Method for provisioning credentials to user equipment in a private telecommunications network - Patent Application 20070122997

The method leverages Physical Layer Security to establish keys between user equipment and network elements, addressing the complexity and cost issues of credential provisioning in private networks, ensuring secure and efficient credential distribution without pre-configuration or remote server access.

JP2026502355APending Publication Date: 2026-01-22THALES SA +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025536656
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-26
Filing Date
2023-12-13
Publication Date
2026-01-22

AI Technical Summary

Technical Problem

Existing solutions for provisioning initial credentials between user equipment and a home network in a private telecommunications network are complex, costly, and often impossible to implement without pre-configured credentials or access to remote servers.

Method used

A method utilizing Physical Layer Security (PLS) to establish a key between user equipment and network elements like gNB/AMF or eNB/MME, enabling credential provisioning without pre-distribution, involving steps to generate and verify keys and identifiers, and securely transmit data.

Benefits of technology

Enables secure and cost-effective credential provisioning within private networks, eliminating the need for pre-configuration and remote server access, while ensuring secure communication and minimal deployment costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026502355000001_ABST
    Figure 2026502355000001_ABST
Patent Text Reader

Abstract

The present invention proposes a method for provisioning a credential to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or eNB / MME, the method comprising: a) sending a provisioning request (40) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key (41) between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security; c) providing a PLS key to the user equipment (10) via a PLS key; d) transmitting 43 a message from the user equipment 10 to the gNB / AMF or eNB / MME 11, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; e) transmitting 44 a message from the gNB / AMF or eNB / MME 11 to the credential holder 12, the message including data permitting identification of the user of the user equipment 10 and / or the user equipment 10 and the master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key. f) verifying in the credential holder (12) the data that allows identifying the user of the user equipment (10) and / or the user equipment (10); g) if the verification is positive, assigning in the credential holder (12) a unique subscription identifier to the user equipment (10) and generating corresponding keys, security parameters, and key derivation functions; h) transmitting the unique subscription identifier from the credential holder (12) to the gNB / AMF or eNB / MME (11). i) transmitting the unique subscription identifier, security parameters, and key derivation function from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by a PLS key or a key derived from the PLS key (47); j) generating a final key at the user equipment (10), the final key being a credential including the unique subscription identifier, security parameters, and final key (48);Including.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to telecommunications, and more particularly to a method for provisioning credentials to user equipment in a private telecommunications network.

[0002] It is known that it is necessary to secure the provisioning of initial credentials (e.g. credentials for primary authentication) between a UE (User Equipment) and a home network, which remains a complex / restrictive procedure.

[0003] In particular, the home network can be a private network (PN) that hosts a gNB / AMF (gNodeB / Access and Mobility Management Function) or an eNB / MME (eNodeB / Mobility Management Entity) and a credential holder (e.g., an ARPF / UDM, which stands for Authentication Credential Repository and Processing Function / Unified Data Management, or an AuC, which stands for Authentication Center). The ARPF is a functional element of the UDM and is responsible for generating 5G Home Environment Authentication Vectors (HEAV) based on the subscriber's shared key.

[0004] The UE may be a telecommunications terminal with or without interoperating with a secure element, such as an eUlCC (embedded UICC) or an iUICC (integrated UICC).

[0005] Existing solutions require the UE to be provisioned with pre-configured credentials (e.g., certificates or public keys) required to have a connection with a remote server in the home network of the MNO (Mobile Network Operator) that handles the private network.

[0006] These requirements may be too costly or may not be possible to meet within the confines of a private network (eg, connecting to a remote server).

[0007] A known technology called PLS (Physical Layer Security) is a promising approach that can benefit traditional encryption methods. The idea of ​​PLS ​​is to utilize the characteristics of the propagation medium and radio channel impairments to ensure secure communication at the physical layer. PLS is a technology foreseen to address 6G security; for example, PLS is described in several white papers on 6G technology. Apple™ proposed to study its use within the 3GPP in its contribution S3-213987, published during the SA3 meeting in November 2021.

[0008] While this specification clarifies that 5G security will primarily rely on traditional cryptography based on pre-provisioned keys at higher layers of the protocol stack, PLS is expected to provide another layer of defense in addition to higher-layer cryptography techniques and can be leveraged to resist advanced attack techniques (e.g., quantum computing) based on physical layer processes, artificial noise injection, or secure beamforming designs.

