IP Library Granted Patent US 12,464,346
Granted Patent B2
US 12,464,346 · App. 18/015,264 · Granted Nov 4, 2025

Slice-specific security requirement information

Inventors: Sheeba Backia Mary Baskaran (Friedrichsdorf, DE); Andreas Kunz (Ladenburg, DE); Genadi Velev (Darmstadt, DE)
Assignee: Lenovo (Singapore) Pte. Ltd.
H04W12/041H04W12/033H04W12/037
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,464,346
App. No.
18/015,264
Granted
Nov 4, 2025
Kind
B2
Abstract

Apparatuses, methods, and systems are disclosed for determining and enforcing service specific network slice security. One apparatus in a mobile communication network includes processor that performs primary authentication with a mobile communication network and a transceiver that receives a SMC message comprising SSI. The processor applies slice security for control plane and user plane traffic related to a network slice according to a Security Requirement Type indicated in the SSI.

Claims (49)

1 . A user equipment (“UE”) for wireless communication, comprising:

at least one memory; and

at least one processor coupled with the at least one memory and configured to cause the UE to:

perform primary authentication with a mobile communication network;

receive a security mode command (“SMC”) message comprising slice-specific security requirement information (“SSI”) and a slice security requirement identifier (“SRID”), wherein the SSI includes a security requirement type parameter indicating whether to derive a dedicated security context after the primary authentication, and wherein the SRID identifies a security requirement information corresponding to a single network slice selection assistance information (“S-NSSAI”); and

apply slice security for control plane and user plane traffic related to a network slice in response to the security requirement type parameter included in the SSI indicating to derive the dedicated security context after the primary authentication,

wherein to apply slice security for control plane and user plane traffic related to the network slice, the at least one processor is configured to cause the UE to derive at least one slice-specific security key based on the received SSI and the SRID.

2 . The UE of claim 1 , wherein the at least one processor is configured to cause the UE to derive the at least one slice-specific security key using as additional inputs at least one of:

a slice identifier (“ID”),

a slice type, or

a service type.

3 . The UE of claim 2 , wherein the at least one slice-specific security key comprises at least one of:

a slice-specific access and mobility management function (“AMF”) key (“Kamf”),

a slice-specific radio access network (“RAN”) key,

a slice-specific non-access stratum (“NAS”) key, or

a slice-specific access stratum (“AS”) key.

4 . The UE of claim 1 , wherein to apply security for control plane and user plane traffic related to a network slice, the at least one processor is configured to cause the UE to use slice-specific inputs in the ciphering and integrity protection while applying a default primary authentication-based security context for a non-access stratum (“NAS”) connection, in response to the security requirement type parameter indicating that traffic of a corresponding network slice is to be protected using the dedicated security context.

5 . The UE of claim 1 , wherein the SMC message contains an SSI inclusion indication parameter that indicates that the SSI for enforcement at the UE is provided with the security mode command message, wherein the SSI is both integrity protected and confidentiality protected with default security keys.

6 . The UE of claim 1 , wherein the SMC message contains a security requirement identifier (“SRID”) that indicates that the SMC message is slice-specific and is cryptographic separated using the SRID.

7 . A processor for wireless communication, comprising:

at least one memory; and

at least one controller coupled with the at least one memory and configured to cause the processor to:

perform primary authentication with a mobile communication network;

receive a security mode command (“SMC”) message comprising slice-specific security requirement information (“SSI”) and a slice security requirement identifier (“SRID”), wherein the SSI includes a security requirement type parameter indicating whether to derive a dedicated security context after the primary authentication, and wherein the SRID identifies a security requirement information corresponding to a single network slice selection assistance information (“S-NSSAI”); and

apply slice security for control plane and user plane traffic related to a network slice in response to the security requirement type parameter included in the SSI indicating to derive the dedicated security context after the primary authentication,

wherein to apply slice security for control plane and user plane traffic related to the network slice, the at least one controller is configured to cause the processor to derive at least one slice-specific security key based on the received SSI and the SRID.

