Method for provisioning credentials to user equipment in a private telecommunications network - Patent Application 20070122997

By utilizing Physical Layer Security to establish a key between UE and network elements, the method addresses the complexity and cost issues of credential provisioning in private networks, enabling secure and cost-effective credential provisioning without pre-configuration.

JP2026502357APending Publication Date: 2026-01-22THALES SA +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025536730
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-12-26
Filing Date
2023-12-13
Publication Date
2026-01-22

AI Technical Summary

Technical Problem

Existing solutions for provisioning initial credentials between user equipment (UE) and a home network in a private telecommunications network are complex, costly, and often impossible to implement without pre-configured credentials, especially when connecting to remote servers is not feasible.

Method used

The method employs Physical Layer Security (PLS) to establish a key between the UE and the gNB/AMF or eNB/MME, enabling secure provisioning of credentials without prior configuration, using a unique subscription identifier and security parameters, which are then stored in a secure element of the UE.

Benefits of technology

This approach eliminates the need for pre-configuration, reduces costs, and allows credential provisioning in private networks without external connectivity, ensuring secure and cost-effective communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026502357000001_ABST
    Figure 2026502357000001_ABST
Patent Text Reader

Abstract

The present invention proposes a method for provisioning credentials to a user equipment 10 in a private telecommunication network, the private telecommunication network including a credential holder 12 and a gNB / AMF or eNB / MME, the method comprising: a) sending a provisioning request from the user equipment 10 to the gNB / AMF or eNB / MME 11; b) establishing a PLS key between the user equipment 10 and the gNB / AMF or eNB / MME 11 via physical layer security; c) sending a message from the user equipment 10 to the gNB / AMF or eNB / MME 11 containing data allowing the user of the user equipment and / or the user equipment 10 to be identified, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; d) sending data from the gNB / AMF or eNB / MME 11 to the credential holder 12 allowing the user of the user equipment and / or the user equipment 10 to be identified; e) verifying in the Credential Holder 12 data allowing to identify the user of the user equipment and / or the user equipment 10; f) if the verification is positive, assigning a unique subscription identifier to the user equipment 10 in the credential holder 12 and generating corresponding keys and security parameters; g) sending a unique subscription identifier, corresponding keys, and security parameters from the credential holder 12 to the gNB / AMF or eNB / MME 11; h) sending the unique subscription identifier, the corresponding key and the security parameters from the gNB / AMF or eNB / MME 11 to the user equipment 10 in a message that is integrity and confidentiality protected by the PLS key or by a key derived from the PLS key, wherein the credentials include the subscription identifier, the corresponding key and the security parameters.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to telecommunications, and more particularly to a method for provisioning credentials to user equipment in a private telecommunications network. [Background technology]

[0002] It is known that it is necessary to secure the provisioning of initial credentials (e.g. credentials for primary authentication) between a UE (User Equipment) and a home network, which remains a complex / restrictive procedure.

[0003] In particular, the home network can be a private network (PN) that hosts a gNB / AMF (gNodeB / Access and Mobility Management Function) or an eNB / MME (eNodeB / Mobility Management Entity) and a credential holder (e.g., an ARPF / UDM, which stands for Authentication Credential Repository and Processing Function / Unified Data Management, or an AuC, which stands for Authentication Center). The ARPF is a functional element of the UDM and is responsible for generating 5G Home Environment Authentication Vectors (HEAV) based on the subscriber's shared key.

[0004] The UE may be a telecommunications terminal with or without interoperating with a secure element, such as an eUlCC (embedded UICC) or an iUICC (integrated UICC).

[0005] Existing solutions require the UE to be provisioned with pre-configured credentials (e.g., certificates or public keys) required to have a connection with a remote server in the home network of the MNO (Mobile Network Operator) that handles the private network.

[0006] These requirements may be too costly or may not be possible to meet within the confines of a private network (eg, connecting to a remote server).

[0007] A known technology called PLS (Physical Layer Security) is a promising approach that can benefit traditional encryption methods. The idea of ​​PLS ​​is to utilize the characteristics of the propagation medium and radio channel impairments to ensure secure communication at the physical layer. PLS is a technology foreseen to address 6G security; for example, PLS is described in several white papers on 6G technology. Apple™ proposed to study its use within the 3GPP in its contribution S3-213987, published during the SA3 meeting in November 2021.

[0008] While this specification clarifies that 5G security will primarily rely on traditional cryptography based on pre-provisioned keys at higher layers of the protocol stack, PLS is expected to provide another layer of defense in addition to higher-layer cryptography techniques and can be leveraged to resist advanced attack techniques (e.g., quantum computing) based on physical layer processes, artificial noise injection, or secure beamforming designs.