[0009] PLS leverages the inherent randomness properties of the wireless channel to establish a key between two wireless entities without the need for pre-distributed credentials. An eavesdropper present in the same area cannot guess / derive the key established between the two wireless entities.

[0010] In the state of the art, no solution exists for generating keys at the UE and private home network level without previously provisioning these two entities.

[0011] The proposed invention offers a solution to this problem.

[0012] More precisely, the present invention proposes to rely on the PLS to perform the provisioning of credentials between the UE / device and the credential holder.

[0013] The present invention proposes a method for provisioning credentials to a user equipment in a private telecommunication network, the private telecommunication network including a credential holder and a gNB / AMF or an eNB / MME, the method comprising: a) sending a provisioning request from the user equipment to the gNB / AMF or eNB / MME; b) Physical layer security to establish a PLS key between the user equipment and the gNB / AMF or eNB / MME; c) generating a master key at the user equipment; d) sending a message from the user equipment to the gNB / AMF or eNB / MME containing data authorizing the user of the user equipment and / or the user equipment and master key, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; e) sending data from the gNB / AMF or eNB / MME to the credential holder that allows identifying the user of the user equipment and / or the user equipment and the master key; f) verifying at the credential holder data allowing to identify the user of the user equipment and / or the user equipment; g) if the verification is positive, assigning, at the credential holder, a unique subscription identifier to the user equipment and generating corresponding keys, security parameters and key derivation functions; h) sending a unique subscription identifier, security parameters, and a key derivation function from the credential holder to the gNB / AMF or eNB / MME; i) sending a unique subscription identifier, security parameters and a key derivation function from the gNB / AMF or eNB / MME to the user equipment in a message that is integrity and confidentiality protected by a PLS key or a key derived from the PLS key; j) generating, at the user equipment, a final key, wherein the credentials include a unique subscription identifier, security parameters, and the final key.

[0014] Preferably, the data allowing to identify the user of the user equipment and / or the user equipment comprises: User Equipment Id, -User Id, - provisioning code.

[0015] Advantageously, steps d and e also comprise sending a provisioning code, and step f also comprises verifying the provisioning code.

[0016] The credentials are preferably stored in a secure element of the user equipment or in a mobile device of the user equipment.

[0017] Preferably, the unique subscription identifier is the IMSI or the SUPI.

[0018] The Credential Holder can be configured by the ARPF / UDM or the AuC.

[0019] The present invention also relates to a method for provisioning a credential to a credential holder in a private telecommunication network, the private telecommunication network including a user equipment and a gNB / AMF or an eNB / MME, the method comprising: a) sending a provisioning request from the user equipment to the gNB / AMF or eNB / MME; b) Physical layer security to establish a PLS key between the user equipment and the gNB / AMF or eNB / MME; c) sending a message from the user equipment to the gNB / AMF or eNB / MME containing data allowing the user of the user equipment and / or the user equipment to be identified, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; d) sending data from the gNB / AMF or eNB / MME to the credential holder that allows identifying the user of the user equipment and / or the user equipment; e) verifying at the credential holder data allowing to identify the user of the user equipment and / or the user equipment; f) if the verification is positive, assigning a unique subscription identifier to the user equipment and generating a master key and a final key at the credential holder; g) transmitting a unique subscription identifier, a master key, a KDF, and a final key from the credential holder to the gNB / AMF or eNB / MME; h) sending from the gNB / AMF or eNB / MME to the user equipment the unique subscription identifier, the master key, the KDF and the final key in a message that is integrity and confidentiality protected by the PLS key or a key derived from the PLS key; i) generating a final key at the user equipment.

[0020] Preferably, the data allowing to identify the user of the user equipment and / or the user equipment comprises: User Equipment Id, -User Id, - provisioning code.

[0021] Advantageously, steps c and d also include transmitting a provisioning code, and step e also includes verifying the provisioning code.

[0022] The credentials are preferably stored in a secure element of the user equipment and / or in a mobile device of the user equipment.

[0023] The unique subscription identifier may be the IMSI or the SUPI.

[0024] The Credential Holder can be configured by the ARPF / UDM or the AuC.

