. PCT/EP… [cited by applicant]
Telecomitalia et al: “Slice Specific Authentication and Authorization with multiple registrations in the samePLMN”. 3GPP Draft; 23502_CR1224R5_ENS_(REL-16)_S2-1906592_WAS 5306 Multi -Access SSSA 23502, 3rd Generation Pa… [cited by applicant]
France Telecom/Oberthur Card Systems: “Clanfication for USIM Application selection”, 3GPP Draft; SI-000326, 3rd Generation Partnership Project (3GPP), Mobile Competence Centre; 650, Route Des Lucioles ; F-06921 Sophia-A… [cited by applicant]
Motorola Mobility et al: “Solution for network slice authentication and authorisation”, 3GPP Draft; S2-188261 Ens Sol-Sliceauth V02, 3rd Generation Partnership Project (3GPP), Mobile Competence Centre; 650, Route Des Lu… [cited by applicant]
Behrad Shanay et al: “5G-SSAAC: Slice-specific Authentication and Access Control in 5G”, 2019 IEEE Conference on Network Softwarization (NETSOFT), IEEE, Jun. 24, 2019 (Jun. 24, 2019), pp. 281-285, XP033602035, DOI: 10.1… [cited by applicant]