IP Library Granted Patent US 12,610,239
Granted Patent B2
US 12,610,239 · App. 18/267,861 · Granted Apr 21, 2026

Trust level in network slices

Inventors: Giuseppe Celozzi (Naples, IT); Luca Baldini (Rome, IT); Daniele Gaito (Naples, IT); Gaetano Patria (San Prisco, IT)
Assignee: Telefonaktiebolaget LM Ericsson (Publ)
H04W12/08H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,610,239
App. No.
18/267,861
Granted
Apr 21, 2026
Kind
B2
Abstract

The invention relates to a method for operating a slice management entity (100) configured to manage a network slice of a cellular network, the method comprising: —periodically determining a trust level of the network slice based on time dependent trust values of network components used by the network slice, —determining whether the determined trust level of the network slice is lower than a minimum threshold level, wherein in the affirmative, —adapting a controlling of at least one of the network components of the network slice to obtain a new trust value for the at least one network component, wherein the new trust level of the network slice is above the minimum threshold level and is calculated taking into account the new trust value of the adapted controlling of the at least one network component.

Claims (52)

1 . A computer implemented method implemented using at least one processing circuitry and a memory for operating a slice management entity configured to manage a network slice of a cellular network, the method comprising:

periodically determining a trust level of the network slice based on time dependent trust values of network components used by the network slice;

determining whether the determined trust level of the network slice is lower than a minimum threshold level;

responsive to the determined trust level being lower than the minimum threshold level, adapting control of at least one of the network components of the network slice to obtain a new trust value for the at least one network component;

responsive to the determined trust level being lower than a second threshold below the minimum threshold level, initiating a process by which no new users of the cellular network are admitted to the network slice; and

periodically determining the trust level of the network slice comprising determining a new trust level of the network slice that is above the minimum threshold level based on the new trust value.

2 . The method according to claim 1 , wherein periodically determining comprises detecting a trigger event occurring when a defined time period has lapsed or when a trigger message is received by which the slice management entity is informed that the time dependent trust value of at least one of the network components has changed.

3 . The method according to claim 1 , wherein periodically determining a trust level of the network slice comprises determining whether any of the trust values of the network components of the network slice has changed, wherein if it is detected that the trust value of the at least one network component of the network slice has changed, it is determined whether the determined trust level of the network slice is lower than a minimum threshold level.

4 . The method according to claim 1 , further comprising informing an operator of the network slice when the controlling of the at least one of the network components cannot be adapted such that the trust level of the network slice is above the minimum threshold level.

5 . The method according to claim 1 , wherein the adapting control comprises:

initiating a software update for the at least one network component; and/or

increasing a monitoring level of the at least one network component; and/or

adding additional security control measures to the at least one network component; and/or

decreasing a monitoring level of the at least one network component when the trust level is above a further threshold.

6 . The method according to claim 1 , wherein periodically determining the trust level comprises receiving a notification from a security management entity of the cellular network, that the trust value of the at least one network component has changed.

7 . The method according to claim 1 , further comprising:

receiving, before the trust level of the network slice is determined, a request from a requesting party requesting the network slice with a trust level above the minimum threshold level;

responsive to determining that the network slice having the trust level above the minimum threshold level is not available:

selecting new network components, each of them having a corresponding trust value;

determining a first trust level for the new slice determined for the new network components; and

checking whether the first trust level is above the minimum threshold level, wherein if this is not the case, the selecting and determining is repeated until the first trust level is above the minimum threshold level.

8 . The method according to claim 7 , wherein the requested slice is identified based on a slice differentiator value, wherein the slice differentiator value comprises the trust level above the minimum threshold.

9 . The method according to claim 1 , wherein periodically determining the trust level is further based on a corresponding weakness level of each of the network components constituting the network slice, the weakness level describing how vulnerable a corresponding network component is to a Common Vulnerabilities and Exposures parameter.

10 . A slice management entity for managing a network slice of a cellular network, the slice management entity comprising:

processing circuitry and memory, the memory containing instructions executable by the process circuitry whereby the slice management entity is configured to:

periodically determine a trust level of the network slice based on time dependent trust values of network components used by the network slice;

determine whether the determined trust level of the network slice is lower than a minimum threshold level; and

responsive to the determined trust level being lower than the minimum threshold level, adapt control of at least one of the network components of the network slice to obtain a new trust value for the at least one network component;

responsive to the determined trust level being lower than a second threshold below the minimum threshold level, initiating a process by which no new users of the cellular network are admitted to the network slice; and

to periodically determine the trust level of the network slice, the slice management entity being configured to determine a new trust level of the network slice that is above the minimum threshold level based on the new trust value.

11 . The slice management entity according to claim 10 , wherein to periodically determine the trust level, the slice management entity is configured to detect a trigger event occurring when a defined time period has lapsed or when a trigger message is received by which the slice management entity is informed that the time dependent trust value of at least one of the network components has changed.

12 . The slice management entity according to claim 10 , wherein to periodically determine the trust level of the network slice, the slice management entity is configured to determine whether any of the trust values of the network components of the network slice has changed, wherein if it is detected that the trust value of the at least one network component of the network slice has changed, it is determined whether the determined trust level of the network slice is lower than a minimum threshold level.

13 . The slice management entity according to claim 10 , wherein the slice management entity is further configured to inform an operator of the network slice when the controlling of the at least one of the network components cannot be adapted such that the trust level of the network slice is above the minimum threshold level.

14 . The slice management entity according to claim 10 , wherein to adapt control of at least one network component, the slice management entity is configured to perform at least one of the following:

initiate a software update for the at least one network component;

increase a monitoring level of the at least one network component;

add additional security control measures to the at least one network component; and

decrease a monitoring level of the at least one network component, if the trust level is above a further threshold.