[0025] The invention will be better understood from a reading of the following description of the drawings. [Brief explanation of the drawings]

[0026] [Figure 1] A method by which a credential holder provides provisioning data to a UE. [Figure 2] A method by which the UE provides provisioning data to the credential holder.

[0027] FIG. 1 illustrates how a credential holder provides provisioning data to a UE.

[0028] In this figure, a user equipment (UE) 10 must be provisioned with some data: a long-term key K, an OTA key, and security parameters, which are part of the credentials to be shared between the UE 10 and a credential holder 12.

[0029] In this diagram, three entities are represented. A UE 10 with or without a secure element (or working with a secure element). gNB / AMF or eNB / MME 11. A gNB is a base station in a 5G telecommunications network, and an eNB is a base station in a 4G telecommunications network. The following description is for a 5G network, but for a 4G network, the term gNB / AMF should be replaced with eNB / MME. A credential holder 12 configured, for example, by ARFP / UDM (5G) or AuC (4G).

[0030] These three entities are in a private network.

[0031] The first step 40 of the method consists in transmitting a request from the UE 10 to the gNB / AMF 11 to provision credentials for the UE 10.

[0032] In step 41, a PLS key is established between the UE 10 and the gNB / AMF 11 by physical layer security. This PLS key is the same key at the UE 10 and gNB / AMF 11 levels.

[0033] In step 42, the UE 10 generates a master key.

[0034] In step 43, the UE 10 sends to the gNB / AMF 11 in a message that is integrity and confidentiality protected by the PLS key (by a cryptographic operation). -UE Id (UE identifier), -User Id (user identifier), - the generated master key, - and optionally a provisioning code.

[0035] This is just an example: all data allowing to identify the user and / or user equipment can be transmitted from the UE 10 to the gNB / AMF 11.

[0036] For example, the following data (with the master key): User Equipment (UE) Id, -User Id, -Provisioning Code (see below)

[0037] So, for example, -UE Id only, -User ID only, -UE Id and User Id, -Provisioning code only, -User ID and provisioning code, -UE Id and provisioning code, - It is possible to send the UE Id and User Id and Provisioning Code.

[0038] In fact, it is possible to use a key derived from this PLS key instead of the PLS key.

[0039] In effect, two keys are derived from the PLS key: one to protect the integrity of the message, and one to protect the confidentiality of that message.

[0040] The provisioning code is, for example, a QR code previously scanned by the UE 10 or a code received by the user over the internet that allows the user to identify itself to the gNB / AMF 11. The provisioning code can also be sent by the UE 10 to the gNB / AMF 11.

[0041] This presence of a provisioning code is recommended to ensure that the provisioning request received by the credential holder 12 comes from a user equipment 10 that is entitled for provisioning. Such a mechanism could be a provisioning code received through out-of-band management by the user of the user equipment 10 and provided to the gNB / AMF or eNB / MME 11 and the credential holder 12 in the request.

[0042] Optionally, a time label and location information of the UE 10 may also be transmitted to the gNB / AMF 11, also protected by a PLS key. These data may be used, for example, as an additional security mechanism to ensure where the UE is located and where the PLS measurements were made. The time label and location information may also be advantageously used on top of the provisioning mechanism. For example, with regard to the time label and location information, one or both parameters (in general) may be used by the PLS to perform PLS key arbitration and / or to verify that keys and / or measurements and / or messages come from the correct user at the correct time.

[0043] The time label and location information can be used on the UE side or on the eNB / gNB side, e.g. some other entity (e.g. MME / AMF, and / or ARPF / UDM, and / or AuC) can perform some correlation / key reconciliation (if necessary) between UE keys and eNB / gNB keys and / or verify provisioning as a complementary measure.

[0044] More precisely, to establish the PLS key, the wireless channel needs to be sampled or some channel estimation needs to be performed on both the Tx and Rx side.

[0045] The measurements / estimations can be performed in the time domain, the frequency domain, or both.

[0046] The (physical layer) measurements are actually performed on both sides (e.g., UE and gNB), but in certain cases the time stamp and location information are on the UE side.

[0047] Preferably, all of this data is concatenated in the message sent by the UE 10 to the gNB / AMF 11 (in the figure, "II" represents concatenation).