[0009] PLS leverages the inherent randomness properties of the wireless channel to establish a key between two wireless entities without the need for pre-distributed credentials. An eavesdropper present in the same area cannot guess / derive the key established between the two wireless entities.

[0010] In the state of the art, no solution exists for generating keys at the UE and private home network level without previously provisioning these two entities.

[0011] The proposed invention offers a solution to this problem.

[0012] More precisely, the present invention proposes to rely on the PLS to perform the provisioning of credentials between the UE / device and the credential holder. Summary of the Invention

[0013] The present invention proposes a method for provisioning credentials to a user equipment in a private telecommunication network, the private telecommunication network including a credential holder and a gNB / AMF or an eNB / MME, the method comprising: a) sending a provisioning request from the user equipment to the gNB / AMF or eNB / MME; b) Physical layer security to establish a PLS key between the user equipment and the gNB / AMF or eNB / MME; c) sending a message from the user equipment to the gNB / AMF or eNB / MME containing data allowing the user of the user equipment and / or the user equipment to be identified, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; d) sending data from the gNB / AMF or eNB / MME to the credential holder that allows identifying the user of the user equipment and / or the user equipment; e) verifying at the credential holder data allowing to identify the user of the user equipment and / or the user equipment; f) if the verification is positive, assigning, at the credential holder, a unique subscription identifier to the user equipment and generating corresponding keys and security parameters; g) sending a unique subscription identifier, corresponding keys, and security parameters from the credential holder to the gNB / AMF or eNB / MME; h) transmitting a unique subscription identifier, a corresponding key and security parameters from the gNB / AMF or eNB / MME to the user equipment in a message integrity and confidentiality protected by a PLS key or by a key derived from the PLS key, the credentials including the subscription identifier, the corresponding key and security parameters. Preferably, the data allowing to identify the user of the user equipment and / or the user equipment comprises: User Equipment Id, -User Id, - provisioning code.

[0014] Advantageously, steps c and d also include transmitting a provisioning code, and step e also includes verifying the provisioning code.

[0015] Also, steps c and d preferably also include transmitting a time label and / or location information, and step e also includes verifying the time label and / or location information.

[0016] Preferably, the credentials are stored in a secure element of the user equipment or in a mobile device of the user equipment.

[0017] Advantageously, the unique subscription identifier is the IMSI or the SUPI.

[0018] In a preferred implementation, the credential holder is configured by an ARPF / UDM or an AuC. The present invention also relates to a method for provisioning a credential to a credential holder in a private telecommunication network, the private telecommunication network including a user equipment and a gNB / AMF or an eNB / MME, the method comprising: a) sending a provisioning request from the user equipment to the gNB / AMF or eNB / MME; b) Physical layer security to establish a PLS key between the user equipment and the gNB / AMF or eNB / MME; c) sending a message from the user equipment to the gNB / AMF or eNB / MME containing data allowing the user of the user equipment and / or the user equipment to be identified, the message being integrity and confidentiality protected by a PLS key or a key derived from the PLS key; d) sending data from the gNB / AMF or eNB / MME to the credential holder that allows identifying the user of the user equipment and / or the user equipment; e) verifying at the credential holder data allowing to identify the user of the user equipment and / or the user equipment; f) if the verification is positive, assigning, at the credential holder, a unique subscription identifier to the user equipment; g) sending a unique subscription identifier from the credential holder to the gNB / AMF or eNB / MME; h) sending a unique subscription identifier from the gNB / AMF or eNB / MME to the user equipment in a message that is integrity and confidentiality protected by a PLS key or a key derived from the PLS key; i) generating keys and security parameters at the user equipment; j) transmitting from the user equipment to the gNB / AMF or eNB / MME keys and security parameters that are integrity and confidentiality protected by the PLS key or a key derived from the PLS key; k) Sending the received keys and security parameters from the gNB / AMF or eNB / MME to a credential holder, wherein the credential includes the keys, security parameters, and a unique subscription identifier.

[0019] Preferably, the data allowing to identify the user of the user equipment and / or the user equipment comprises: User Equipment Id, -User Id, - provisioning code.

[0020] Advantageously, steps c and d also include transmitting a provisioning code, and step e also includes verifying the provisioning code.

[0021] Preferably, steps c and d also include transmitting a time label and / or location information, and step e also includes verifying the time label and / or location information.

[0022] The credentials are preferably stored in a secure element of the user equipment or in a mobile device of the user equipment.

[0023] Preferably, the unique subscription identifier is the IMSI or the SUPI.