8 . The processor of claim 7 , wherein the at least one controller is configured to cause the processor to derive the at least one slice-specific security key using as additional inputs at least one of:

a slice identifier (“ID”),

a slice type, or

a service type.

9 . The processor of claim 7 , wherein the at least one slice-specific security key comprises at least one of:

a slice-specific access and mobility management function (“AMF”) key (“Kamf”),

a slice-specific radio access network (“RAN”) key,

a slice-specific non-access stratum (“NAS”) key, or

a slice-specific access stratum (“AS”) key.

10 . A method performed by a user equipment (“UE”), the method comprising:

performing primary authentication with a mobile communication network;

receiving a security mode command (“SMC”) message comprising slice-specific security requirement information (“SSI”) and a slice security requirement identifier (“SRID”), wherein the SSI includes a security requirement type parameter indicating whether to derive a dedicated security context after the primary authentication, wherein the security requirement type parameter indicates to derive the dedicated security context after the primary authentication, and wherein the SRID identifies a security requirement information corresponding to a single network slice selection assistance information (“S-NSSAI”); and

applying slice security for control plane and user plane traffic related to a network slice in response to the security requirement type parameter included in the SSI indicating to derive the dedicated security context after the primary authentication,

wherein applying slice security for control plane and user plane traffic related to the network slice further comprises deriving at least one slice-specific security key based on the received SSI and the SRID.

11 . The method of claim 10 , further comprising deriving the at least one slice-specific security key using as additional inputs at least one of:

a slice identifier (“ID”),

a slice type, or

a service type.

12 . The method of claim 10 , wherein the at least one slice-specific security key comprises at least one of:

a slice-specific access and mobility management function (“AMF”) key (“Kamf”),

a slice-specific radio access network (“RAN”) key,

a slice-specific non-access stratum (“NAS”) key, or

a slice-specific access stratum (“AS”) key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2023
From: BASKARAN, SHEEBA BACKIA MARY; KUNZ, ANDREAS; VELEV, GENADI
To: LENOVO (SINGAPORE) PTE. LTD.
Reel/Frame 062428/0110 →
Continuity (2)
Provisional Application 63049549 · Jul 8, 2020
Related Publication 20230269589A1 · Aug 24, 2023
References Cited (11)
US 20190141081A1 · Kunz et al. · 2019 [cited by applicant]
US 20190342082A1 · Lei · 2019 [cited by examiner]
US 20230232219A1 · Mao · 2023 [cited by examiner]
PCT/IB2021/056164, “Notification of Transmittal of the International Search Report and the Written Opinion of the International Searching Authority, or the Declaration”, International Searching Authority, Sep. 29, 2021,… [cited by applicant]
Lenovo et al., “Update to Solution#6”, 3GPP TSG-SA3 Meeting #102bis-e S3-211119, Mar. 1-5, 2021, pp. 1-5. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the security aspects of the next generation system (Release 14)”, 3GPP TR 33.899 V1.3.0, Aug. 2017, pp. 1-60… [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Service requirements for the 5G system; Stage 1 (Release 17)”, 3GPP TS 22.261 V17.2.0, Mar. 2020, pp. 1-83. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16)”, 3GPP TS 23.501 V16.4.0, Mar. 2020, pp. 1-430. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Procedures for the 5G System (5GS); Stage 2 (Release 16)”, 3GPP TS 23.502 V16.4.0, Mar. 2020, pp. 1-582. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Security architecture and procedures for 5G system (Release 16)”, 3GPP TS 33.501 V16.2.0, Mar. 2020, pp. 1-227. [cited by applicant]
3GPP, “3rd Generation Partnership Project; Technical Specification Group Radio Access Network; NR; Packet Data Convergence Protocol (PDCP) specification (Release 16)”, 3GPP TS 38.323 V16.0.0, Mar. 2020, pp. 1-37. [cited by applicant]