[0048] Upon reception, the gNB / AMF 11 can decrypt the received message using the PLS key and send the received data (at least the UE Id, User Id and master key) to the credential holder 12. This is performed in step 44. Here, it is considered that the link between the gNB / AMF 11 and the credential holder 12 is secured. This solution relies on the assumption that the gNB / AMF 11 is trusted and communicates securely with the ARPF / UDM 12 of the private network. If this is not the case, the gNB / AMF 11 may have previously transmitted the PLS key to the credential holder 12 in encrypted form. This allows the encrypted received message to simply be forwarded from the UE 10 to the credential holder 12 without decryption in the gNB / AMF 11.

[0049] In step 45, the Credential Holder 12 performs a verification of the UE Id, the User Id and here (optionally) the provisioning code. If these parameters are positively verified, the Credential Holder 12 generates final keys and related parameters associated with the unique subscription identifier (IMSI or SUPI). These final keys are typically the long-term key K and the OTA key. The security parameters are typically the OPc (Operator Secret key) and the transport key.

[0050] In step 46, the Credential Holder 12 sends in a message the unique subscription identifier (IMSI or SUPI), security parameters and KDF (Key Derivation Function). These data are preferably concatenated into a single message. As before, this message is sent in the clear if the link between the Credential Holder 12 and the gNB / AMF 11 is trusted, otherwise it is encrypted with the PLS key.

[0051] The KDF is, for example, AES128-CMAC or AES256-CMAC.

[0052] In step 47, the gNB / AMF 11 sends the unique subscription identifier (IMSI or SUPI), security parameters (OPc and transport key) and KDF to the UE 10 in a message integrity and confidentiality protected by the PLS key. These data correspond to the credentials that must be transmitted to the UE 10 so that the UE 10 can communicate in a secure manner with the MNO's infrastructure of the private network.

[0053] In step 48, the UE 10 can generate the final keys (long-term key K and OTA key) associated with the associated unique subscription identifier (IMSI or SUPI) using the master key and the KDF.

[0054] Steps 49 and 50 indicate that the UE 10 and the Credential Holder 12 share the same key and communication can take place between these two entities.

[0055] The present invention therefore achieves this provisioning in which a PLS is used to establish a key shared between the provisioning UE 10 and the gNB / AMF 11 located in the private network.

[0056] In the method described above, the provisioning data (key K, OTA keys, security parameters) are provided to the credential holder 12 by the UE.

[0057] It is also possible to have a symmetric scheme where the provisioning data (key K, OTA keys, security parameters) is provided to the UE 10 by the Credential Holder 12.

[0058] This is explained with respect to FIG.

[0059] In this figure, the same elements 10-12 as in FIG. 1 are shown, and steps 50 and 51 are identical to steps 40 and 41 in FIG.

[0060] In step 52, the UE 10 sends to the gNB / AMF 11 in a message that is integrity and confidentiality protected by the PLS key (by a cryptographic operation). -UE Id (UE identifier), -User Id (user identifier), - and optionally a provisioning code.

[0061] Again, this is only an example: all data allowing to identify the user and / or user equipment can be transmitted from the UE 10 to the gNB / AMF 11.

[0062] For example, as described above with respect to FIG. 1, it is possible to transmit one or several of the following data: User Equipment (UE) Id, -User Id, -Provisioning code.

[0063] So, for example, -UE Id only, -User ID only, -UE Id and User Id, -Provisioning code only, -User ID and provisioning code, -UE Id and provisioning code, - It is possible to send the UE Id and User Id and Provisioning Code.

[0064] In fact, it is possible to use a key derived from this PLS key instead of the PLS key.

[0065] In effect, two keys are derived from the PLS key: one to protect the integrity of the message, and one to protect the confidentiality of that message.

[0066] The PLS key is established by physical layer security.

[0067] The provisioning code is, for example, a QR code previously scanned by the UE 10 or a code received by the user over the internet that allows the user to identify itself to the gNB / AMF 11. The provisioning code can also be sent by the UE 10 to the gNB / AMF 11.

[0068] This presence of a provisioning code is recommended to ensure that the provisioning request received by the credential holder 12 comes from a user equipment 10 that is entitled for provisioning. Such a mechanism could be a provisioning code received through out-of-band management by the user of the user equipment 10 and provided to the gNB / AMF or eNB / MME 11 and the credential holder 12 in the request.

