IP Library › Granted Patent US 12,355,884
Granted Patent B2
US 12,355,884 · App. 17/171,675 · Granted Jul 8, 2025

Network slice authentication method and communications apparatus

Inventors: Fei Li (Shenzhen, CN); Bo Zhang (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
H04L9/3213H04L63/0876H04L63/102H04L63/20H04L67/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,884
App. No.
17/171,675
Granted
Jul 8, 2025
Kind
B2
Abstract

A service authorization method includes receiving, by a server from a client, a request requesting an access token, where the request includes slice information, performing, by the server, authentication on the client, adding, by the server, the slice information to the access token, and sending, by the server, a response message to the client when the client is authenticated, where the response message comprises the access token.

Claims (51)

1. A service authorization method comprising:

receiving, by a first server, a first request from a client that is a network element for performing a network function in a core network deployed using a service-based architecture, wherein the first request requests an access token, and wherein the first request comprises first slice information, and wherein the first slice information comprises a network slice instance (NSI) identifier (ID) list or a single network slice selection assistance information (S-NSSAI) list;

performing, by the first server, authentication on the client;

sending, by the first server, a first response message to the client when the client is authenticated, wherein the first response message comprises the access token, and wherein the access token comprises the first slice information;

receiving, by a second server, a second request from the client, wherein the second request requests a function service, and wherein the second request comprises the access token;

verifying, by the second server, the first slice information to obtain a verification result; and

replying, by the second server, to the client based on the verification result.

2. The service authorization method of claim 1 , wherein the access token further comprises an expected service name and type, a client identifier, and a client type.

3. The service authorization method of claim 1 , wherein verifying the first slice information comprises determining, by the second server, whether the first slice information matches second slice information stored in the second server.

4. A service authorization system comprising:

a first server configured to:

receive, from a client that is a network element for performing a network function in a core network deployed using a service-based architecture, a first request requesting an access token, wherein the first request comprises first slice information, and wherein the first slice information comprises a network slice instance (NSI) identifier (ID) list or a single network slice selection assistance information (S-NSSAI) list;

perform authentication on the client; and

send a first response message to the client when the client is authenticated, wherein the first response message comprises the access token, and wherein the access token comprises the first slice information;

a second server in communication with the first server and configured to:

receive, from the client, a second request requesting a function service, wherein the second request comprises the access token;

verify the first slice information to obtain a verification result; and

reply to the client based on the verification result; and

a hardware processor configured to implement the first server or the second server.

5. The service authorization system of claim 4 , wherein the access token further comprises an expected service name and type, a client identifier, and a client type.

6. The service authorization system of claim 4 , wherein the second server is further configured to verify the first slice information by determining whether the first slice information matches second slice information stored in the second server.

7. A service authorization method implemented by a server and comprising:

receiving, from a client that is a network element for performing a network function in a core network deployed using a service-based architecture, a request requesting an access token, wherein the request comprises slice information, and wherein the slice information comprises a network slice instance (NSI) identifier (ID) list or a single network slice selection assistance information (S-NSSAI) list;

performing authentication on the client; and

sending a response message to the client when the client is authenticated,

wherein the response message comprises the access token, and

wherein the access token comprises the slice information.

8. The service authorization method of claim 7 , wherein the access token further comprises an expected service name and type, a client identifier, and a client type.

9. A service request method implemented by a server and comprising:

receiving, from a client that is a network element for performing a network function in a core network deployed using a service-based architecture, a request requesting a function service, wherein the request comprises an access token, wherein the access token comprises first slice information, and wherein the first slice information comprises a network slice instance (NSI) identifier (ID) list or a single network slice selection assistance information (S-NSSAI) list;

verifying the first slice information to obtain a verification result; and

replying to the client based on the verification result.

10. The service request method of claim 9 , wherein verifying the first slice information comprises determining whether the first slice information matches second slice information stored in the server.