[0024] Advantageously, the credential holder is configured by the ARPF / UDM or the AuC. [Brief explanation of the drawings]

[0025] The invention will be better understood from a reading of the following description of the drawings. [Figure 1] A method by which a credential holder provides provisioning data to a UE. [Figure 2] A method by which the UE provides provisioning data to the credential holder. DETAILED DESCRIPTION OF THE INVENTION

[0026] FIG. 1 illustrates how a credential holder provides provisioning data to a UE.

[0027] In this figure, the UE must be provisioned with some data: a long-term key K, an OTA key, and security parameters, which are part of the credentials to be shared between the UE and the credential holder.

[0028] In this diagram, three entities are represented. A UE 10 with or without a secure element (or working with a secure element). gNB / AMF or eNB / MME 11. A gNB is a base station in a 5G telecommunications network, and an eNB is a base station in a 4G telecommunications network. The following description is for a 5G network, but for a 4G network, the term gNB / AMF should be replaced with eNB / MME. A credential holder 12 configured, for example, by ARFP / UDM (5G) or AuC (4G).

[0029] These three entities are in a private network.

[0030] The first step 20 of the method consists in transmitting a request from the UE 10 to the gNB / AMF 11 to provision credentials for the UE 10.

[0031] In step 21, physical layer security establishes a PLS key between the UE 10 and the gNB / AMF 11. This PLS key is the same at the level of the UE 10 and the gNB / AMF 11, assuming symmetric radio channel characteristics.

[0032] In step 22, the UE 10 sends the UE Id (UE identifier) ​​and the User Id (user identifier) ​​to the gNB / AMF 11 in a message that is integrity and confidentiality protected by the PLS key (by a cryptographic operation). This is just an example. All data that allows identifying a user or user equipment can be sent from the UE 10 to the gNB / AMF 11.

[0033] For example, the following data: -User equipment (UE) Id, -User Id, -Provisioning Code (see below)

[0034] So, for example, -UE Id only, -User ID only, -UE Id and User Id, -Provisioning code only, -User ID and provisioning code, -UE Id and provisioning code, - It is possible to send the UE Id and User Id and Provisioning Code.

[0035] In fact, it is possible to use a key derived from this PLS key instead of the PLS key: in effect, two keys are derived from the PLS key, one to protect the integrity of the message and the other to protect the confidentiality of that message.

[0036] The provisioning code is, for example, a QR code previously scanned by the UE 10 or a code received by the user over the internet that allows the user to identify itself to the gNB / AMF 11. The provisioning code can also be sent by the UE 10 to the gNB / AMF 11.

[0037] This presence of a provisioning code is recommended to ensure that the provisioning request received by the credential holder 12 comes from a user equipment 10 that is entitled for provisioning. Such a mechanism could be a provisioning code received through out-of-band management by the user of the user equipment 10 and provided to the gNB / AMF or eNB / MME 11 and the credential holder 12 in the request.

[0038] Optionally, a time label and location information of the UE 10 may also be transmitted to the gNB / AMF 11, also protected by a PLS key. These data may be used, for example, as an additional security mechanism to ensure where the UE is located and where the PLS measurements were made. The time label and location information may also be advantageously used on top of the provisioning mechanism. For example, with regard to the time label and location information, one or both parameters (in general) may be used by the PLS to perform PLS key arbitration and / or to verify that keys and / or measurements and / or messages come from the correct user at the correct time.

[0039] The time label and location information can be used on the UE side or on the eNB / gNB side, e.g. some other entity (e.g. MME / AMF, and / or ARPF / UDM, and / or AuC) can perform some correlation / key reconciliation (if necessary) between UE keys and eNB / gNB keys and / or verify provisioning as a complementary measure.

[0040] Preferably, all of this data is concatenated in the message sent by the UE 10 to the gNB / AMF 11 (in the figure, "II" represents concatenation).

[0041] Upon reception, the gNB / AMF 11 can decrypt the received message using the PLS key and send the received data (here at least the UE Id and User Id) to the Credential Holder 12. This is performed in step 23. Here, it is considered that the link between the gNB / AMF 11 and the Credential Holder 12 is secured. This solution relies on the assumption that the gNB / AMF 11 is trusted and communicates securely with the ARPF / UDM 12 of the private network. If this is not the case, the gNB / AMF 11 may have previously transmitted the PLS key to the Credential Holder 12 in encrypted form. This allows the encrypted received message to simply be forwarded from the UE 10 to the Credential Holder 12 without decryption in the gNB / AMF 11.