[0069] Optionally, as previously described with respect to FIG. 1, a time label and location information of the UE 10 may also be transmitted to the gNB / AMF 11, also protected by a PLS key. These data may be used, for example, as an additional security mechanism to ensure where the UE is located and where the PLS measurements were made. The time label and location information may also be advantageously used on top of the provisioning mechanism. For example, with regard to the time label and location information, one or both parameters may (generally) be used by the PLS to perform PLS key reconciliation and / or to verify that keys and / or measurements and / or messages come from the correct user at the correct time. The time label and location information may be used on the UE side or the eNB / gNB side, for example, where some other entity (e.g., MME / AMF, and / or ARPF / UDM, and / or AuC) may perform some correlation / key reconciliation (if necessary) between UE keys and eNB / gNB keys and / or verify provisioning as a complementary measure.

[0070] Preferably, all of this data is concatenated in the message sent by the UE 10 to the gNB / AMF 11 (in the figure, "II" represents concatenation).

[0071] Once received, the gNB / AMF 11 can use the PLS key to decrypt the received message and send the received data (at least the UE Id, the User Id, and, if present, the provisioning code) to the Credential Holder 12. This is performed in step 53. Here, it is considered that the link between the gNB / AMF 11 and the Credential Holder 12 is secured. This solution relies on the assumption that the gNB / AMF 11 is trusted and communicates securely with the ARPF / UDM 12 of the private network. If this is not the case, the gNB / AMF 11 may have previously transmitted the PLS key to the Credential Holder 12 in encrypted form. This allows the encrypted received message to simply be forwarded from the UE 10 to the Credential Holder 12 without decryption in the gNB / AMF 11.

[0072] In step 54, the Credential Holder 12 performs a verification of the UE Id, the User Id and here (optionally) the provisioning code. If these parameters are positively verified, the Credential Holder 12 assigns a unique subscription identifier (IMSI or SUPI) to the UE 10 and generates master and final keys. These final keys are typically the long-term key K and the OTA key. The security parameters are typically the OPc (Operator Private Key) and the transport key.

[0073] In step 55, the Credential Holder 12 sends the unique subscription identifier (IMSI or SUPI), the master key, security parameters and the KDF (Key Derivation Function) in a message to the gNB / AMF 11. These data are preferably concatenated in a single message.

[0074] The KDF is, for example, AES128-CMAC or AES256-CMAC.

[0075] As before, this message is sent in the clear if the link between the credential holder 12 and the gNB / AMF 11 is trusted, otherwise it is encrypted with the PLS key.

[0076] In step 56, the gNB / AMF 11 sends the unique subscription identifier (IMSI or SUPI), the master key, the security parameters (OPc and transport keys) and the KDF to the UE 10 in a message integrity and confidentiality protected by the PLS key. These data correspond to the credentials that must be transmitted to the UE 10 so that the UE 10 can communicate in a secure manner with the MNO's infrastructure of the private network.

[0077] In step 57, the UE 10 can generate the final keys (long-term key K and OTA key) associated with the associated unique subscription identifier (IMSI or SUPI) using the master key and the KDF.

[0078] Steps 58 and 59 indicate that the UE 10 and the Credential Holder 12 share the same key and communication can take place between these two entities.

[0079] The present invention therefore achieves this provisioning in which a PLS is used to establish a key shared between the UE 10 to be provisioned and the gNB / AMF 11, both located in a private network.

[0080] In the method described above in FIG. 2, the provisioning data (key K, OTA keys, security parameters) are provided to the UE 10 by the Credential Holder 12.

[0081] The advantages provided by the present invention are as follows: There is no need to pre-configure the user equipment 10 with any credentials or certificates. It is possible to perform credential provisioning for generic user equipment 10 independently of the targeted private network. The User Id is just a serial number, there is no customization regarding the targeted private network. No need to access remote servers: this is a very useful feature in the sphere of private networks, since connecting to remote servers (outside the coverage of the private network) is very often not possible (either for technical reasons (e.g. no external link or available external connectivity) or for security reasons). - The solution is very cost-effective for both the device and server side, especially it is much less expensive than RSP (Remote SIM Provisioning). There is minimal BOM (Bill of Materials) and deployment costs as it avoids the use of PKI and simplifies the architecture.