11. A server comprising:

a receiver configured to receive a request from a client that is a network element for performing a network function in a core network deployed using a service-based architecture, wherein the request requests an access token, wherein the request comprises slice information, and wherein the slice information comprises a network slice instance (NSI) identifier (ID) list or a single network slice selection assistance information (S-NSSAI) list;

a processor coupled to the receiver and configured to authenticate the client; and

a transmitter coupled to the processor and configured to send a response message to the client when the client is authenticated,

wherein the response message comprises the access token, and

wherein the access token comprises the slice information.

12. The server of claim 11 , wherein the access token further comprises an expected service name and type, a client identifier, and a client type.

13. A server comprising:

a receiver configured to receive a request from a client that is a network element for performing a network function in a core network deployed using a service-based architecture, wherein the request requests a function service, wherein the request comprises an access token, wherein the access token comprises first slice information, and wherein the first slice information comprises a network slice instance (NSI) identifier (ID) list or a single network slice selection assistance information (S-NSSAI) list;

a processor coupled to the receiver and configured to verify the first slice information to obtain a verification result; and

a transmitter coupled to the processor and configured to reply to the client based on the verification result.

14. The server of claim 13 , wherein the processor is further configured to verify the first slice information by determining whether the first slice information matches second slice information stored in the server.

15. The service authorization method of claim 1 , wherein the NSI ID list comprises at least one slice.

16. The service authorization method of claim 1 , wherein the S-NSSAI list comprises at least one slice type granularity.

17. The service authorization system of claim 4 , wherein the NSI ID list comprises at least one slice.

18. The service authorization system of claim 4 , wherein the S-NSSAI list comprises at least one slice type granularity.

19. The service authorization method of claim 7 , wherein the NSI ID list comprises at least one slice.

20. The service authorization method of claim 7 , wherein the S-NSSAI list comprises at least one slice type granularity.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2021
From: LI, FEI; ZHANG, BO
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 055390/0862 →
Priority Claims (2)
CN 201811307957.5 · Nov 5, 2018 · national
CN 201910002319.0 · Jan 2, 2019 · national
Continuity (2)
Continuation PCTCN2019111923 · Oct 18, 2019
Related Publication 20210168139A1 · Jun 3, 2021
References Cited (23)
US 10715327B1 · Ramanujan · 2020 [cited by examiner]
US 11419046B2 · Fiorese · 2022 [cited by examiner]
US 20120052859A1 · Cai · 2012 [cited by examiner]
US 20140112135A1 · Huang · 2014 [cited by examiner]
US 20160028737A1 · Srinivasan et al. · 2016 [cited by applicant]
US 20180191568A1 · Hoffmann · 2018 [cited by examiner]
US 20180206152A1 · Zhang et al. · 2018 [cited by applicant]
US 20180302408A1 · Touati et al. · 2018 [cited by applicant]
US 20190124561A1 · Faccin · 2019 [cited by examiner]
US 20190166493A1 · You et al. · 2019 [cited by applicant]
US 20220224589A1 · Das · 2022 [cited by examiner]
CN 104821937A · 2015 [cited by applicant]
CN 105659558A · 2016 [cited by applicant]
CN 106210042A · 2016 [cited by applicant]
CN 106550410A · 2017 [cited by applicant]
CN 107347202A · 2017 [cited by applicant]
CN 107666666A · 2018 [cited by applicant]
WO 2018009344A1 · 2018 [cited by applicant]
WO 2018013925A1 · 2018 [cited by applicant]
WO 2018049583A1 · 2018 [cited by applicant]
Huawei, et al., 3GPP TSG SA WG3 (Security) Meeting #91, S3-181252, “OAuth based authorization for access to management functions,” Apr. 16-20, 2018, Belgrade, Serbia, 2 pages. [cited by applicant]
3GPP TS 24.501 V15.1.0, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; Non-Access-Stratum (NAS) protocol for 5G System (5GS); Stage 3 (Release 15),” Sep. 2018, 398 pages. [cited by applicant]
3GPP TS 33.501 V15.2.0, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 15)”, Sep. 2018, 175 pages. [cited by applicant]