Wireless Credential Provisioning via AAA Server Mediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication systems face challenges in allowing user equipment (UE) to access and authenticate with networks using third-party wireless technologies, particularly in unlicensed spectrums, without relying on traditional home subscriber servers (HSS) or mobile network operators (MNOs, and without decoupling service identification from network identification.
Innovation Solution
A method and apparatus for obtaining provisioned credentials for wireless network services involve determining the need for credentials, selecting a provisioning server, and establishing a connection with the network, allowing UE to access services by decoupling service identification from network identification, enabling access to networks through authentication, authorization, and accounting (AAA) servers, even in unlicensed frequency bands.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional HSS and MNO-based authentication is used, then network security and subscription verification are ensured, but UE cannot access third-party networks or unlicensed spectrum networks
Solution Approach 1:
The patent introduces AAA servers as intermediary components between UE and third-party networks. The AAA server acts as a mediator that handles authentication, authorization, and credential management, allowing UE to access networks without direct HSS integration. This resolves the contradiction by enabling third-party network access while maintaining security through the intermediary authentication mechanism.
Solution Approach 2:
The patent segments the authentication system into separate functional components: credential storage in UE, AAA servers for authentication management, and provisioning servers for credential distribution. This segmentation allows flexible access to third-party networks while maintaining security boundaries, resolving the contradiction between versatility and complexity.
2Speed
If credentials are stored locally in UE, then authentication speed is improved, but security risk increases
Solution Approach 1:
The AAA server acts as a secure intermediary that verifies credentials without requiring UE to store sensitive authentication data long-term. The credential provisioning process through AAA servers enables fast authentication while maintaining security by centralizing credential management and verification.
Solution Approach 2:
Credentials are provisioned to UE in advance through secure AAA server communication before actual network access is needed. This preliminary credential distribution enables fast authentication speed while the secure provisioning process mitigates security risks by establishing credentials through authenticated channels before use.
3Adaptability or versatility
If service identification is coupled with network identification, then network management is simplified, but UE cannot access services on third-party networks
Solution Approach 1:
The patent segments service identification from network identification by introducing service-specific credential profiles in UE that can be independently managed. This allows UE to access services on third-party networks by selecting appropriate service credentials while keeping network management complexity manageable through structured credential organization.
Solution Approach 2:
The AAA server framework provides universal authentication capabilities that work across multiple network types and service providers. The standardized AAA interface enables cross-network service access while the underlying credential management system handles the complexity of multi-network authentication transparently.
Data Source
AI summary
Aspects described herein relate to obtaining provisioned credentials for wireless network services. It can be determined that credentials have not been configured for accessing a network. In this case, a provisioning server supported by the network for obtaining credentials is selected, and a request to establish a connection with the network is transmitted. The transmitted request can indicate the provisioning server.