Claims

1. A method for provisioning credentials to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or an eNB / MME, the method comprising: a) sending a provisioning request (40) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security (41); c) generating a master key (42) at said user equipment (10); d) sending a message (43) from the user equipment (10) to the gNB / AMF or eNB / MME (11) containing data authorizing the user of the user equipment (10) and / or the user equipment (10) and the master key, the message being integrity and confidentiality protected by the PLS key or a key derived from the PLS key; e) transmitting (44) the data from the gNB / AMF or eNB / MME (11) to the credential holder (12) that allows the user of the user equipment (10) and / or the user equipment (10) and the master key to be identified; f) verifying (45) at the credential holder (12) the data allowing to identify the user of the user equipment (10) and / or the user equipment (10); g) if the verification is positive, assigning a unique subscription identifier to the user equipment (10) and generating corresponding keys, security parameters and key derivation functions in the credential holder (12); h) sending (46) the unique subscription identifier, the security parameters, and the key derivation function from the credential holder (12) to the gNB / AMF or eNB / MME (11); i) transmitting the unique subscription identifier, the security parameters, and the key derivation function from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by the PLS key or a key derived from the PLS key (47); j) generating (48) at the user equipment (10) a final key, the credentials including the unique subscription identifier, the security parameters, and the final key.

2. The data allowing to identify the user of the user equipment (10) and / or the user equipment (10) User Equipment Id, User Id, - a provisioning code.

3. 3. The method of claim 1, wherein steps d and e also include transmitting a provisioning code, and step f also includes verifying said provisioning code.

4. The method according to any one of claims 1 to 3, wherein the credentials are stored in a secure element of the user equipment (10) or in a mobile device of the user equipment (10).

5. The method according to any one of claims 1 to 4, wherein the unique subscription identifier is an IMSI or a SUPI.

6. The method according to any one of claims 1 to 5, wherein the credential holder is constituted by an ARPF / UDM or an AuC.

7. A method for provisioning a credential to a credential holder (12) in a private telecommunications network, the private telecommunications network including a user equipment (10) and a gNB / AMF or eNB / MME (11), the method comprising: a) sending a provisioning request (50) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security (51); c) sending (52) a message from the user equipment (10) to the gNB / AMF or eNB / MME (11) containing data allowing identification of the user of the user equipment (10) and / or the user equipment (10), the message being integrity and confidentiality protected by the PLS key or a key derived from the PLS key; d) transmitting (53) the data from the gNB / AMF or eNB / MME (11) to the credential holder (12) that allows the user of the user equipment (10) and / or the user equipment (10) to be identified; e) verifying (54) at the credential holder (12) the data allowing to identify the user of the user equipment (10) and / or the user equipment (10); f) if the verification is positive, assigning a unique subscription identifier to the user equipment (10) in the credential holder (12) and generating a master key and a final key; g) transmitting (55) the unique subscription identifier, the master key, the KDF, and the final key from the credential holder (12) to the gNB / AMF or eNB / MME (11); h) transmitting (56) the unique subscription identifier, the master key, the KDF and the final key from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message integrity and confidentiality protected by the PLS key or a key derived from the PLS key; i) generating (57) a final key at said user equipment (10).

8. The data allowing to identify the user of the user equipment (10) and / or the user equipment (10) User Equipment Id, User Id, - a provisioning code.

9. 9. The method of claim 7 or 8, wherein steps c and d also include transmitting a provisioning code, and step e also includes verifying said provisioning code.

10. The method according to any one of claims 7 to 9, wherein the credentials are stored in a secure element of the user equipment (10) or in a mobile device of the user equipment (10).

11. The method according to any one of claims 7 to 10, wherein the unique subscription identifier is an IMSI or a SUPI.

12. The method according to any one of claims 7 to 11, wherein the credential holder (12) is constituted by an ARPF / UDM or an AuC.

Citation Information

Patent Citations

  • Method, UE, and network for providing KDF negotiation

    US20210409939A1

  • Key provisioning method and related products

    WO2022141574A1

  • Provisioning server selection in a cellular network

    WO2022172159A1