15 . The slice management entity according to claim 10 , wherein to periodically determine the trust level, the slice management entity is configured to receive a notification from a security management entity of the cellular network, that the trust value of the at least one network component has changed.

16 . The slice management entity according to claim 10 , wherein the slice management entity is further configured to:

receive, before the trust level of the network slice is determined, a request from a requesting party requesting the network slice with a trust level above the minimum threshold level;

responsive to the network slice having the trust level above the minimum threshold level being unavailable:

select new network components, each of them having a corresponding trust value;

determine a first trust level for the new slice determined for the new network components; and

check whether the first trust level is above the minimum threshold level, wherein if this is not the case, the selecting and determining is repeated until the first trust level is above the minimum threshold level.

17 . The slice management entity according to claim 15 , wherein the requested slice is identified based on a slice differentiator value, wherein the slice differentiator value comprises the trust level above the minimum threshold.

18 . A non-transitory computer readable medium storing a computer program product for controlling a slice management entity, the computer program product comprising software instructions that, when run on the slice management entity, cause the slice management entity to:

periodically determine a trust level of the network slice based on time dependent trust values of network components used by the network slice;

determine whether the determined trust level of the network slice is lower than a minimum threshold level;

responsive to the determined trust level being lower than the minimum threshold level, adapt control of at least one of the network components of the network slice to obtain a new trust value for the at least one network component;

responsive to the determined trust level being lower than a second threshold below the minimum threshold level, initiating a process by which no new users of the cellular network are admitted to the network slice; and

to periodically determine the trust level of the network slice, the slice management entity being caused to determine a new trust level of the network slice that is above the minimum threshold level and is calculated based on the new trust value.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 16, 2023
From: CELOZZI, GIUSEPPE; BALDINI, LUCA; GAITO, DANIELE; PATRIA, GAETANO
To: TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Reel/Frame 063970/0938 →
Continuity (1)
Related Publication 20240056810A1 · Feb 15, 2024
References Cited (29)
US 8635662B2 · Lang · 2014 [cited by examiner]
US 9686234B1 · Dorwin · 2017 [cited by examiner]
US 10349240B2 · Senarath · 2019 [cited by examiner]
US 11456882B2 · Kravitz · 2022 [cited by examiner]
US 20100043066A1 · Miliefsky · 2010 [cited by examiner]
US 20140325234A1 · Shiyafetdinov · 2014 [cited by examiner]
US 20160352924A1 · Senarath · 2016 [cited by examiner]
US 20160353268A1 · Senarath · 2016 [cited by examiner]
US 20170295197A1 · Parimi · 2017 [cited by examiner]
US 20200195495A1 · Parker · 2020 [cited by examiner]
US 20200314134A1 · Izrael · 2020 [cited by examiner]
US 20220217540A1 · Choyi · 2022 [cited by examiner]
US 20220321330A1 · Hu · 2022 [cited by examiner]
EP 3529949A1 · 2019 [cited by applicant]
EP 3696700A1 · 2020 [cited by applicant]
WO 2018074953A1 · 2018 [cited by applicant]
WO 2018075930A1 · 2018 [cited by applicant]
WO 2021025600A1 · 2021 [cited by applicant]
Niu, B. et al., “5G Network Slice Security Trust Degree Calculation Model”, 2017 3rd IEEE International Conference on Computer and Communications, Dec. 13-16, 2017, pp. 1150-1157, IEEE. [cited by applicant]
3rd Generation Partnership Project, “3rd Generation Partnership Project, Technical Specification Group Services and System Aspects; Telecommunication management; Study on management and orchestration of network slicing … [cited by applicant]
3rd Generation Partnership Project, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; System architecture for the 5G System (5GS); Stage 2 (Release 16)”, Technical Specifica… [cited by applicant]
GSM Association, “Generic Network Slice Template”, Official Document NG.116—Generic Network Slice Template, Version 2.0, Oct. 16, 2019, pp. 1-61, GSMA. [cited by applicant]
3rd Generation Partnership Project, “3rd Generation Partnership Project; Technical Specification Group Core Network and Terminals; 5G System; Network Slice Selection Services; Stage 3 (Release 16)”, Technical Specificat… [cited by applicant]
3rd Generation Partnership Project, “3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Study on the security aspects of the next generation system (Release 14)”, Technical Re… [cited by applicant]
ETSI, “Network Functions Virtualisation (NFV) Release 3; Security; Security Management and Monitoring specification”, Group Specification, ETSI GS NFV-SEC 013 V3.1.1, Feb. 2017, pp. 1-54, ETSI. [cited by applicant]
ETSI, “Network Functions Virtualisation (NFV) Release 3; Security; System architecture specification for execution of sensitive NFV components”, Group Specification, ETSI GS NFV-SEC 012 V3.1.1, Jan. 2017, pp. 1-17, ETSI. [cited by applicant]
ETSI, “Network Functions Virtualisation (NFV) Release 3; Management and Orchestration; VNF Descriptor and Packaging Specification”, Group Specification, ETSI GS NFV-IFA 011 V3.3.1, Sep. 2019, pp. 1-85, ETSI. [cited by applicant]
ETSI, “Network Functions Virtualisation (NFV) Release 3; Evolution and Ecosystem; Report on Network Slicing Support with ETSI NFV Architecture Framework”, Group Report, ETSI GS NFV-EVE 012 V3.1.1, Feb. 2017, pp. 1-35, E… [cited by applicant]
ETSI, “Network Functions Virtualisation (NFV) Release 3; Management and Orchestration; Network Service Templates Specification”, Group Specification, ETSI GS NFV-IFA 014 V3.3.1, Sep. 2019, pp. 1-46, ETSI. [cited by applicant]