[0042] Next, the Credential Holder 12 performs the following three operations: - In step 24, verify the UE Id and User Id (and optionally the correlation of the provisioning code, time label and location information). In step 25, if the verification is positive (at least the UE Id and the User Id are recognized by the Credential Holder 12), the Credential Holder 12 assigns a unique subscription identifier to the UE 10. This unique subscription identifier can for example be the IMSI (in 4G networks) or the SUPI (in 5G networks). In step 26, the Credential Holder 12 generates keys and security parameters corresponding to this unique subscription identifier. These keys are typically a long-term key K and an OTA key. The security parameters are typically an OPc (Operator Secret key) and a transport key.

[0043] In step 27, the Credential Holder 12 sends in a message the unique subscription identifier (IMSI or SUPI), the keys (long-term key K and OTA key) and the security parameters. These data are preferably concatenated into a single message. As before, this message is sent in the clear if the link between the Credential Holder 12 and the gNB / AMF 11 is trusted, otherwise it is encrypted with the PLS key.

[0044] In step 28, the gNB / AMF 11 sends the unique subscription identifier (IMSI or SUPI), the corresponding keys (long-term key K and OTA key) and security parameters (OPc and transport key) to the UE 10 in a message integrity and confidentiality protected by the PLS key. These data correspond to the credentials that must be transmitted to the UE 10 so that the UE 10 can communicate in a secure manner with the MNO's infrastructure of the private network.

[0045] Steps 29 and 30 indicate that the UE 10 and the Credential Holder 12 share the same key and communication can take place between these two entities.

[0046] The present invention therefore achieves this provisioning in which a PLS is used to establish a key shared between the provisioning UE 10 and the gNB / AMF 11 located in the private network.

[0047] In the method described above, the provisioning data (key K, OTA keys, security parameters) are provided to the credential holder 12 by the UE.

[0048] It is also possible to have a symmetric scheme where the provisioning data (key K, OTA keys, security parameters) is provided to the UE 10 by the Credential Holder 12.

[0049] This is explained with respect to FIG.

[0050] In this figure, the same elements 10-12 as in FIG. 1 are represented, and steps 20-24 are identical to those in FIG.

[0051] In step 31, after the credential holder 12 verifies the user equipment Id and user Id (and optionally the provisioning code), the credential holder 12 sends a unique subscription identifier (IMSI or SUPI) to the gNB / AMF or eNB / MME 11.

[0052] As mentioned above, the data transmitted to the credential holder may include the following data making it possible to identify the user and / or the user equipment: User Equipment (UE) Id, -User Id, - provisioning code.

[0053] In step 32, the gNB / AMF or eNB / MME 11 sends this unique subscription identifier to the user equipment 10 in a message that is integrity and confidentiality protected by the PLS key or a key derived from the PLS key.

[0054] In step 33, the user equipment 10 can generate keys (long-term key K and OTA key) and security parameters.

[0055] These keys and security parameters are then transmitted by the user equipment 10 to the gNB / AMF or eNB / MME 11 in step 34, with their integrity and confidentiality protected by the PLS key or a key derived from the PLS key.

[0056] In step 35, the gNB / AMF or eNB / MME 11 sends the decrypted key and security parameters to the credential holder 12.

[0057] At the end of this procedure, the user equipment 10 and the credential holder 12 share credentials (shared secrets 29 and 30 described above with respect to FIG. 1) that include keys, security parameters, and a unique subscription identifier.

[0058] Similar to what was described with respect to FIG. 1, a provisioning code may also be sent from the user equipment 10 to the ARPF / UDM or AuC 11 in step 22, and this provisioning code may be verified by the credential holder 12 in step 24.

[0059] Here again, The credentials can be stored in a secure element of the user equipment 10 or in the mobile device of the user equipment 10. The unique subscription identifier can be the IMSI or the SUPI. The credential holder can be configured by the ARPF / UDM or the AuC.

[0060] The advantages provided by the present invention are as follows: There is no need to pre-configure the user equipment 10 with any credentials or certificates. It is possible to perform credential provisioning for generic user equipment 10 independently of the targeted private network. The User Id is just a serial number, there is no customization regarding the targeted private network. No need to access remote servers: this is a very useful feature in the sphere of private networks, since connecting to remote servers (outside the coverage of the private network) is very often not possible (either for technical reasons (e.g. no external link or available external connectivity) or for security reasons). - The solution is very cost-effective for both the device and server side, especially it is much less expensive than RSP (Remote SIM Provisioning). There is minimal BOM (Bill of Materials) and deployment costs as it avoids the use of PKI and simplifies the architecture.

Claims

1. A method for provisioning credentials to a user equipment (10) in a private telecommunications network, the private telecommunications network including a credential holder and a gNB / AMF or eNB / MME (11), the method comprising: a) sending a provisioning request (20) from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security (21); c) sending (22) a message from the user equipment (10) to the gNB / AMF or eNB / MME (11) containing data that allows identification of the user of the user equipment (10) or the user equipment (10), the message being integrity and confidentiality protected by the PLS key or a key derived from the PLS key; d) transmitting (23) the data from the gNB / AMF or eNB / MME (11) to the credential holder (12) that allows the user of the user equipment (10) or the user equipment (10) to be identified; e) verifying (24) at the credential holder (12) the data allowing to identify the user of the user equipment (10) or the user equipment (10); f) if the verification is positive, assigning (25) a unique subscription identifier to the user equipment (10) in the credential holder (12) and generating (26) corresponding keys and security parameters; g) sending the unique subscription identifier, the corresponding key, and the security parameters from the credential holder to the gNB / AMF or eNB / MME (11) (27); h) sending (28) the unique subscription identifier, the corresponding key, and the security parameters from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message whose integrity and confidentiality are protected by the PLS key or by a key derived from the PLS key, wherein the credentials include the subscription identifier, the corresponding key, and the security parameters.

2. The data allowing to identify the user of the user equipment (10) or the user equipment (10) - User Equipment (10) Id, User Id, - a provisioning code.

3. 3. The method of claim 1, wherein steps c and d also include transmitting a provisioning code, and step e also includes verifying said provisioning code.

4. 4. The method according to claim 1, wherein steps c and d also comprise transmitting a time label and / or location information, and wherein step e also comprises verifying said time label and / or said location information.

5. The method according to any one of claims 1 to 4, wherein the credentials are stored in a secure element of the user equipment (10) or in a mobile device of the user equipment (10).

6. The method according to any one of claims 1 to 5, wherein the unique subscription identifier is an IMSI or a SUPI.

7. The method according to any one of claims 1 to 6, wherein the credential holder is constituted by an ARPF / UDM or an AuC.

8. A method for provisioning a credential to a credential holder (12) in a private telecommunications network, the private telecommunications network including a user equipment (10) and a gNB / AMF or eNB / MME (11), the method comprising: a) sending a provisioning request from the user equipment (10) to the gNB / AMF or eNB / MME (11); b) establishing a PLS key between the user equipment (10) and the gNB / AMF or eNB / MME (11) by physical layer security; c) sending a message from the user equipment (10) to the gNB / AMF or eNB / MME (11) containing data that allows identification of the user of the user equipment (10) or the user equipment (10), the message being integrity and confidentiality protected by the PLS key or a key derived from the PLS key; d) transmitting the data from the gNB / AMF or eNB / MME (11) to the credential holder (12) that allows the user of the user equipment (10) or the user equipment (10) to be identified; e) verifying, at the credential holder (12), the data allowing to identify the user of the user equipment (10) or the user equipment (10); f) if said verification is positive, assigning in said Credential Holder (12) a unique subscription identifier to said user equipment (10); g) sending the unique subscription identifier from the credential holder (12) to the gNB / AMF or eNB / MME (11); h) transmitting the unique subscription identifier from the gNB / AMF or eNB / MME (11) to the user equipment (10) in a message whose integrity and confidentiality are protected by the PLS key or a key derived from the PLS key; i) generating keys and security parameters at said user equipment (10); j) transmitting the key and security parameters from the user equipment (10) to the gNB / AMF or eNB / MME (11), the integrity and confidentiality of which are protected by the PLS key or a key derived from the PLS key; k) transmitting the received key and security parameters from the gNB / AMF or eNB / MME (11) to the credential holder (12), wherein the credential includes the key, the security parameters, and the unique subscription identifier.

9. The data allowing to identify the user of the user equipment (10) or the user equipment (10) - User Equipment (10) Id, User Id, - a provisioning code.

10. 10. The method of claim 8 or 9, wherein steps c and d also include transmitting a provisioning code, and step e also includes verifying said provisioning code.

11. The method according to any one of claims 8 to 10, wherein steps c and d also comprise transmitting a time label and / or location information, and wherein step e also comprises verifying said time label and / or said location information.

12. The method according to any one of claims 8 to 11, wherein the credentials are stored in a secure element of the user equipment (10) or in a mobile device of the user equipment (10).

13. The method according to any one of claims 8 to 12, wherein the unique subscription identifier is an IMSI or a SUPI.

14. The method according to any one of claims 8 to 13, wherein the credential holder (12) is constituted by an ARPF / UDM or an AuC.

Citation Information

Patent Citations

  • Provisioning server selection in a cellular network

    WO2022172159A1